Collections
Views that cut across industry and geography. Each one groups threat actors, vulnerabilities and malware families by something they share — a delivery mechanism, a class of exposed technology, a way of getting paid — and then renders what our graph currently holds for that set. The membership is chosen by hand; the numbers are not.
- Exploited Edge Devices The VPN concentrators, firewalls, file-transfer servers and remote-access tools that both ransomware crews and state actors break. · 26 entries · 219 in 90d · 18 KEV CVEs · 35 briefings
- Social-Engineering Intrusion Sets The crews whose defining tradecraft is a person, not a vulnerability: help-desk impersonation, MFA fatigue, vishing and paste-your-own-malware. · 20 entries · 60 in 90d · 32 briefings
- How North Korea Earns Cryptocurrency theft, fraudulent IT employment and ransomware for cash — one state's revenue portfolio, grouped by motive rather than by unit. · 18 entries · 24 briefings
- The China-Nexus Toolkit What a shared implant narrows an attribution to — ShadowPad, PlugX and DLL side-loading, measured across every China-origin actor we track. · 31 entries · 4 KEV CVEs · 30 briefings
- Mass-Victim Weeks When one crew publishes hundreds of victims at once — the burst statistic that finds these events, and the debut dumps that look identical. · 8 entries · 127 in 90d · 3 KEV CVEs · 16 briefings
How to read these
A collection is an editorial judgement about which entities belong together, published so it can be argued with. Every count beside it is computed live from the same graph the rest of the site reads, so a group that stops being active stops showing incidents here without anyone editing the page. What does not update by itself is the membership — each page states, in its own words, how its list was chosen and what it leaves out.