Cybersecurity Threats

The CIS® and MS-ISAC® cybersecurity professionals analyze risks and alert members to current online security threats.

Timely updates when you need to take action

Subscribe to Advisories
Low
Guarded
Elevated
High
Severe

Explanation of the Current Alert Level of GUARDED

The alert level is the overall current threat level.

This threat level is based on analysis by the Center for Internet Security® (CIS®) Operations, Intelligence, and Services (OIS) department covering the cyber threat landscape for Quarter 2 (Q2) of 2026. In calendar year 2026Q2, OIS published 32 Cybersecurity Advisories for critical severity high risk vulnerabilities in popular software applications known to be in use in U.S. State, Local, Tribal, and Territorial (SLTT) environments. A significant upward trend in AI-enhanced attacks is fueling high volumes of social engineering and phishing, lateral movement, credential dumping, and web shell activity. Organizations and users are advised to update and apply all appropriate vendor security patches to vulnerable systems and to continue to update their antimalware detections daily. Organizations should also provide updated user awareness training on malicious attachments and links contained in emails especially from un-trusted sources.

Read more about our approach

Vulnerability Advisories

Latest Advisory

Multiple Vulnerabilities in Ivanti Products Could Allow for Arbitrary Code Execution
10 Sep 2026
Multiple vulnerabilities have been discovered in Ivanti products, the most severe of which could allow for arbitrary code execution. Successful e...
Read the details

 

Centralize Your Vulnerability Awareness

Keep track of new vulnerabilities in a centralized location to prioritize your remediation tasks and advance your efforts to achieve essential cyber hygiene through CIS Critical Security Controls: Implementation Group 1 (IG1).

View All Advisories

Resources for Countering Cybersecurity Threats

MS-ISAC

Exclusive membership and resources available to U.S. SLTTs.

Join

The CIS SOC

24x7x365 expert monitoring, analysis, and escalation of cybersecurity threats

Download

 

Top Malware

During the first half (H1) of 2026, PureLogs led the Top 10 Malware list of the Multi-State Information Sharing and Analysis Center® (MS-ISAC®), comprising 27% of detections by MS-ISAC monitoring services. Agent Tesla, a remote access trojan, and CoinMiner, a cryptocurrency miner, followed PureLogs.

Top 10 Malware threats

In H1 2026, the MS-ISAC also observed the return of Lumma Stealer, an infostealer malware, while PureLogs, RedTail, and FormBook made their first appearances.

  • PureLogs is a .NET infostealer from the Pure family of malware. Delivered via phishing (TXZ archives) using the PawsRunner steganography loader, PureLogs steals credentials, cookies, and browser data from 100+ applications.
  • RedTail is a Linux cryptojacker that mines Monero cryptocurrency. First observed in early 2024, the malware obtains initial access via SSH brute-force or exploitation (PAN-OS, PHP, others), and it achieves persistence via implanted SSH keys. RedTail evades detection through file and log deletion.
  • FormBook is a Windows infostealer / Malware as a Service (MaaS) offering delivered via phishing emails. Using fileless execution via process hollowing into signed Windows binaries, FormBook steals credentials, cookies, keystrokes, and clipboard from 40+ browsers and email clients.