Detection engineering communities have released a series of updates and insights aimed at improving threat detection capabilities across multiple platforms. Notable highlights include the integration of chaos engineering principles into incident response playbooks, the use of AI to generate and translate detection rules, and the expansion of community-driven detection content for PowerShell execution, lateral movement, and service installations. These efforts are designed to help security teams stay ahead of evolving attacker techniques and streamline the process of operationalizing threat intelligence.
In parallel, major detection rule repositories such as Sigma, Splunk, and YARA have seen significant activity, with dozens of new and updated rules targeting recent exploits and vulnerabilities. Key updates include new Sigma rules for Commvault RCE and GoAnywhere MFT attacks, Splunk content for Oracle E-Business Suite exploitation, and YARA rules for WSUS RCE and WinRAR path traversal. Cloud detection coverage has also been enhanced, with new rules for AWS and Azure environments, and credential dumping detections have been refined to monitor additional processes and command-line flags. These developments collectively strengthen the detection engineering landscape and provide security teams with actionable tools to address current threats.

See real exploitation activity before you spend the cycle.
5 events from the most recent confirmed update back to the earliest known activity.
Huntress said it observed active exploitation of internet-exposed WSUS servers for CVE-2025-59287 and published indicators of compromise and a Sigma detection rule.
Microsoft issued an out-of-band patch for CVE-2025-59287, a critical unauthenticated deserialization remote code execution flaw in WSUS with a CVSS score of 9.8.
The UN Convention against Cybercrime opened for signature in Hanoi, with 72 countries signing according to the newsletter's threat landscape summary.
A retrospective survey covering 2024–2025 open-source supply chain compromises identified phishing and 'control handoff' as major root causes, citing incidents such as xzutils and polyfill.io.
Capita was hit by a BlackBasta ransomware attack in 2023, an incident later examined through an ICO report and leaked chat logs cited in the newsletter.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.