MITRE released version 18 of its ATT&CK framework, introducing significant improvements to help organizations detect, track, and respond to cyberthreats across cloud, mobile, industrial, and traditional IT environments. The update features more structured detection strategies and analytics, making it easier for defenders to operationalize the framework and map adversary tactics, techniques, and procedures (TTPs) to actionable defenses. Version 18 also expands coverage to include modern threats targeting cloud infrastructure and DevOps workflows, adds new techniques, and incorporates additional cyberthreat intelligence on groups, tools, and campaigns.
Security leaders are now exploring how to pair MITRE ATT&CK v18 with the MITRE ATLAS framework to address the unique challenges of AI governance and defense. By combining ATT&CK’s improved detection capabilities with ATLAS’s focus on AI threats, CISOs can move from policy-based to behavior-based detections, particularly in environments leveraging generative AI. Practical resources, such as OWASP’s GenAI governance checklists and threat defense tools, are being used to operationalize these frameworks and strengthen AI-ready cyber defense strategies.

See the reporting duties and controls this puts on the clock.
1 event from the most recent confirmed update back to the earliest known activity.
MITRE released ATT&CK v18 as a major update to improve how organizations track, detect, and respond to threats across traditional IT, cloud, mobile, and OT environments. The release introduced structured Detection Strategies and Analytics objects, added 11 new cloud/DevOps-focused techniques, and expanded CTI, mobile, and OT coverage.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.