Threat coverage by the numbers
What we monitor for you
You don't have the capacity to follow every threat source yourself. We do it for you and deliver only what is relevant to your environment and sector.
CVEs and vulnerabilities
You know which new CVEs are actively being exploited and whether your software or hardware is vulnerable. Not every CVE is critical; we filter on exploitability in the wild.
Ransomware groups
You have insight into the 30+ active ransomware groups we track: TTPs, victim profiles, ransom strategy and infrastructure. Know whether your sector is in the crosshairs.
APT actors
You know which state-sponsored actors are active in the Netherlands, Belgium and Spain. From NOBELIUM to APT28: we track campaigns and map them to MITRE ATT&CK techniques.
OT and ICS threats
Your OT environment is not blind. We monitor threats specific to industrial protocols and ICS/SCADA environments, including new malware that disrupts production processes.
Dark web and data leaks
You know when your organisation name, credentials or internal data appears on dark web forums. We actively monitor initial access brokers and data leak platforms.
Sector intelligence
You receive intelligence filtered for your sector: financials, government, healthcare, industry or technology. Generic feeds deliver noise; sector-specific context delivers action.
Recent intelligence
Week 15, 2026: three active threats we are currently monitoring and for which we have published detection rules and IoCs.
Qilin ransomware bypasses EDR via BYOVD kernel-driver attack: 1,800+ victims, behaviour detection required
The Qilin ransomware group is using the BYOVD (Bring Your Own Vulnerable Driver) technique to disable EDR kernel callbacks. By loading a legitimate but vulnerable driver, attackers remove endpoint detection visibility at the kernel level. With over 1,800 confirmed victims worldwide, this is no longer an experimental approach but a proven attack chain. Traditional EDR solutions that rely solely on signatures or kernel hooks are vulnerable to this technique. Organisations that consider EDR to be sufficient protection need to reassess this assumption. Action: implement behaviour-based detection alongside EDR, activate driver allowlisting, consider DEFION MXDR with additional detection layers, and verify that your current EDR vendor supports BYOVD detection.
CVE-2026-48027 added to CISA KEV: malicious VS Code extension published for 18 minutes caused full developer environment compromise
CVE-2026-48027, affecting the Nx Console VS Code extension, has been added to the CISA Known Exploited Vulnerabilities catalogue. A malicious version of the extension was published to the VS Code Marketplace for 18 minutes before takedown, during which it was capable of full developer environment compromise: credential theft, source code exfiltration, and lateral movement via CI/CD pipelines. This incident demonstrates that developer tooling is now a primary supply chain attack vector. A single compromised developer machine can cascade into production environment access. Action: audit installed VS Code extensions across the development team, rotate any credentials stored in developer environments, and implement zero-trust for developer workstation network access.
IBM Langflow RCE zero-day in the wild: CVSS 9.8, AI infrastructure fast-track CVE, historically under 36 hours to exploitation
A critical remote code execution vulnerability (CVSS 9.8) has been identified in IBM Langflow, a widely used platform for building LLM-based applications and AI pipelines. The vulnerability is confirmed in the wild and has been assigned as an AI infrastructure fast-track CVE, a category introduced in 2026 to accelerate response to vulnerabilities in AI platforms. Historically, exploitation of LLM platform vulnerabilities reaches peak volume within 36 hours of disclosure. Organisations using Langflow in production AI pipelines should treat this as immediately actionable. Action: patch or isolate Langflow instances immediately, audit access logs for exploitation indicators, and review network exposure of AI platform management interfaces.
Research and reports
DEFION publishes on two levels. Technical depth for security teams. Strategic context for management.
Technical
- ✓ In-depth CVE analyses and exploitability scores
- ✓ Malware reversals and behavioural analyses
- ✓ KQL detection rules for Microsoft Sentinel
- ✓ Pwn2Own and conference technical write-ups
- ✓ MITRE ATT&CK mapping per campaign
Strategic
- ✓ Monthly threat reports for the CISO
- ✓ Sector analyses per industry and region
- ✓ MITRE ATT&CK heatmaps at organisational level
- ✓ Client briefings on active campaigns
- ✓ Quarterly Threat Landscape report NL/EU
Who is this relevant for?
Threat Intelligence is not just for SOC analysts. Every security role benefits from the right information at the right time.
CISO
- ✓ Monthly threat briefing for the boardroom
- ✓ Risk assessment per sector and regulation
- ✓ Evidence base for security investments
SOC Analyst
- ✓ IoC feeds ready for use in your SIEM
- ✓ KQL detection rules per campaign
- ✓ Technical depth per threat and TTP
IT Director
- ✓ Visibility into vulnerabilities in your environment
- ✓ Patch prioritisation based on exploitability
- ✓ Overview of active threats in your sector
Incident Responder
- ✓ Context-rich IoCs and YARA rules
- ✓ TTP mapping for attribution and containment
- ✓ Rapid sector briefings on active campaigns
Intelligence products
From freely accessible publications to client-specific threat analyses. Choose the level that suits your organisation.
Freely accessible
- ✓ Blog: technical analyses and threat reports
- ✓ Quarterly Threat Landscape report NL/EU
- ✓ CVE updates and patch advisories
- ✓ Research Labs publications
MDR clients
- ✓ Weekly tailored threat briefings
- ✓ IoC feeds directly in your SIEM or EDR
- ✓ KQL detection rules per campaign
- ✓ Direct notification on critical threats
- ✓ MITRE ATT&CK heatmap per quarter
Custom
- ✓ Client-specific threat analysis
- ✓ Sector briefing for your industry
- ✓ Dark web scan for organisation name and credentials
- ✓ Imminent Threat Exposure assessment
FAQ Threat Intelligence
What is Threat Intelligence and why do I need it?
What is the difference between strategic and operational threat intelligence?
How does DEFION Threat Intelligence differ from a commercial feed?
How quickly do you publish when an active campaign or zero-day emerges?
Can I subscribe to Threat Intelligence without MDR?
Request a threat analysis
Want to know which threats are active in your sector and whether your environment is vulnerable? Our analysts produce a targeted analysis based on your profile.
No obligations. First analysis free of charge for qualified organisations.
®