Cyber Decision LedgerDecision area

Campaign

7 public Decision Records in the whole ledger carry this label. Back to the full Ledger →

Decision Records

Campaign-linkage tracking postureCRT-2026-02092026.08.07Morning roundtable6 references

Separate tracking for distinct incident classes

Do not treat the discussed incidents as one homogeneous campaign on the current packet evidence. Track separate evidence classes for CI/CD control-plane abuse, water-sector operational control exposure, identity trust abuse, cloud malware, SaaS or token exposure, and supply-chain activity until shared technical pivots justify merging them.

On the current packet evidence, do not merge the discussed activity into one broad campaign. Track the incident classes separately and revisit the linkage decision if credible shared technical pivots are attached.

ActiveLast revised 2026-08-07
TechDevOps supply chainAreaCampaignRisk acceptance
SeverityMedium
ConfidenceHigh confidence · 0/9 backed · 2 gaps
SOC instrumentation for calendar-based command and controlCRT-2026-01792026.08.04Morning roundtable5 references

Microsoft 365 calendar and Graph abuse telemetry

Instrument Microsoft 365 and Graph telemetry to hunt for unusual calendar creation and attachment activity, far-future events, abnormal Graph API use, OAuth and Entra token changes, suspicious endpoint configuration files, and DNS-tunnel fallback behavior.

SOC teams should add hunting coverage for abnormal Microsoft 365 calendar and Graph activity, unusual OAuth or Entra token behavior, suspicious endpoint configuration files, and fallback DNS tunneling patterns associated with SaaS abuse.

ActiveLast revised 2026-08-04
TechIdentity & accessSaaS collaborationAreaCampaignSOC escalation
SeverityHigh
ConfidenceHigh confidence · 0/9 backed · 2 gaps
Ransomware readiness for reported service portal and industrial locker claimCRT-2026-01312026.07.26Morning roundtable5 references

DevMan and Funky Mantis ransomware readiness posture

Do not change the OT threat model around an unverified industrial locker claim. Monitor affiliate tooling and hunt Windows, Linux, and ESXi ransomware behavior while hardening identity, backup, virtualization, and IT-to-OT recovery choke points.

Treat the reported industrial locker capability as unconfirmed unless sample-level evidence emerges, but use the ransomware-service reporting to harden identity, backup, virtualization, and IT-to-OT recovery paths and to hunt common Windows, Linux, and ESXi ransomware behavior.

ActiveLast revised 2026-07-26
TechOS platformAreaCampaignRisk acceptanceVendor claim
SeverityHigh
ConfidenceHigh confidence · 0/9 backed · 2 gaps
CMS webshell exposure handlingCRT-2026-00792026.07.14Morning roundtable6 references

Split CMS webshell incidents from exposure-only cases

Use an evidence-based split: isolate confirmed compromised CMS hosts with webshell evidence, preserve evidence, rotate related credentials, and rebuild from clean media; if there is only matching exposure without shell evidence, patch and hunt, remove public admin paths, and add WAF/CDN controls.

For public CMS hosts with confirmed webshell evidence, treat the host as an incident: isolate it, preserve evidence, rotate related credentials, and rebuild from clean media. For exposure without compromise evidence, patch and hunt, remove public admin paths, and add WAF/CDN controls. Avoid product-specific or global-campaign claims until authoritative details are attached.

ActiveLast revised 2026-07-14
TechWeb applicationAreaCampaignPatch prioritization
SeveritySeverity was not recorded when this record was first published.
ConfidenceHigh confidence · 0/9 backed · 2 gaps
Canonical/Ubuntu disruption and supply-chain escalation postureCRT-2026-00682026.07.12Morning roundtable4 references

Treat Canonical/Ubuntu hacktivist claims as availability triage absent supply-chain evidence

Treat the Canonical/Ubuntu pro-Iran hacktivist claim as geopolitical disruption context and availability-risk triage, not as assumed Iranian state tasking or Ubuntu supply-chain compromise, unless authoritative evidence shows deeper impact.

Treat public pro-Iran Canonical/Ubuntu disruption claims as availability and context triage; do not assume Iranian state tasking or Ubuntu package/supply-chain compromise absent authoritative impact or integrity evidence.

ActiveLast revised 2026-07-12
AreaCampaignPatch prioritizationSupply chain
SeverityMedium
ConfidenceHigh confidence · 0/9 backed · 2 gaps
Incident briefing and delegated-trust framingCRT-2026-00602026.07.11Morning roundtable4 references

Brief incidents as separate lanes with a delegated-trust pattern

Do not brief the day’s incidents as one grand control-plane campaign. Track a narrower delegated-trust abuse pattern across identity, workflows, packages, agents, and cloud services while keeping CMS webshelling, weak wallet randomness, and conventional exploitation in separate operational lanes.

Brief the incidents as separate operational risk lanes while tracking a narrower delegated-trust abuse pattern across identity, workflow, package, agent, and cloud-service contexts. Avoid presenting unrelated CMS exploitation, weak wallet randomness, or conventional exploitation as one campaign.

ActiveLast revised 2026-07-11
AreaCampaignThreat actor
SeverityMedium
ConfidenceHigh confidence · 0/9 backed · 2 gaps
Microsoft 365 identity containmentCRT-2026-00522026.07.10Afternoon roundtable5 references

Restrict Microsoft 365 trust-enrollment and session-persistence paths

Restrict new passkey, security-key, authenticator, phone, and recovery-method enrollment for high-risk users to managed devices, trusted networks, or verified help-desk workflows; limit broad device-code authentication where feasible; revoke suspicious sessions, refresh tokens, OAuth grants, and attacker-added authentication methods.

Microsoft 365 tenants should harden trust-enrollment and session-persistence controls now: restrict new authentication-method registration for high-risk users, limit device-code authentication where feasible, and review or revoke suspicious sessions, refresh tokens, OAuth grants, and added authentication methods. Named campaign details in the source packet are treated as source-reported rather than independently confirmed.

ActiveLast revised 2026-07-10
TechSaaS collaborationAreaCampaign
SeveritySeverity was not recorded when this record was first published.
ConfidenceHigh confidence · 0/9 backed · 2 gaps

Unified Search

Search the public record.