{
  "globalThreatLevel": "High",
  "globalThreatLevelSubtext": "Critical threats actively exploited",
  "lastUpdated": "2026-09-02T02:00:58.772915+00:00",
  "severityWindowDays": 30,
  "severityCounts": {
    "info": 111,
    "high": 131,
    "medium": 67,
    "low": 13,
    "critical": 32
  },
  "topCves": [
    {
      "id": "CVE-2026-21962",
      "description": "CVE-2026-21962: Oracle WebLogic RCE Under Active Attack",
      "score": 10
    },
    {
      "id": "CVE-2026-58231",
      "description": "CVE-2026-58231: SAP Commerce Cloud Unauthenticated RCE Flaw",
      "score": 10
    },
    {
      "id": "CVE-2026-59726",
      "description": "CVE-2026-59726: Ruflo RCE and AI Memory Poisoning Mitigation",
      "score": 10
    },
    {
      "id": "CVE-2026-16812",
      "description": "CVE-2026-16812: Arista VeloCloud Orchestrator Command Injection Exploit",
      "score": 10
    }
  ],
  "threatCategories": [
    {
      "label": "Supply Chain",
      "level": 29,
      "color": "bg-yellow-500"
    },
    {
      "label": "Zero-Days",
      "level": 27,
      "color": "bg-blue-500"
    },
    {
      "label": "Ransomware",
      "level": 25,
      "color": "bg-red-500"
    },
    {
      "label": "Phishing",
      "level": 25,
      "color": "bg-orange-500"
    }
  ],
  "activeCampaigns": [
    {
      "name": "APT28 activity",
      "type": "Threat Intel",
      "status": "Reported",
      "severity": "high"
    },
    {
      "name": "Salt Typhoon activity",
      "type": "Threat Intel",
      "status": "Reported",
      "severity": "high"
    },
    {
      "name": "Lazarus Group activity",
      "type": "Threat Intel",
      "status": "Reported",
      "severity": "critical"
    }
  ],
  "topThreatActors": [
    {
      "name": "APT29",
      "attribution": "Russia",
      "mentions": 4
    },
    {
      "name": "Sandworm",
      "attribution": "Russia",
      "mentions": 3
    },
    {
      "name": "APT28",
      "attribution": "Russia",
      "mentions": 2
    },
    {
      "name": "Salt Typhoon",
      "attribution": "China",
      "mentions": 1
    },
    {
      "name": "Midnight Blizzard",
      "attribution": "Russia",
      "mentions": 1
    }
  ],
  "hotVendors": [
    {
      "name": "Linux",
      "count": 4
    },
    {
      "name": "Apple",
      "count": 3
    },
    {
      "name": "Microsoft",
      "count": 3
    },
    {
      "name": "Fortinet",
      "count": 2
    },
    {
      "name": "Google",
      "count": 2
    },
    {
      "name": "Atlassian",
      "count": 1
    }
  ],
  "_meta": {
    "source": "https://runtimerebel.com",
    "documentation": "https://runtimerebel.com/api-docs",
    "licence": "CC BY 4.0 — attribution to runtimerebel.com required",
    "updated": "Regenerated every 8 hours by the ingestion pipeline."
  }
}