Threat Intelligence

Testing Informed by What Is Actually Being Exploited

Craft Consulting Solutions operates its own threat-intelligence platform. It continuously aggregates public security reporting and enriches it with CVE, exploit, breach, and adversary-technique analysis, so our testing and advisory work reflects the current threat landscape rather than a static checklist.

Quarterly Threat Briefing. A strategic read on the quarter’s trends and what they mean for your security program — free to read or download.

Read the Q2 2026 Briefing

Live Figures

What the platform is tracking now

Catalogued over the last 365 days. These figures update as the platform ingests and enriches new reporting.

Articles analyzed
20,274from 25+ sources
CVEs catalogued
11,5001,080 rated critical
Breaches tracked
1,970$94.7B in reported losses
ATT&CK techniques
579observed in reporting

Aggregated from public security reporting, as of September 18, 2026. These are counts of publicly reported events.

Live from the platform

Under active exploitation right now

The latest CVEs confirmed as exploited in the wild — added to the CISA / VulnCheck Known Exploited Vulnerabilities catalog, newest first, as of Sep 18, 2026. This is the data our testing prioritizes against.

CVE Severity CVSS EPSS Status Ransomware Added
CVE-2026-76461 Critical 9.8 KEV Weaponized Sep 14, 2026
CVE-2026-42018 High 7.5 <1% KEV Weaponized Sep 11, 2026
CVE-2026-42016 High 8.1 <1% KEV Weaponized Sep 11, 2026
CVE-2026-85706 Critical 10.0 KEV Weaponized Sep 11, 2026
CVE-2026-19490 Critical 9.8 6% KEV Weaponized Sep 9, 2026
CVE-2026-75650 Critical 10.0 2% KEV Weaponized Sep 8, 2026
CVE-2026-82329 Critical 9.8 8% KEV Weaponized Sep 2, 2026
CVE-2026-82078 Critical 9.1 2% KEV Weaponized Aug 31, 2026

KEV = confirmed exploited in the wild. EPSS = predicted exploitation probability. Sourced from our threat-intelligence platform — explore all CVEs.

Threat Briefings

An intelligence feed, not a snapshot

The platform publishes a briefing every day. Here is the latest, with the past two weeks below it.

September 17, 2026 66 articles · 20 CVEs · 7 breaches

A critical zero-day vulnerability in Cisco Identity Services Engine is actively being exploited in the wild. This flaw, tracked as CVE-2026-76460, allows unauthenticated remote attackers to bypass authentication via…

Read the full briefing (opens in a new tab)

Earlier briefings

Browse the full archive (opens in a new tab)

Each briefing is synthesized from public security reporting for that day.

Why It Exists

Intelligence that grounds the work

Most security engagements are scoped against a generic methodology. A better test is scoped against what attackers are actually doing right now: which vulnerabilities are being exploited in the wild, which techniques are appearing in real incidents, and which threats are relevant to your industry.

The platform exists to make that possible. It runs continuously, independent of any single engagement, so when we scope a penetration test or brief your leadership, the picture is current rather than a snapshot from the last time someone updated a slide deck.

Built and operated in-house. The platform is developed and run by Craft Consulting Solutions. AI enrichment runs entirely on owned local hardware, with no third-party AI service in the pipeline and no client data involved in its operation.

Capabilities

What the platform does

A continuously running intelligence pipeline, from raw reporting through enriched, queryable analysis.

Aggregation & enrichment

Ingests from 25+ leading security sources on an hourly cycle, deduplicates, and enriches each article with AI-extracted entities: threat actors, tools, breaches, affected platforms, and relevance.

CVE & exploit intelligence

CVSS and EPSS scoring, CISA KEV status, exploit maturity, ransomware associations, and CVE-to-exploit module mappings, drawn from a database of 340,000+ CVEs and 2,600+ known exploit modules.

MITRE ATT&CK & ATLAS

Techniques extracted from real reporting and correlated to threat actors and articles, across both the ATT&CK enterprise matrix and ATLAS, which covers attacks against AI systems.

Breach analytics

Records exposed, data volume, and financial impact extracted from reporting, with rolling 365-day metrics and breakdowns by industry vertical and attack vector.

Threat-actor & tool tracking

Actor profiles and an attacker-tool catalog, each with technique associations and the reporting that mentions them, so activity can be tracked over time.

AI threat briefings

Autonomous investigations on campaigns, actors, breaches, and CVEs, plus scheduled daily, weekly, monthly, and quarterly digests, exportable as reports.

From Intelligence to Exploitation

Testing that pulls live exploit data

The platform is not just a dashboard. Its intelligence feeds Crimson — our in-house exploitation engine — and shapes how we test.

A track record, not a trend. Craft Consulting Solutions has applied artificial intelligence, machine learning, and data analytics to penetration testing since 2021 — well before it became an industry talking point.

Crimson is our in-house exploitation engine, connected directly to the platform during an engagement. It turns raw scan data into ranked targets: machine-learning models score each host’s exploitability, and before testing a given vulnerability Crimson pulls that CVE’s current exploit intelligence — EPSS probability, KEV status, exploit maturity, known exploit modules, and ransomware associations. Effort follows what is genuinely exploitable, and which systems matter most, rather than what a scanner rates by severity alone.

Crimson then drives validated exploitation through a controlled Metasploit workflow, with the consultant in the loop and guardrails at every step. The same intelligence connection works in isolated and air-gapped environments through an offline exchange, so client environments that cannot reach the Internet still benefit from current data.

More on Crimson

How Clients Benefit

Where this shows up in an engagement

Penetration testing

Tests scoped against techniques and vulnerabilities under active exploitation, so findings reflect real attacker behavior.

Penetration testing

Assessments

Program and gap assessments informed by current breach trends and the controls that are actually failing.

Security assessments

Security leadership

Executive and board briefings backed by current, sourced threat intelligence rather than generic industry commentary.

Security leadership

Put current threat intelligence to work

Whether you need a penetration test scoped against live exploitation data, an assessment grounded in current breach trends, or ongoing threat briefings for your leadership, we can help.