Aggregation & enrichment
Ingests from 25+ leading security sources on an hourly cycle, deduplicates, and enriches each article with AI-extracted entities: threat actors, tools, breaches, affected platforms, and relevance.
Threat Intelligence
Craft Consulting Solutions operates its own threat-intelligence platform. It continuously aggregates public security reporting and enriches it with CVE, exploit, breach, and adversary-technique analysis, so our testing and advisory work reflects the current threat landscape rather than a static checklist.
Quarterly Threat Briefing. A strategic read on the quarter’s trends and what they mean for your security program — free to read or download.
Read the Q2 2026 BriefingLive Figures
Catalogued over the last 365 days. These figures update as the platform ingests and enriches new reporting.
Aggregated from public security reporting, as of September 18, 2026. These are counts of publicly reported events.
Live from the platform
The latest CVEs confirmed as exploited in the wild — added to the CISA / VulnCheck Known Exploited Vulnerabilities catalog, newest first, as of Sep 18, 2026. This is the data our testing prioritizes against.
| CVE | Severity | CVSS | EPSS | Status | Ransomware | Added |
|---|---|---|---|---|---|---|
| CVE-2026-76461 | Critical | 9.8 | — | KEV Weaponized | — | Sep 14, 2026 |
| CVE-2026-42018 | High | 7.5 | <1% | KEV Weaponized | — | Sep 11, 2026 |
| CVE-2026-42016 | High | 8.1 | <1% | KEV Weaponized | — | Sep 11, 2026 |
| CVE-2026-85706 | Critical | 10.0 | — | KEV Weaponized | — | Sep 11, 2026 |
| CVE-2026-19490 | Critical | 9.8 | 6% | KEV Weaponized | — | Sep 9, 2026 |
| CVE-2026-75650 | Critical | 10.0 | 2% | KEV Weaponized | — | Sep 8, 2026 |
| CVE-2026-82329 | Critical | 9.8 | 8% | KEV Weaponized | — | Sep 2, 2026 |
| CVE-2026-82078 | Critical | 9.1 | 2% | KEV Weaponized | — | Aug 31, 2026 |
KEV = confirmed exploited in the wild. EPSS = predicted exploitation probability. Sourced from our threat-intelligence platform — explore all CVEs.
Threat Briefings
The platform publishes a briefing every day. Here is the latest, with the past two weeks below it.
A critical zero-day vulnerability in Cisco Identity Services Engine is actively being exploited in the wild. This flaw, tracked as CVE-2026-76460, allows unauthenticated remote attackers to bypass authentication via…
Read the full briefing (opens in a new tab)Each briefing is synthesized from public security reporting for that day.
Why It Exists
Most security engagements are scoped against a generic methodology. A better test is scoped against what attackers are actually doing right now: which vulnerabilities are being exploited in the wild, which techniques are appearing in real incidents, and which threats are relevant to your industry.
The platform exists to make that possible. It runs continuously, independent of any single engagement, so when we scope a penetration test or brief your leadership, the picture is current rather than a snapshot from the last time someone updated a slide deck.
Built and operated in-house. The platform is developed and run by Craft Consulting Solutions. AI enrichment runs entirely on owned local hardware, with no third-party AI service in the pipeline and no client data involved in its operation.
Capabilities
A continuously running intelligence pipeline, from raw reporting through enriched, queryable analysis.
Ingests from 25+ leading security sources on an hourly cycle, deduplicates, and enriches each article with AI-extracted entities: threat actors, tools, breaches, affected platforms, and relevance.
CVSS and EPSS scoring, CISA KEV status, exploit maturity, ransomware associations, and CVE-to-exploit module mappings, drawn from a database of 340,000+ CVEs and 2,600+ known exploit modules.
Techniques extracted from real reporting and correlated to threat actors and articles, across both the ATT&CK enterprise matrix and ATLAS, which covers attacks against AI systems.
Records exposed, data volume, and financial impact extracted from reporting, with rolling 365-day metrics and breakdowns by industry vertical and attack vector.
Actor profiles and an attacker-tool catalog, each with technique associations and the reporting that mentions them, so activity can be tracked over time.
Autonomous investigations on campaigns, actors, breaches, and CVEs, plus scheduled daily, weekly, monthly, and quarterly digests, exportable as reports.
From Intelligence to Exploitation
The platform is not just a dashboard. Its intelligence feeds Crimson — our in-house exploitation engine — and shapes how we test.
A track record, not a trend. Craft Consulting Solutions has applied artificial intelligence, machine learning, and data analytics to penetration testing since 2021 — well before it became an industry talking point.
Crimson is our in-house exploitation engine, connected directly to the platform during an engagement. It turns raw scan data into ranked targets: machine-learning models score each host’s exploitability, and before testing a given vulnerability Crimson pulls that CVE’s current exploit intelligence — EPSS probability, KEV status, exploit maturity, known exploit modules, and ransomware associations. Effort follows what is genuinely exploitable, and which systems matter most, rather than what a scanner rates by severity alone.
Crimson then drives validated exploitation through a controlled Metasploit workflow, with the consultant in the loop and guardrails at every step. The same intelligence connection works in isolated and air-gapped environments through an offline exchange, so client environments that cannot reach the Internet still benefit from current data.
How Clients Benefit
Tests scoped against techniques and vulnerabilities under active exploitation, so findings reflect real attacker behavior.
Program and gap assessments informed by current breach trends and the controls that are actually failing.
Executive and board briefings backed by current, sourced threat intelligence rather than generic industry commentary.
Whether you need a penetration test scoped against live exploitation data, an assessment grounded in current breach trends, or ongoing threat briefings for your leadership, we can help.