Fraud & Identity Theft MITRE Releases Fight Fraud Framework The document provides a behavior-based model of the tactics and techniques employed by fraudsters. Ionut ArghireApril 10, 2026
ICS/OT MITRE Launches New Security Framework for Embedded Systems The Embedded Systems Threat Matrix (ESTM) aims to help organizations protect critical embedded systems. Eduard KovacsJanuary 21, 2026
Application Security MITRE Releases 2025 List of Top 25 Most Dangerous Software Vulnerabilities XSS remains the top software weakness, followed by SQL injection and CSRF. Buffer overflow issues and improper access control make it to top 25. Ionut ArghireDecember 12, 2025
Cloud Security MITRE Posts Results of 2025 ATT&CK Enterprise Evaluations Eleven companies took part in the evaluations and several have boasted 100% detection and coverage rates. Eduard KovacsDecember 11, 2025
Risk Management MITRE Unveils ATT&CK v18 With Updates to Detections, Mobile, ICS MITRE has unveiled the latest version of ATT&CK, with the most significant changes in the defensive part of the framework. Eduard KovacsOctober 29, 2025
Vulnerabilities MITRE Updates List of Most Common Hardware Weaknesses MITRE has updated the list of Most Important Hardware Weaknesses to align it with evolving hardware security challenges. Ionut ArghireAugust 22, 2025
Risk Management MITRE Unveils AADAPT Framework to Tackle Cryptocurrency Threats The MITRE AADAPT framework provides documentation for identifying, investigating, and responding to weaknesses in digital asset payments. Ionut ArghireJuly 15, 2025
Malware & Threats MITRE Hackers’ Backdoor Has Targeted Windows for Years Windows versions of the BrickStorm backdoor that the Chinese APT used in the MITRE hack last year have been active for years. Ionut ArghireApril 17, 2025
Government MITRE CVE Program Gets Last-Hour Funding Reprieve The US government's cybersecurity agency CISA has “executed the option period on the contract” to keep the vulnerability catalog operational. Ryan NaraineApril 16, 2025
Government MITRE Warns CVE Program Faces Disruption Amid US Funding Uncertainty MITRE warns of a deterioration of national vulnerability databases and advisories, slowed vendor reaction and limited response operations. Ryan NaraineApril 15, 2025
Vulnerabilities MITRE Updates List of 25 Most Dangerous Software Vulnerabilities MITRE has released an updated CWE Top 25 Most Dangerous Software Weaknesses list, with cross-site scripting (XSS) at the top. Ionut ArghireNovember 21, 2024
Artificial Intelligence MITRE Announces AI Incident Sharing Project MITRE’s AI Incident Sharing initiative helps organizations receive and hand out data on real-world AI incidents. Ionut ArghireOctober 7, 2024
ICS/OT MITRE Adds Mitigations to EMB3D Threat Model MITRE has expanded the EMB3D Threat Model with essential mitigations to help organizations address threats to embedded devices. Ionut ArghireOctober 2, 2024
Incident Response VMware Abused in Recent MITRE Hack for Persistence, Evasion MITRE has shared information on how China-linked hackers abused VMware for persistence and detection evasion in the recent hack. Eduard KovacsMay 23, 2024
IoT Security MITRE EMB3D Threat Model Officially Released MITRE announced the public availability of the EMB3D threat model for embedded devices used in critical infrastructure. Eduard KovacsMay 14, 2024
Nation-State MITRE Hack: China-Linked Group Breached Systems in December 2023 MITRE has shared more details on the recent hack, including the new malware involved in the attack and a timeline of the attacker’s activities. Eduard KovacsMay 7, 2024
Nation-State MITRE Hacked by State-Sponsored Group via Ivanti Zero-Days MITRE R&D network hacked in early January by a state-sponsored threat group that exploited an Ivanti zero-day vulnerability. Eduard KovacsApril 22, 2024
Vulnerabilities CVE and NVD – A Weak and Fractured Source of Vulnerability Truth MITRE is unable to compile a list of all new vulnerabilities, and NIST is unable to subsequently, and consequently, provide an enriched database of... Kevin TownsendApril 3, 2024
Malware & Threats Hunter-Killer Malware Tactic Growing: Stealthy, Persistent and Aggressive A malware tactic dubbed ‘hunter-killer’ is growing, based on an analysis of more than 600,000 malware samples. This may become the standard approach for... Kevin TownsendFebruary 13, 2024
ICS/OT MITRE Unveils EMB3D Threat Model for Embedded Devices Used in Critical Infrastructure MITRE and partners unveil EMB3D, a new threat model designed for critical infrastructure embedded devices. Eduard KovacsDecember 13, 2023