DMZ//THREAT INTEL
FEED ACTIVELAST SYNC: 06:39:11ZSOURCES: 14CRITICAL: 30
⚠ ACTIVE ALERTS
MuddyWater (Operation Olalampo — Chaos Ransomware False Flag) CRITICAL — Rapid7 disclosed in May 2026 that MuddyWater (Seedworm) conducted a sophisticated… /// @GossiTheDog CRITICAL — Check Point CVE-2026-50751 CISA KEV deadline is TODAY (June 11). Federal agencies must… /// @MsftSecIntel CRITICAL — We are tracking the Miasma/Hades supply chain campaign (now 471+ artifacts across npm +… /// @FalconFeedsio CRITICAL — 🚨 CROSS-CORRELATED ALERT: XSS.is IAB listings for Check Point VPN access… /// @vxunderground CRITICAL — TheGentlemen ransomware group — second most productive RaaS globally in 2026 per Check…
30Critical Threats
16Active CVEs
4IOCs Tracked
11New Advisories
CLASSIFIED // NEW HERE
DMZ surfaces threats hiding between the headlines.
We correlate signals across underground forums, security researcher posts on X, vendor disclosures, and CISA advisories — then publish what defenders actually need to know. No noise. No engagement bait. Just the threats that matter.
30 REPORTS TODAY

Why I'm Building DMZ

I served nine years in the Navy as an Aviation Boatswain's Mate before I ever touched a SIEM. A year into my first analyst role, I started building DMZ — the threat intel publication I wish existed when I was sitting at my desk a year ago,…

CRITICAL

MuddyWater (Operation Olalampo — Chaos Ransomware False Flag)

Rapid7 disclosed in May 2026 that MuddyWater (Seedworm) conducted a sophisticated false-flag ransomware operation in early 2026, operating under the Chaos RaaS banner while forensic analysis revealed MOIS-linked code-signing certificates…

Added to DMZ2026-06-11
READ →
HIGH

🔥 [SELLING] Check Point IKEv1 VPN Auth Bypass PoC + Working Scanner — CVE-2026-50751

Dropping full working PoC for ████████████ — Check Point Remote Access VPN IKEv1 cert validation logic flaw. Zero creds needed. Tested against ████████████. Scanner included identifies exposed gateways in bulk. Already used in 3 confirmed…

Added to DMZ2026-06-11
READ →
HIGH

[FREE LEAK] Tradeify Full Customer CRM — 240K+ Records via Hardcoded Klaviyo API Key

Exfiltrated full CRM of ████████████ by abusing a Klaviyo private API key hardcoded in client-side JS. ████████████ — full names, emails, phones, physical addresses, purchase history. Finance sector victims. Reply gate for sample. API key…

Added to DMZ2026-06-11
READ →
LOW

Fortinet FortiOS & FortiSwitchManager Missing Authentication in CAPWAP Daemon (FG-IR-26-125)

Fortinet disclosed FG-IR-26-125, a missing authentication for critical function vulnerability (CWE-306) in the FortiOS and FortiSwitchManager CAPWAP daemon that can allow a local unauthenticated attacker on the same IP subnet to write…

Disclosed2026-06-10Added to DMZ2026-06-11
READ →