Product updates

KEVDétection

New ThreatClaw Detections: Exploited CVEs in VMware, SharePoint & MLflow

This week, ThreatClaw expands coverage for 8 newly exploited CVEs, including critical flaws in VMware vCenter, Microsoft SharePoint, and MLflow. Learn why these matter.

NIS2ReCyFComplianceOSCAL

Your detection rules, mapped to NIS2 and ReCyF

Every ThreatClaw feed subscription now ships with a per-requirement coverage map for NIS2 and ReCyF, an OSCAL export, and a connector that pre-fills your GRC. Here is exactly how it works, and what it does not claim.

T1003.002T1003.004KEVDétection

New ThreatClaw Detections: Linux & Windows Persistence, 4 Exploited CVEs

This week, ThreatClaw expands coverage with 51 new Sigma rules targeting Linux/macOS/Windows persistence, plus 4 actively exploited CVEs in Cisco, Microsoft, Metabase, and Progress LoadMaster.

ReleaseYARARansomwareThreat Detection

New Coverage: 51 Fresh Malware Families in the ThreatClaw YARA Feed

The August rule release adds 51 new malware families to the YARA feed, forged from live in-the-wild samples, every rule compile-validated on the real engine with zero false positives on a benign corpus.

YARADetectionPrometeiWannaCryEternalBlueSpyNoteGhostNFCRansomwareAndroidLinuxThreat Intelligence

YARA Summer Pack: 72 malware families covered this summer (Prometei, WannaCry, SpyNote…)

From June to August 2026, ThreatClaw forged 72 new malware families into its YARA feed: Prometei, WannaCry, EternalBlue, GhostNFC, SpyNote, Mamont, Neshta… each tested against 5,694 legitimate binaries, zero false positives.

T1566.002KEVDétection

New Detection: Brand Spoofing Surge & 6 Exploited CVEs in SMB

ThreatClaw expands coverage with 67 new rules targeting brand impersonation (T1566.002) and 6 actively exploited CVEs in Check Point, SharePoint, and WordPress.

YARADetectionPrometeiLinux BotnetThreat Intelligence

14 new malware families covered: the June YARA batch

Prometei botnet on Linux, Windows code injection, Office macros, Android, downloaders. ThreatClaw adds 14 fresh malware families to its YARA feed, 391 rules, tested against 5,694 legitimate binaries with zero false positives.

KEVDétection

New ThreatClaw Coverage: Exploited CVEs in SharePoint, Fortinet & Oracle

This week, ThreatClaw expands detection for 12 newly exploited CVEs, including critical flaws in Microsoft SharePoint, Fortinet FortiSandbox, and Oracle E-Business Suite.

T1542.001KEVDétection

New ThreatClaw Detections: Exploited CMS Flaws & Firmware Risks

This week, ThreatClaw expands coverage for actively exploited CMS vulnerabilities (CVE-2026-48908, CVE-2026-56290) and suspicious firmware updates (T1542.001), hardening defenses against supply-chain attacks.

T1003T1003.001KEVDétection

New ThreatClaw Detections: Exploited CVEs & Advanced Web Threats

This week’s update expands coverage for 20+ exploited CVEs, critical web vulnerabilities, and 20+ malware families, hardening defenses against initial access and persistence threats.

T1003T1003.001KEVDétection

New ThreatClaw Coverage: Exploited CVEs, Ransomware Evasion & BYOVD Risks

This week’s ThreatClaw update expands detection for 4 exploited CVEs, ransomware staging techniques, BYOVD attacks, and 258 new Sigma rules targeting enterprise threats.