type,value,subtype,comment,link,relevance external-report-link,https://bsky.app/profile/newsarea.bsky.social/post/3mr3fmmrewj24,post-link,Link to the post,https://bsky.app/profile/newsarea.bsky.social/post/3mr3fmmrewj24,100 external-report-link,https://bsky.app/profile/ninjaowl.ai/post/3mr47nkbhjy2g,post-link,Link to the post,https://bsky.app/profile/ninjaowl.ai/post/3mr47nkbhjy2g,100 external-report-link,https://bsky.app/profile/undercodenews.bsky.social/post/3mr5wnc2eqj2z,post-link,Link to the post,https://bsky.app/profile/undercodenews.bsky.social/post/3mr5wnc2eqj2z,100 external-report-link,https://bsky.app/profile/undercodenews.bsky.social/post/3mr5wkwjkvn2d,post-link,Link to the post,https://bsky.app/profile/undercodenews.bsky.social/post/3mr5wkwjkvn2d,100 domain,ecrime.ch,,Domain hosting the report about the RansomHouse ransomware/datatheft group's claim against Nichirei Corp.,https://bsky.app/profile/ecrime.ch/post/3mr5xaql3gf2g,100 url,https://ecrime.ch,,URL linking to the report about the RansomHouse ransomware/datatheft group's claim against Nichirei Corp.,https://bsky.app/profile/ecrime.ch/post/3mr5xaql3gf2g,100 external-report-link,https://bsky.app/profile/ecrime.ch/post/3mr5xaql3gf2g,post-link,Link to the post,https://bsky.app/profile/ecrime.ch/post/3mr5xaql3gf2g,100 domain,thehackernews.com,,Domain extracted from the URL in the text,https://bsky.app/profile/ninjaowl.ai/post/3mr6zbe7end27,100 url,hxxp://thehackernews[.]com/20...,,Defanged URL extracted from the text,https://bsky.app/profile/ninjaowl.ai/post/3mr6zbe7end27,100 external-report-link,https://bsky.app/profile/ninjaowl.ai/post/3mr6zbe7end27,post-link,Link to the post,https://bsky.app/profile/ninjaowl.ai/post/3mr6zbe7end27,100 external-report-link,https://bsky.app/profile/bhaveshverma.com/post/3mr7rnqczz22k,post-link,Link to the post,https://bsky.app/profile/bhaveshverma.com/post/3mr7rnqczz22k,100 url,https://www.wired.com/story/foxconn-ransomware-attack-shows-nothing-is-safe-forever/,,Article discussing Foxconn's ransomware attack and cybersecurity implications.,https://bsky.app/profile/sagabreakfast.bsky.social/post/3mrcsdmknvr2o,100 external-report-link,https://bsky.app/profile/sagabreakfast.bsky.social/post/3mrcsdmknvr2o,post-link,Link to the post,https://bsky.app/profile/sagabreakfast.bsky.social/post/3mrcsdmknvr2o,100 url,https://ift.tt/xKtGioY,,Chaos ransomware msaRAT article URL,https://t.me/c/1177932374/21076,100 url,https://ift.tt/TeIfw3V,,Reddit discussion link about the article,https://t.me/c/1177932374/21076,100 username,@blueteamalerts,,Twitter handle mentioned in the text,https://t.me/c/1177932374/21076,100 external-report-link,https://t.me/c/1177932374/21076,post-link,Link to the post,https://t.me/c/1177932374/21076,100 domain,cyberwald.com,,Domain mentioned in the podcast link.,https://social.tchncs.de/@cyberwald/116973406962300114,100 url,https://cyberwald.com/podcast/2026-07-24.podcast.ogg,,Podcast URL provided in the text.,https://social.tchncs.de/@cyberwald/116973406962300114,100 vulnerability,CVE-2026-64600,,Referenced Linux Root-Lücke.,https://social.tchncs.de/@cyberwald/116973406962300114,100 vulnerability,CVE-2026-16232,,Referenced Check Point SmartConsole vulnerability.,https://social.tchncs.de/@cyberwald/116973406962300114,100 external-report-link,https://social.tchncs.de/@cyberwald/116973406962300114,post-link,Link to the post,https://social.tchncs.de/@cyberwald/116973406962300114,100 threat-actor,Clop,,Clop ransomware gang name,https://bsky.app/profile/hacker.at.thenote.app/post/3mrh7wovrrc2a,100 threat-actor,Cl0p,,Alternative tracking name for Clop ransomware gang,https://bsky.app/profile/hacker.at.thenote.app/post/3mrh7wovrrc2a,100 external-report-link,https://bsky.app/profile/hacker.at.thenote.app/post/3mrh7wovrrc2a,post-link,Link to the post,https://bsky.app/profile/hacker.at.thenote.app/post/3mrh7wovrrc2a,100 external-report-link,https://otx.alienvault.com/pulse/6a636223b470c7200c1cfac1,external-article,Pulse link containing details about the msaRAT ransomware activity,https://social.raytec.co/@techbot/116975086404545944,100 username,cryptocti,,Pulse author associated with the msaRAT ransomware activity,https://social.raytec.co/@techbot/116975086404545944,100 browser-extension-id,Chrome,,Headless browser used for C2 communications by msaRAT,https://social.raytec.co/@techbot/116975086404545944,100 browser-extension-id,Edge,,Headless browser used for C2 communications by msaRAT,https://social.raytec.co/@techbot/116975086404545944,100 external-report-link,https://social.raytec.co/@techbot/116975086404545944,post-link,Link to the post,https://social.raytec.co/@techbot/116975086404545944,100 domain,www.bleepingcomputer.com,,Domain from the provided URL,https://mastodon.social/@gtbarry/116975081792289798,100 threat-actor,Everest,,Name of the ransomware gang mentioned,https://mastodon.social/@gtbarry/116975081792289798,100 username,Stadler Rail,,Name of the company mentioned in the attack,https://mastodon.social/@gtbarry/116975081792289798,100 external-report-link,https://mastodon.social/@gtbarry/116975081792289798,post-link,Link to the post,https://mastodon.social/@gtbarry/116975081792289798,100 external-report-link,https://bsky.app/profile/undercodenews.bsky.social/post/3mrhhh65fdt2d,post-link,Link to the post,https://bsky.app/profile/undercodenews.bsky.social/post/3mrhhh65fdt2d,100 domain,insicurezzadigitale.com,,Domain hosting the blog about Funky Mantis and DevMan ransomware gang.,https://bsky.app/profile/nuke86.rfeed.it/post/3mrjy53bfxv24,100 url,http://insicurezzadigitale.com/funky-mantis,,URL of the blog post discussing Funky Mantis and DevMan ransomware gang.,https://bsky.app/profile/nuke86.rfeed.it/post/3mrjy53bfxv24,100 external-report-link,https://bsky.app/profile/nuke86.rfeed.it/post/3mrjy53bfxv24,post-link,Link to the post,https://bsky.app/profile/nuke86.rfeed.it/post/3mrjy53bfxv24,100 domain,insicurezzadigitale.com,,Domain hosting the blog article about UNC6692's tradecraft,https://bsky.app/profile/nuke86.rfeed.it/post/3mrk4q2dk442r,100 threat-actor,UNC6692,,Attributed threat actor mentioned in the blog title,https://bsky.app/profile/nuke86.rfeed.it/post/3mrk4q2dk442r,100 external-report-link,https://bsky.app/profile/nuke86.rfeed.it/post/3mrk4q2dk442r,post-link,Link to the post,https://bsky.app/profile/nuke86.rfeed.it/post/3mrk4q2dk442r,100 external-report-link,https://bsky.app/profile/undercodenews.bsky.social/post/3mrk6afuevd2f,post-link,Link to the post,https://bsky.app/profile/undercodenews.bsky.social/post/3mrk6afuevd2f,100 domain,takethehop.com,,Domain associated with the IncRansom ransomware attack on Texas regional transit network.,https://bsky.app/profile/cerberusit.bsky.social/post/3mrmrpjq3q52q,100 threat-actor,IncRansom,,Ransomware group that claimed the attack.,https://bsky.app/profile/cerberusit.bsky.social/post/3mrmrpjq3q52q,100 external-report-link,https://bsky.app/profile/cerberusit.bsky.social/post/3mrmrpjq3q52q,post-link,Link to the post,https://bsky.app/profile/cerberusit.bsky.social/post/3mrmrpjq3q52q,100 external-report-link,https://bsky.app/profile/richardfreiberg.bsky.social/post/3mrmqvvdv2s2m,post-link,Link to the post,https://bsky.app/profile/richardfreiberg.bsky.social/post/3mrmqvvdv2s2m,100 domain,ecrime.ch,,Domain hosting the report about the Qilin ransomware/data theft group targeting Savills SASU.,https://bsky.app/profile/ecrime.ch/post/3mrmqt7xriu27,100 url,https://ecrime.ch,,URL linking to the report about the Qilin ransomware/data theft group targeting Savills SASU.,https://bsky.app/profile/ecrime.ch/post/3mrmqt7xriu27,100 external-report-link,https://bsky.app/profile/ecrime.ch/post/3mrmqt7xriu27,post-link,Link to the post,https://bsky.app/profile/ecrime.ch/post/3mrmqt7xriu27,100 domain,www.bleepingcomputer.com,,Source article domain,https://bsky.app/profile/thenewoil.org/post/3mqugppgo7qv2,90 url,hxxp://www[.]bleepingcomputer[.]com/news/security/coca-cola-says-fairlife-ransomware-attack-halts-us-dairy-production/,,Source article URL (defanged),https://bsky.app/profile/thenewoil.org/post/3mqugppgo7qv2,90 external-report-link,https://bsky.app/profile/thenewoil.org/post/3mqugppgo7qv2,post-link,Link to the post,https://bsky.app/profile/thenewoil.org/post/3mqugppgo7qv2,90 external-report-link,https://bsky.app/profile/kotosecurity.bsky.social/post/3mqunkpi2mb2u,post-link,Link to the post,https://bsky.app/profile/kotosecurity.bsky.social/post/3mqunkpi2mb2u,90 domain,ecrime.ch,,Domain hosting the report about the DragonForce ransomware/datatheft group's claim against NewNet S.A.,https://bsky.app/profile/ecrime.ch/post/3mqwd2pgbcp2s,90 url,https://ecrime.ch,,URL linking to the report about the DragonForce ransomware/datatheft group's claim against NewNet S.A.,https://bsky.app/profile/ecrime.ch/post/3mqwd2pgbcp2s,90 external-report-link,https://bsky.app/profile/ecrime.ch/post/3mqwd2pgbcp2s,post-link,Link to the post,https://bsky.app/profile/ecrime.ch/post/3mqwd2pgbcp2s,90 domain,ecrime.ch,,Domain hosting the report about the LockBit 5.0 ransomware/data theft claim.,https://bsky.app/profile/ecrime.ch/post/3mqwd2ojoba2g,90 url,https://ecrime.ch,,URL linking to the report about the LockBit 5.0 ransomware/data theft claim.,https://bsky.app/profile/ecrime.ch/post/3mqwd2ojoba2g,90 external-report-link,https://bsky.app/profile/ecrime.ch/post/3mqwd2ojoba2g,post-link,Link to the post,https://bsky.app/profile/ecrime.ch/post/3mqwd2ojoba2g,90 domain,ecrime.ch,,Domain hosting the report about LockBit 5.0 ransomware/datatheft group targeting Adventus Pte. Ltd.,https://bsky.app/profile/ecrime.ch/post/3mqwd2noxv72a,90 url,https://ecrime.ch,,URL linking to the report about LockBit 5.0 ransomware/datatheft group targeting Adventus Pte. Ltd.,https://bsky.app/profile/ecrime.ch/post/3mqwd2noxv72a,90 external-report-link,https://bsky.app/profile/ecrime.ch/post/3mqwd2noxv72a,post-link,Link to the post,https://bsky.app/profile/ecrime.ch/post/3mqwd2noxv72a,90 url,https://ecrime.ch/,,Link to the external report about the ransomware/datatheft group LockBit 5.0 claim.,https://bsky.app/profile/ecrime.ch/post/3mqwcrnwd3o27,90 threat-actor,LockBit5.0,,Ransomware/datatheft group mentioned in the claim.,https://bsky.app/profile/ecrime.ch/post/3mqwcrnwd3o27,90 username,Pioneer Coldstore & Cladding Pvt. Ltd.,,Organization name mentioned in the claim.,https://bsky.app/profile/ecrime.ch/post/3mqwcrnwd3o27,90 external-report-link,https://bsky.app/profile/ecrime.ch/post/3mqwcrnwd3o27,post-link,Link to the post,https://bsky.app/profile/ecrime.ch/post/3mqwcrnwd3o27,90 domain,ecrime.ch,,Domain hosting the report about the LockBit 5.0 ransomware/data theft claim.,https://bsky.app/profile/ecrime.ch/post/3mqwcrn3bve2b,90 url,https://ecrime.ch,,URL linking to the report about the LockBit 5.0 ransomware/data theft claim.,https://bsky.app/profile/ecrime.ch/post/3mqwcrn3bve2b,90 external-report-link,https://bsky.app/profile/ecrime.ch/post/3mqwcrn3bve2b,post-link,Link to the post,https://bsky.app/profile/ecrime.ch/post/3mqwcrn3bve2b,90 domain,ecrime.ch,,Domain hosting the report about the LockBit 5.0 ransomware/datatheft group claim.,https://bsky.app/profile/ecrime.ch/post/3mqwcrm7l6w2q,90 url,https://ecrime.ch,,URL linking to the report about the LockBit 5.0 ransomware/datatheft group claim.,https://bsky.app/profile/ecrime.ch/post/3mqwcrm7l6w2q,90 external-report-link,https://bsky.app/profile/ecrime.ch/post/3mqwcrm7l6w2q,post-link,Link to the post,https://bsky.app/profile/ecrime.ch/post/3mqwcrm7l6w2q,90 url,https://ecrime.ch/,,Link to the external report about the ransomware/datatheft group LockBit 5.0 and the claimed attack on Micropack S.A.,https://bsky.app/profile/ecrime.ch/post/3mqwcin24kb2g,90 threat-actor,LockBit5.0,,Name of the ransomware/datatheft group claiming the attack.,https://bsky.app/profile/ecrime.ch/post/3mqwcin24kb2g,90 username,Micropack S.A.,,Organization name mentioned in the claim.,https://bsky.app/profile/ecrime.ch/post/3mqwcin24kb2g,90 external-report-link,https://bsky.app/profile/ecrime.ch/post/3mqwcin24kb2g,post-link,Link to the post,https://bsky.app/profile/ecrime.ch/post/3mqwcin24kb2g,90 domain,intel.threadlinqs.com,,Domain from the provided threat intelligence link,https://mastodon.social/@threadlinqs/116935905990302882,90 vulnerability,CVE-2025-7771,,CVE associated with Qilin Ransomware,https://mastodon.social/@threadlinqs/116935905990302882,90 threat-actor,AgendaCrypt,,Ransomware family mentioned in the context,https://mastodon.social/@threadlinqs/116935905990302882,90 threat-actor,Gentlemen,,Ransomware family mentioned in the context,https://mastodon.social/@threadlinqs/116935905990302882,90 threat-actor,MedusaLocker,,Ransomware family mentioned in the context,https://mastodon.social/@threadlinqs/116935905990302882,90 threat-actor,Qilin,,Ransomware family mentioned in the context,https://mastodon.social/@threadlinqs/116935905990302882,90 external-report-link,https://mastodon.social/@threadlinqs/116935905990302882,post-link,Link to the post,https://mastodon.social/@threadlinqs/116935905990302882,90 external-report-link,https://otx.alienvault.com/pulse/6a5da9de7880be3a0bc9f970,external-article,Link to the AlienVault OTX Pulse for the Spirals ransomware campaign.,https://social.raytec.co/@techbot/116950596218040788,90 username,Tr1sa111,,Pulse author or threat actor username.,https://social.raytec.co/@techbot/116950596218040788,90 external-report-link,https://social.raytec.co/@techbot/116950596218040788,post-link,Link to the post,https://social.raytec.co/@techbot/116950596218040788,90 external-report-link,https://bsky.app/profile/cti.fyi/post/3mrhjblcayh2o,post-link,Link to the post,https://bsky.app/profile/cti.fyi/post/3mrhjblcayh2o,85 external-report-link,https://bsky.app/profile/digitfyi.bsky.social/post/3mrhha6tx6n2l,post-link,Link to the post,https://bsky.app/profile/digitfyi.bsky.social/post/3mrhha6tx6n2l,85 external-report-link,https://bsky.app/profile/intelfusions.com/post/3mrjyw5bhco2m,post-link,Link to the post,https://bsky.app/profile/intelfusions.com/post/3mrjyw5bhco2m,85 url,https://cti.fyi/groups/securotrop.html,,Group blog post link mentioning Securotrop ransomware group,https://infosec.exchange/@CTI_FYI/116978709528287501,85 threat-actor,securotrop,,Name of the ransomware group,https://infosec.exchange/@CTI_FYI/116978709528287501,85 external-report-link,https://infosec.exchange/@CTI_FYI/116978709528287501,post-link,Link to the post,https://infosec.exchange/@CTI_FYI/116978709528287501,85 external-report-link,https://bsky.app/profile/hendryadrian.bsky.social/post/3mrk5l542ww2m,post-link,Link to the post,https://bsky.app/profile/hendryadrian.bsky.social/post/3mrk5l542ww2m,85 threat-actor,Deadlock,,Name of the ransomware group claimed to be behind the attack.,https://bsky.app/profile/hendryadrian.bsky.social/post/3mrk4qcy2qp2j,85 filename,tramex grilles,,Product type mentioned in the context of the attack.,https://bsky.app/profile/hendryadrian.bsky.social/post/3mrk4qcy2qp2j,85 external-report-link,https://bsky.app/profile/hendryadrian.bsky.social/post/3mrk4qcy2qp2j,post-link,Link to the post,https://bsky.app/profile/hendryadrian.bsky.social/post/3mrk4qcy2qp2j,85 threat-actor,Deadlock ransomware,,Likely refers to the Deadlock ransomware group or strain mentioned in the context of the attack.,https://bsky.app/profile/hendryadrian.bsky.social/post/3mrk3vhcrup2j,85 domain,carrierab.se,,Swedish transport and logistics company targeted in the attack.,https://bsky.app/profile/hendryadrian.bsky.social/post/3mrk3vhcrup2j,85 domain,jordbro.se,,Location of the targeted company.,https://bsky.app/profile/hendryadrian.bsky.social/post/3mrk3vhcrup2j,85 domain,stockholm.se,,"Capital city of Sweden, contextually relevant to the attack.",https://bsky.app/profile/hendryadrian.bsky.social/post/3mrk3vhcrup2j,85 external-report-link,https://bsky.app/profile/hendryadrian.bsky.social/post/3mrk3vhcrup2j,post-link,Link to the post,https://bsky.app/profile/hendryadrian.bsky.social/post/3mrk3vhcrup2j,85 domain,cyberthreats247.com,,Domain mentioned in the article as the source for further reading,https://bsky.app/profile/cyberthreats.bsky.social/post/3mrmsakrsbs2e,85 threat-actor,Anubis,,Name of the ransomware group responsible for the attack,https://bsky.app/profile/cyberthreats.bsky.social/post/3mrmsakrsbs2e,85 external-report-link,https://bsky.app/profile/cyberthreats.bsky.social/post/3mrmsakrsbs2e,post-link,Link to the post,https://bsky.app/profile/cyberthreats.bsky.social/post/3mrmsakrsbs2e,85 domain,cti.fyi,,Domain extracted from the provided URLs related to the ransom group 'genesis'.,https://infosec.exchange/@CTI_FYI/116988828814892222,85 url,https://cti.fyi/groups/genesis.html,,URL pointing to the ransom group 'genesis' blog posts.,https://infosec.exchange/@CTI_FYI/116988828814892222,85 external-report-link,https://infosec.exchange/@CTI_FYI/116988828814892222,post-link,Link to the post,https://infosec.exchange/@CTI_FYI/116988828814892222,85