CTI - Cyber Threat Intelligence
CTI - Cyber Threat Intelligence server banner

CTI - Cyber Threat Intelligence Community Forum

Community Discussions

Transitioning to Cyber Threat Intelligence: Expert Insights

Hi all. I've got 30 years in Military Surveillance, Reconnaissance and Intelligence in the traditional sense, and slid sideways into the civilian cyber world after a few years in SIGINT. After doing some GRC work, I'd prefer to be more pointed and am much more comfortable with being actively involved in intelligence so want to both build my own and help the community to develop some capacity here. I'm long in the tooth but have plenty of fight in me yet.

I'm educated to post-grad level in intelligence, so understand policy and planning, legalities, ethics, and processes in the military, civilian and international communities. Please feel free to get in touch. Any advice or guidance on navigating CTI would be gratefully received.

SharePoint Unauth RCE Chain (CVE-2026-55040 & CVE-2026-63520)

BLUF: Active exploitation is underway targeting on-premises Microsoft SharePoint servers using a chained exploit. By chaining a JWT token authentication bypass (CVE-2026-55040) with a Business Connectivity Services RCE flaw (CVE-2026-63520), attackers can achieve unauthenticated remote code execution.

A public PoC was released on August 12, 2026, and this chain has been added to the CISA KEV list. Exploit attempts have spiked globally.

⚠️ Affected Products:

  • SharePoint Enterprise Server 2016 (< 16.0.5561.1001)
  • SharePoint Server 2019 (< 16.0.10417.20175)
  • SharePoint Server Subscription Edition (< 16.0.19725.20434)

Note: While currently unattributed, related SharePoint campaigns have historically been linked to China-nexus actors like Storm-2603 and APT27.

🔍 The Attack Chain & Behavioral IOCs

There are no static IOCs (IPs, hashes, or domains) reliable for this campaign. Defenders must hunt for the following behavioral chain:

  • Reconnaissance: Attacker enumerates AD SIDs or UPNs (via LDAP, MS Graph, or SharePoint user-picker).
  • Auth Bypass (CVE-2026-55040): Attacker forges a JWT session token to impersonate the targeted user. Look for claims authentication with alg: none or missing issuer validation.
  • Privilege Mapping: Burst enumeration of domain permission groups and SharePoint content repos within 10 minutes of auth.
  • Lateral Movement Staging: Domain trust discovery (LDAP trustedDomain queries) within 1 hour of the forged session.
  • Execution/Persistence (CVE-2026-63520): Outbound HTTP/S to unknown external URLs, or web shell/IIS component deployment on the SharePoint server.

🛠️ Hunting & Detection Rules

1️⃣ JWT Forgery Anomaly (Direct Exploit)

Target Logs: SharePoint STS Audit Logs / ULS Logs

Detection Logic: Filter for ClaimsAuthentication events. Flag any session where the JWT algorithm is explicitly set to none, OR where issuer validation is logged as false or is completely missing/null.

2️⃣ Recon & Auth Chaining (Precondition)

Target Logs: Azure AD Audit Logs / MS Graph + SharePoint STS

Detection Logic: Monitor for an actor performing directory recon (e.g., "Search users", "Get user"). Cross-reference the target of that search with your SharePoint Claims Auth logs. Alert if that specific targeted user successfully authenticates via Claims Auth within 5 minutes of the recon event.

3️⃣ Burst Permission Discovery (Post-Exploitation)

Target Logs: SharePoint ULS Logs

Detection Logic: Baseline your ClaimsAuthentication timestamps. Alert if the authenticated user triggers 5 or more enumeration actions (e.g., GroupMembershipEnum, SiteContentSearch, DocumentLibraryBulkRead) within 10 minutes of their initial login.

🛡️ Patch Immediately: Apply the August 2026 Patch Tuesday updates to all on-prem SharePoint environments.

3 messages

How to Use Vendor Corner | CTI Cyber Threat Intelligence

vendor-corner is the dedicated space for transparent discussion of cybersecurity products, services, vendors, demos, commercial offerings, and vendor-related questions.

Use this forum for things like:

  • Cybersecurity products and platforms
  • Product launches and significant updates
  • Vendor demos and webinars
  • Free trials, resources, or community offers
  • Vendor Q&A
  • Product feedback and user experiences
  • Commercial training or services
  • Community partnerships and sponsorship opportunities

If you work for, represent, receive compensation from, or otherwise have a material relationship with a company or product you’re discussing, clearly disclose your affiliation.

Posts should explain what you’re offering, who it is relevant to, and provide an official website or product link whenever appropriate.

Member safety and trust are our highest priorities:

  • Unsolicited sales or promotional DMs are not permitted.
  • Do not scrape members, harvest leads, or mass-contact community members.
  • Do not require members to DM you for basic product, pricing, or offer information.
  • Do not request passwords, API keys, credentials, financial information, or sensitive organizational data.
  • Do not pressure members to install software, scripts, agents, or browser extensions.
  • Do not disguise affiliate relationships, paid endorsements, sponsorships, or other commercial interests.
  • Do not use misleading claims, deceptive offers, fake testimonials, or high-pressure sales tactics.
  • Use official and clearly identifiable links whenever possible.

Vendors are welcome to participate throughout the broader community when they’re making a genuine contribution. Original threat research may belong in #threat-desk or #research-showcase, and technical methodology discussions may belong in #analyst-workbench—just disclose relevant affiliations.

Purely promotional or commercial content belongs here.

If you receive an unsolicited sales message or encounter suspicious vendor behavior, stop engaging and contact the moderation team.

Collaborate on Cybersecurity Projects | CTI Community Guide

projects-collaboration is where community members can find collaborators, contributors, reviewers, and partners for cybersecurity and CTI projects.

Use this forum for things like:

  • Threat research collaborations
  • Open-source tools and projects
  • Detection and lab projects
  • Research papers and write-ups
  • Conference presentations and CFP reviews
  • Community resources and datasets
  • Beta testing and peer review
  • Finding contributors with specific skills

Tell the community what you’re working on, what kind of help you’re looking for, and what participation would involve.

Be clear about whether the project is volunteer, paid, commercial, academic, open source, or otherwise affiliated with an organization.

For member safety:

  • Do not misrepresent paid or commercial work as a volunteer community project.
  • Clearly disclose compensation or lack of compensation.
  • Never request passwords, credentials, identification documents, financial information, or unnecessary personal data.
  • Do not pressure members to move conversations into DMs or onto unfamiliar platforms.
  • Be transparent about external repositories, tools, software, or files participants may be asked to use.
  • Do not distribute live malware or malicious payloads through project posts.
  • Disclose vendor, employer, academic, or other relevant affiliations.

If a collaboration request seems misleading, unsafe, or suspicious, stop engaging and contact the moderation team.

Completed research, tools, and projects belong in #research-showcase. Methodology and technical discussions belong in #analyst-workbench, while actual employment opportunities belong in #jobs-opportunities.

Find Cybersecurity Conferences & Meetups | CTI Community

conferences-meetup is where community members can discover cybersecurity conferences, meetups, summits, virtual events, and other professional gatherings—and connect with others who are attending.

Share events such as:

  • Cybersecurity and CTI conferences
  • Local security meetups
  • Industry summits
  • Virtual events
  • Community gatherings
  • Calls for papers or speakers
  • CTI community meetups around larger events

Create one post per event and include the event name, date, location or virtual format, and an official event or registration link whenever available.

If you’re an organizer, sponsor, vendor, speaker, or otherwise affiliated with the event, clearly disclose your affiliation.

Use event posts to discuss sessions, share recommendations, see who else is attending, and coordinate community meetups.

For member safety:

  • Meet other members in public event or venue spaces whenever possible.
  • Never feel obligated to meet another member privately.
  • Do not publicly share hotel room numbers, detailed travel plans, phone numbers, home addresses, or other sensitive personal information.
  • Use official registration and ticketing links whenever possible.
  • Be cautious of requests to send money for tickets, travel, lodging, or event access.
  • Unsolicited sales, recruiting, or promotional DMs are not permitted.

If an event or interaction seems suspicious, stop engaging and contact the moderation team.

Research collaborations and community projects belong in #projects-collaboration, while vendor-focused or primarily promotional events belong in #vendor-corner.

Master Cyber Threat Intelligence: Learning & Mentorship Guid

learning-mentorship is where community members can learn from one another, develop their cybersecurity and CTI skills, and connect around professional growth.

Use this forum for things like:

  • Breaking into Cyber Threat Intelligence
  • Mentorship questions and connections
  • Learning resources
  • Certifications and training
  • Study groups
  • Resume and portfolio feedback
  • Interview preparation
  • Career development

Give your post a clear title, select the most relevant tag, and tell the community what you’re hoping to learn, improve, or get help with.

If you’re looking for mentorship, explain what area you’d like guidance in. If you’re willing to mentor others, you’re welcome to offer your experience—but mentorship in this community is voluntary and does not represent an endorsement by the server.

For member safety:

  • No one is required to move a conversation into DMs.
  • Never pressure another member to share personal or sensitive information.
  • Do not request passwords, identification documents, financial information, or other unnecessary private information.
  • Mentorship should never require payment, purchases, gifts, or enrollment in a paid service.
  • Do not promise jobs, referrals, certifications, or guaranteed career outcomes.
  • Commercial coaching, recruiting, courses, and services belong in the appropriate vendor area—not disguised as mentorship.

If another member makes you uncomfortable, pressures you to communicate privately, requests sensitive information, or asks for money, stop engaging and contact the moderation team.

General career conversation belongs in #career-chat, while actual job openings belong in #jobs-opportunities.

Cybersecurity Jobs & Career Opportunities | CTI Community

jobs-opportunities is where community members can share legitimate cybersecurity and CTI job openings, internships, contracts, and other professional opportunities.

Member safety is our highest priority. Job posts should be transparent, verifiable, and give members enough information to evaluate an opportunity without needing to contact someone privately.

Share opportunities such as:

  • Cyber Threat Intelligence
  • SOC / DFIR
  • Detection Engineering and Threat Hunting
  • Malware and Security Research
  • Security Engineering
  • Cybersecurity leadership
  • Internships and early-career positions
  • Relevant contract opportunities

When posting an opportunity, include the company, position title, location/work arrangement, employment type, experience level, and official application link whenever available.

If you work for the employer, are the hiring manager, or are acting as a recruiter, clearly disclose your affiliation. If you’re simply sharing a position you found, feel free to state “No affiliation — sharing with the community.”

For the safety of our members:

  • Do not post opportunities that require members to DM you for basic job details or an application link.
  • Use an official employer or reputable recruiting application page whenever possible.
  • Do not request resumes, personal information, credentials, identification documents, financial information, or other sensitive information through Discord.
  • Do not charge application, recruiting, training, equipment, background-check, or other upfront fees.
  • Do not use misleading, shortened, disguised, or suspicious application links.
  • Do not engage in resume harvesting, mass recruiting, unsolicited recruitment DMs, or scraping member information.
  • Do not post deceptive opportunities, pyramid/MLM schemes, questionable commission-only offers, or roles that misrepresent the employer or nature of the work.

Members should independently verify an employer and opportunity before providing personal information or applying. If something about a listing or recruiter seems suspicious, do not engage—report it to the moderation team so we can review it.

When a position is no longer available, update the post with the Closed tag.

Career questions and advice belong in #career-chat, while mentorship, résumé help, learning resources, and breaking into CTI belong in #learning-mentorship.

Join the CTI Community: Introduce Yourself Today

introductions is where new and existing community members can introduce themselves and get to know the people behind the usernames.

Share whatever you’re comfortable with, such as:

  • Your preferred name or handle
  • Your cybersecurity background
  • Areas of CTI that interest you
  • What you’re hoping to learn
  • Topics you can help others with
  • Projects, research, or interests you’d like to share

There’s no required format and no need to share personal information such as your employer, real name, or location.

Give your post a simple title and tell us as much or as little as you’d like.

Take a moment to welcome other members, ask questions, and connect with people who share your interests.

For general conversation, head to #general-cti. Quick CTI questions belong in #ask-cti, and deeper technical discussions belong in #analyst-workbench.

How to Use Threat Desk: CTI Community Guide

threat-desk is where community members can discuss significant developments across the threat landscape.

Share and discuss things like:

  • Active campaigns and emerging threats
  • Threat actor activity
  • Malware operations
  • Ransomware and cybercrime
  • Vulnerability exploitation
  • Cloud and identity threats
  • Supply-chain activity
  • Notable threat intelligence reports

Tell us what happened, why it matters, and include a source when available.

Give your post a clear, descriptive title and select the most relevant tag. Avoid dropping links without context—briefly explain why the information is worth discussing.

Keep discussions appropriate for TLP:CLEAR. Defang potentially malicious URLs or domains when needed, and do not upload live malware or restricted information.

Specific requests for research or intelligence assistance belong in #intel-requests, and methodology, tooling, or analyst tradecraft discussions belong in #analyst-workbench.

How to Use Intel Requests | CTI Community Guide

intel-requests is where community members can request help answering a specific intelligence question or finding information related to something they’re researching.

Request help with things like:

  • Threat actor or campaign information
  • Infrastructure and IOC context
  • Historical reporting and sources
  • Malware information
  • Attribution and OSINT research
  • Detection and hunting information
  • Connections between related activity
  • Help validating an analytical finding

Tell us what you’re trying to determine, provide any useful context, and share what you’ve already found or checked when relevant.

Select the Open tag and the most relevant request type when posting. Once you’ve received what you need, update the request to Resolved.

Keep requests appropriate for TLP:CLEAR discussion and do not share confidential, client, employer, victim, or otherwise restricted information.

Current threat discussions belong in #threat-desk, and methodology, tooling, or analytical tradecraft discussions belong in #analyst-workbench.