Weekly Intelligence

South African Cyber Threat Intelligence.

Every week we track the ransomware activity, critical CVEs, data breaches and regulatory moves that actually affect South African organisations — then publish what matters, free.

One report a week. No sales spam. Unsubscribe any time.

The archive

Every report we have published.

Each edition is also available as a PDF brief you can circulate internally.

Week 41 Threat Intelligence Report

Weekly Threat Intelligence Report: 27 September – 3 October 2026

The state air navigation operator discloses ransomware-linked malware in airport OT through a tender, INC Ransom lists BCX, and the MIP breach reaches a second insurer through a binder holder.

View Report
Week 40 Threat Intelligence Report

Weekly Threat Intelligence Report: 20 – 26 September 2026

The Information Regulator and Prudential Authority rule that the insurer owes the notification whatever the supplier did and that paying a ransom does not discharge it, while The Gentlemen list a second South African insurer in three weeks.

View Report
Week 39 Threat Intelligence Report

Weekly Threat Intelligence Report: 13 – 19 September 2026

MIP Holdings breach exposes 400,000 records from about 45 insurers and a paid ransom fails to stop publication; RelyComply named as the FICA verification provider behind breaches at six regulated institutions.

View Report
Week 38 Threat Intelligence Report

Weekly Threat Intelligence Report: 6 – 12 September 2026

Bidvest Bank and EasyEquities notify customers over a third-party provider breach, Hollard and VSB Attorneys listed 22 minutes apart, and three vendor advisories contradict the exploitation catalogue.

View Report
Week 37 Threat Intelligence Report

Weekly Threat Intelligence Report: 30 August – 5 September 2026

Rand Water confirms a breach at Africa's largest bulk water utility, the Information Regulator reveals it holds over 8,000 breach notifications, and SonicWall tells customers to re-image rather than patch.

View Report
Week 36 Threat Intelligence Report

Weekly Threat Intelligence Report: 23 – 29 August 2026

The Furniture Bargaining Council publishes its own ransomware notice, the Lengau supercomputer crypto-mining cause reaches Parliament, and AI appears on both sides of the vulnerability.

View Report
Week 35 Threat Intelligence Report

Weekly Threat Intelligence Report: 16 – 22 August 2026

MedusaLocker lists The Courier Guy and the company finds no sign of a breach, Babcock SA is claimed, and nine KEV additions land in five days with six already overdue.

View Report
Week 34 Threat Intelligence Report

Weekly Threat Intelligence Report: 9 – 15 August 2026

LEGO Certified Stores SA is breached two suppliers down the chain through Metabase, Toyota SA through a bulk SMS provider, and Euphoria Telecom directly. Every confirmed incident sat on a supply chain.

View Report
Week 33 Threat Intelligence Report

Weekly Threat Intelligence Report: 2 – 8 August 2026

DC Partner, one of four NCR-accredited payment distribution agencies, confirms a Krybit ransomware attack; Fidelity confirms as RansomHouse publishes; INTERPOL puts SA at 92% of Africa's ransomware detections.

View Report
Week 32 Threat Intelligence Report

Weekly Threat Intelligence Report: 26 July – 2 August 2026

Four South African ransomware victims surface at once led by Fidelity Services Group, while SARS formally confirms that taxpayer phishing is now AI-generated at the peak of filing season.

View Report
Week 31 Threat Intelligence Report

Weekly Threat Intelligence Report: 19 – 26 July 2026

Rectron confirms a DragonForce breach and notifies the Regulator, the SA ransomware tally corrects upward to 115, and two new KEV entries defeat patch-only remediation.

View Report
Week 30 Threat Intelligence Report

Weekly Threat Intelligence Report: 12 – 19 July 2026

South Africa's six-week quiet ends with BE Travel ransomware, a Gauteng jobs portal breach of 283 ID document sets and a nationwide Rectron shutdown, as Microsoft ships 621 CVEs.

View Report
Week 29 Threat Intelligence Report

Weekly Threat Intelligence Report: 5 – 12 July 2026

Six CISA KEV additions in seven days all rated CVSS 9.8 or higher, four of them Joomla extension flaws hitting the SA SME and municipal web stack, while SA breach cost is published at R141.96 billion.

View Report
Week 28 Threat Intelligence Report

Weekly Threat Intelligence Report: 28 June – 5 July 2026

Capitec orders card replacements over the Pick n Pay legacy-app breach, mystery medical-aid breach identified as Profmed via PPSHA with five schemes exposed, Oracle EBS Payments CVSS 9.8 exploited before the KEV.

View Report
Week 27 Threat Intelligence Report

Weekly Threat Intelligence Report: 21–28 June 2026

#OpSouthAfrica hacktivists breach Correctional Services (~11 GB) and Ephraim Mogale Municipality, IR serves 10-day notices on TransUnion and Experian, Standard Bank leak attributed to Prinz Eugen/ROOTBOY publishing 100,000 rows/day.

View Report
Week 26 Threat Intelligence Report

Weekly Threat Intelligence Report: 14–21 June 2026

FortiBleed exposes ~74,000 FortiGate firewalls with plaintext credentials, Splunk Enterprise CVSS 9.8 pre-auth RCE actively exploited, 2026 npm/GitHub supply-chain campaign attributed to a South African operator.

View Report
Week 25 Threat Intelligence Report

Weekly Threat Intelligence Report: 7–14 June 2026

AVBOB knocked offline (350+ branches), record 208-CVE Patch Tuesday led by a wormable kernel RCE, SAPS Western Cape breach exposes 2,978 officers’ medical records, Ivanti Sentry 10.0 weaponised in under 24 hours.

View Report
Week 24 Threat Intelligence Report

Weekly Threat Intelligence Report: 31 May – 7 June 2026

National supercomputer Lengau forced offline by credential breach, ROOTBOY publicly releases full 1.2 TB Standard Bank dataset, NETSCOUT ranks SA #1 globally for DDoS against banking, Cisco SD-WAN takes its 7th zero-day of 2026.

View Report
Week 23 Threat Intelligence Report

Weekly Threat Intelligence Report: 24–31 May 2026

PAN-OS GlobalProtect CVSS 9.3 moves to mass exploitation, Pick n Pay/Bottles breach confirmed under POPIA s.22, first China-APT compromise of a SA university (Webworm), Exchange OWA deadline passes with no patch.

View Report
Week 22 Threat Intelligence Report

Weekly Threat Intelligence Report: 17–24 May 2026

SA ISP ransom-DDoS wave peaks at 676 Gbit/s across 5 providers, Defender OOB patches after 7+ weeks, new CVSS 10.0 cPanel vuln, SA added to Lazarus APT target geography.

View Report
Week 21 Threat Intelligence Report

Weekly Threat Intelligence Report: 10–17 May 2026

SANBS KillSec claim (unverified), Merensky Timber and Sew Treat hit by BlackSuit, SA tally reaches 111, Cisco SD-WAN CVSS 10.0 KEV deadline, Exchange OWA zero-day with no permanent patch.

View Report
Week 20 Threat Intelligence Report

Weekly Threat Intelligence Report: 3–10 May 2026

Standard Bank formally indexed on ransomware.live (108th victim), Ekurhuleni R2 billion billing fraud, ShinyHunters Canvas 12 May deadline threatens 5 SA universities, APT28 SAMA expansion.

View Report
Week 19 Threat Intelligence Report

Weekly Threat Intelligence Report: 27 April – 3 May 2026

Stormous claims CGCSA (151K+ docs, Unilever/Nestlé partner data), SA victim count reaches 107, IR files first major court action against Blouberg Municipality for unpaid POPIA fine.

View Report
Week 18 Threat Intelligence Report

Weekly Threat Intelligence Report: 20–26 April 2026

Standard Bank scope expands to credit cards and passports, XP95 deadlines lapse, Polmed SAPS data goes public, Defender zero-day trio — two still unpatched, Bitwarden CLI supply chain attack.

View Report
Week 17 Threat Intelligence Report

Weekly Threat Intelligence Report: 13–19 April 2026

CRITICAL: Standard Bank 1.2 TB released by ROOTBOY, XP95 deadline arrives, Polmed exposes 100K+ SAPS officers, Adumo POS source code on dark web, Cisco IOS-XE CVSS 9.8 zero-day.

View Report
Week 16 Threat Intelligence Report

Weekly Threat Intelligence Report: 6–12 April 2026

XP95 20 April deadline 7 days away, Salt Typhoon confirms first SA telecom nation-state breach, Krybit claims Megasurf ISP, IR compels dual-entity Liberty/Standard Bank disclosure.

View Report
Week 15 Threat Intelligence Report

Weekly Threat Intelligence Report: March 30 – April 5, 2026

DragonForce pivots to SA healthcare, Windows CLFS zero-day exploited in ransomware chains, and FSCA Joint Standard enforcement begins.

View Report
Week 14 Threat Intelligence Report

Weekly Threat Intelligence Report: March 23 – 29, 2026

LockBit 5.0 resurfaces targeting SA financial institutions, Nightspire escalates infrastructure attacks, and SARB mandates 24-hour incident reporting.

View Report
Week 13 Threat Intelligence Report

Weekly Threat Intelligence Report: March 21 – 27, 2026

Interlock exploits Cisco zero-day for 5 weeks undetected, DragonForce hits SA insurer, and POPIA issues real fines.

View Report
Week 12 Threat Intelligence Report

Weekly Threat Intelligence Report: March 14 – 20, 2026

Threat level escalated to HIGH — SA businesses breached every 3 hours as ransomware and data theft surge.

View Report
Week 11 Threat Intelligence Report

Weekly Threat Intelligence Report: March 07 – 13, 2026

Analysis of regional ransomware spikes and critical CVEs affecting South African infrastructure this week.

View Report