This privacy-safe snapshot describes what CyberTI processed during the 30 days ending 24 July 2026. It measures platform records—not attacks, victims, incidents, or unique threat campaigns.
Executive summary
At the snapshot time, the deployment had 18 configured sources, of which 15 were active: 7 web, 6 forum, and 2 Telegram sources. Source status represents operational configuration, not a judgment of source quality.
Collected signals and indicators
The 225 collected items were recorded between 24 June and 24 July 2026 and came from 13 distinct contributing sources. They produced 1,444 extracted IOC occurrences and 1,239 distinct type-value pairs.
| IOC type | Occurrences |
|---|---|
| URL | 418 |
| IPv4 | 411 |
| 314 | |
| MD5 | 196 |
| Domain | 36 |
| Telegram handle | 32 |
| Telegram URL | 17 |
| FQDN | 15 |
| Other (BTC wallet, CVE, SHA-256) | 5 |
Alert distribution
| Label | Records | Share |
|---|---|---|
| High | 692 | 75.9% |
| Medium | 161 | 17.7% |
| Review | 45 | 4.9% |
| Low | 14 | 1.5% |
Of the 912 alert records, 903 remained in the analyst state new at snapshot time and 9 were marked false positive. The collected-item population also produced 268 item-to-asset match records.
Phishing-candidate pipeline
The separate phishing cohort contained 1,227 candidates first seen during the window. Automated checks found 1,163 resolving in DNS (94.8%), 1,063 reachable over HTTP (86.6%), and 958 with active TLS (78.1%). The same cohort produced 2,360 candidate-to-asset match records.
| Severity | Candidates | Share |
|---|---|---|
| Info | 498 | 40.6% |
| Confirmed | 311 | 25.3% |
| High | 210 | 17.1% |
| Suspicious | 208 | 17.0% |
Methodology and limitations
- Window: records from 24 June 2026 00:00 UTC through a database snapshot at 24 July 2026 15:43:29 UTC.
- Access: read-only SQL aggregation against production tables. No production writes were made.
- Privacy: no raw IOC value, source name, customer identifier, domain, matched term, message content, or analyst identity was extracted for publication.
- Populations: collected items, alerts, and phishing candidates are separate processing populations. Their totals must not be added together.
- IOC counting: an occurrence is an extracted row; the distinct count deduplicates type-value pairs within the window.
- Phishing cohort: candidates are included by their first-seen timestamp. Asset-match counts use that same candidate cohort.
- Interpretation: these are processing records, not estimates of attacks, victims, incidents, prevalence, or unique campaigns.
- Snapshot: statuses can change after the snapshot as enrichment and analyst review continue.