CyberTI Research · July 2026

CyberTI threat signal snapshot: 24 July 2026

An anonymized 30-day snapshot of signals, indicators, alerts, and phishing candidates processed by CyberTI, with methodology and limitations.

This privacy-safe snapshot describes what CyberTI processed during the 30 days ending 24 July 2026. It measures platform records—not attacks, victims, incidents, or unique threat campaigns.

Executive summary

225Collected items from 13 contributing sources
1,444Extracted IOC occurrences
912Alert records created
1,227Phishing candidates first seen in-window

At the snapshot time, the deployment had 18 configured sources, of which 15 were active: 7 web, 6 forum, and 2 Telegram sources. Source status represents operational configuration, not a judgment of source quality.

Collected signals and indicators

The 225 collected items were recorded between 24 June and 24 July 2026 and came from 13 distinct contributing sources. They produced 1,444 extracted IOC occurrences and 1,239 distinct type-value pairs.

Extracted IOC occurrences by type
IOC typeOccurrences
URL418
IPv4411
Email314
MD5196
Domain36
Telegram handle32
Telegram URL17
FQDN15
Other (BTC wallet, CVE, SHA-256)5

Alert distribution

Alert records by severity or queue label
LabelRecordsShare
High69275.9%
Medium16117.7%
Review454.9%
Low141.5%

Of the 912 alert records, 903 remained in the analyst state new at snapshot time and 9 were marked false positive. The collected-item population also produced 268 item-to-asset match records.

Phishing-candidate pipeline

The separate phishing cohort contained 1,227 candidates first seen during the window. Automated checks found 1,163 resolving in DNS (94.8%), 1,063 reachable over HTTP (86.6%), and 958 with active TLS (78.1%). The same cohort produced 2,360 candidate-to-asset match records.

Phishing candidates by recorded severity
SeverityCandidatesShare
Info49840.6%
Confirmed31125.3%
High21017.1%
Suspicious20817.0%

Methodology and limitations

  • Window: records from 24 June 2026 00:00 UTC through a database snapshot at 24 July 2026 15:43:29 UTC.
  • Access: read-only SQL aggregation against production tables. No production writes were made.
  • Privacy: no raw IOC value, source name, customer identifier, domain, matched term, message content, or analyst identity was extracted for publication.
  • Populations: collected items, alerts, and phishing candidates are separate processing populations. Their totals must not be added together.
  • IOC counting: an occurrence is an extracted row; the distinct count deduplicates type-value pairs within the window.
  • Phishing cohort: candidates are included by their first-seen timestamp. Asset-match counts use that same candidate cohort.
  • Interpretation: these are processing records, not estimates of attacks, victims, incidents, prevalence, or unique campaigns.
  • Snapshot: statuses can change after the snapshot as enrichment and analyst review continue.
Reproducibility boundaryThe exact aggregates can be reproduced internally from the stated window and cohort definitions. The underlying records remain private, so external readers cannot independently reconstruct row-level results.