HACK/PROJECT Daily Threat Intelligence
Threat feed live Updated — 24.07.2026 15:36 CET 37 dossiers MITRE ATT&CK mapping

Topic · Threats

Malware and attacks

How cyber threats are classified, and where to find a shared taxonomy.

Dossiers in this section

8 dossiers

The topic in brief

A common language: MITRE ATT&CK

Talking about “viruses” isn't enough. The security community uses MITRE ATT&CK, a public knowledge base cataloguing tactics (the “why” of an attack step) and techniques (the “how”), with stable identifiers. It's the vocabulary advisories and reports use to describe intrusions. In every one of our dossiers, technique IDs are copied from advisories, never inferred.

The threats that actually matter

The ENISA Threat Landscape, the annual report of the EU cybersecurity agency, identifies seven prime threats: attacks on availability, ransomware, threats to data, malware, social engineering, information manipulation, and supply-chain attacks. The 2025 edition analysed 4,875 incidents between July 2024 and June 2025, with a clear trend: different groups reusing tools and techniques.

Defence starts with understanding

Most attacks don't use an exotic technique: they exploit unpatched systems, weak credentials, unnecessary exposure. Recognising threat families and mapping them onto a shared taxonomy is the first step to prioritising defences on what actually happens, not on what makes the biggest headlines.

FAQ

What is MITRE ATT&CK?
A public knowledge base of attack tactics and techniques, with stable identifiers, used as a common language across security advisories.
What are the EU's main threats?
Per the ENISA Threat Landscape: availability, ransomware, threats to data, malware, social engineering, information manipulation, and supply-chain attacks.