Digital Progression Full Site
Weekly Intelligence

South Africa Cyber Threat Intelligence

Weekly reports tracking ransomware activity, critical CVEs, data breaches, and regulatory developments affecting South African organisations.

Week 22 2026 Threat Intelligence Report – South Africa

Weekly Threat Intelligence Report: 17–24 May 2026

SA ISP ransom-DDoS wave peaks at 676 Gbit/s across 5 providers, Defender OOB patches after 7+ weeks, new CVSS 10.0 cPanel vuln, SA added to Lazarus APT target geography.

View Report
Week 21 2026 Threat Intelligence Report – South Africa

Weekly Threat Intelligence Report: 10–17 May 2026

SANBS KillSec claim (unverified), Merensky Timber and Sew Treat hit by BlackSuit, SA tally reaches 111, Cisco SD-WAN CVSS 10.0 KEV deadline, Exchange OWA zero-day with no permanent patch.

View Report
Week 20 2026 Threat Intelligence Report – South Africa

Weekly Threat Intelligence Report: 3–10 May 2026

Standard Bank formally indexed on ransomware.live (108th victim), Ekurhuleni R2 billion billing fraud, ShinyHunters Canvas 12 May deadline threatens 5 SA universities, APT28 SAMA expansion.

View Report
Week 19 2026 Threat Intelligence Report – South Africa

Weekly Threat Intelligence Report: 27 April – 3 May 2026

Stormous claims CGCSA (151K+ docs, Unilever/Nestlé partner data), SA victim count reaches 107, IR files first major court action against Blouberg Municipality for unpaid POPIA fine.

View Report
Week 18 2026 Threat Intelligence Report – South Africa

Weekly Threat Intelligence Report: 20–26 April 2026

Standard Bank scope expands to credit cards and passports, XP95 deadlines lapse, Polmed SAPS data goes public, Defender zero-day trio — two still unpatched, Bitwarden CLI supply chain attack.

View Report
Week 17 2026 Threat Intelligence Report – South Africa

Weekly Threat Intelligence Report: 13–19 April 2026

CRITICAL: Standard Bank 1.2 TB released by ROOTBOY, XP95 deadline arrives, Polmed exposes 100K+ SAPS officers, Adumo POS source code on dark web, Cisco IOS-XE CVSS 9.8 zero-day.

View Report
Week 16 2026 Threat Intelligence Report – South Africa

Weekly Threat Intelligence Report: 6–12 April 2026

XP95 20 April deadline 7 days away, Salt Typhoon confirms first SA telecom nation-state breach, Krybit claims Megasurf ISP, IR compels dual-entity Liberty/Standard Bank disclosure.

View Report
Week 15 2026 Threat Intelligence Report – South Africa

Weekly Threat Intelligence Report: March 30 – April 5, 2026

DragonForce pivots to SA healthcare, Windows CLFS zero-day exploited in ransomware chains, and FSCA Joint Standard enforcement begins.

View Report
Week 14 2026 Threat Intelligence Report – South Africa

Weekly Threat Intelligence Report: March 23 – 29, 2026

LockBit 5.0 resurfaces targeting SA financial institutions, Nightspire escalates infrastructure attacks, and SARB mandates 24-hour incident reporting.

View Report
Week 13 2026 Threat Intelligence Report – South Africa

Weekly Threat Intelligence Report: March 21 – 27, 2026

Interlock exploits Cisco zero-day for 5 weeks undetected, DragonForce hits SA insurer, and POPIA issues real fines.

View Report
Week 12 2026 Threat Intelligence Report – South Africa

Weekly Threat Intelligence Report: March 14 – 20, 2026

Threat level escalated to HIGH — SA businesses breached every 3 hours as ransomware and data theft surge.

View Report
Week 11 2026 Threat Intelligence Report – South Africa

Weekly Threat Intelligence Report: March 07 – 13, 2026

Analysis of regional ransomware spikes and critical CVEs affecting South African infrastructure this week.

View Report