Activity timeline
T1587.004 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 36 reports, and 122 of the 122 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1587.004 Exploits is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of T1587 Develop Capabilities. Threadlinqs maps 122 of 2623 tracked threats (4.7%) to it; by severity that is 63 critical, 49 high, 7 medium.
Threats that use T1587.004 most often also use T1190 Exploit Public-Facing Application (76 threats), T1068 Exploitation for Privilege Escalation (61 threats), T1203 Exploitation for Client Execution (55 threats), T1082 System Information Discovery (53 threats), T1588.006 Vulnerabilities (53 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
17 tracked threat actors appear in the threats that use T1587.004; the most frequent are APT28 (2), Hacktron AI (2), Nightmare Eclipse (2), UAT-9686 (2), BlueDelta (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1587.004.
Threat actors using it
Tracked threats
The 30 most recent of 122 tracked threats that use T1587.004.
- GTIG: AI-Era Vulnerability Discovery and Exploitation Surge — In-the-Wild Exploitation of BeyondTrust…critical
- Apple CoreGraphics Out-of-Bounds Write (CVE-2026-86950) Possibly Exploited in Targeted Attackshigh
- Cloudflare Containers Cross-Tenant Data Exposure via Unzeroed Reused Storage Blocks (skip_block_zeroing)high
- Multiple Vulnerabilities in Google Chrome Patched in Stable Channel Update 154.0.8037.57 (GovCERT.HK…medium
- Vulnerability in F5 Products (CVE-2026-42015) — BIG-IP Next CNF, BIG-IP Next for Kubernetes, F5OSmedium
- CVE-2026-94127: Critical F5 BIG-IP APM Zero-Day Heap Overflow in OAuth Authorization Server Exploited for…critical
- BigDiskBuster PoC Blocks Windows Defender Signature/Platform Updates (DoS)medium
- Click2Shell: WordPress Theme-Preview CSRF/Selector-Injection Chain to Forced Theme Installcritical
- F5 BIG-IP DNS Denial of Service via BIND DNSSEC Random Subdomain Attack (CVE-2026-11622)high
- SolarWinds Access Rights Manager Hard-Coded Cryptographic Key (CVE-2026-28326) Enables Unauthenticated RCEcritical
- CISA Flags Three Actively Exploited Linux Kernel Vulnerabilities: kTLS Receive-Path Disclosure/DoS, ebtables…critical
- "LPE Quartet": Public Exploits Released for Four Linux Kernel Local-Root Flaws (DirtyAH6, TUNderflow…high
- AI-Built Exploit Chain Turns Unpatched libheif Flaw and OpenAI Forum Sign-In Bug into Internal Code Accesshigh
- AI-Driven Exploit Chain Against OpenAI Community Forum via libheif Flaw (CVE-2026-32882)high
- CISA Adds Actively Exploited Cisco Secure Email Gateway SQL Injection (CVE-2026-76461) to KEV Catalogcritical
- CVE-2025-37947: Out-of-Bounds Write in Linux ksmbd Kernel SMB Server Enables Local Privilege Escalationhigh
- Nation-State and Financially Motivated Actors Weaponize Claude AI Multi-Agent Frameworks for Automated…critical
- VLC Media Player: Integer Overflow in AllocatePicture (CVE-2026-56711) and RTSP Heap Out-of-Bounds Read…high
- Dutch NCSC Warns of Critical Check Point VPN Flaws (CVE-2026-85102, CVE-2026-85103) — Exploitation Expected…critical
- GitLab Patches Max-Severity Unauthenticated Path Traversal Flaw in Repository Commits API (CVE-2026-85706…critical
- Broadcom Patches Critical VMware Workstation and Fusion VM Escape Vulnerabilities (CVE-2026-59346…critical
- OpenAI GPT-6 Astra Reaches 'Critical' Cybersecurity Capability Threshold; Attempted Supply-Chain Attacks and…critical
- Google Patches Chrome Zero-Day CVE-2026-85046 (6th of 2026), Actively Exploited V8 Type Confusionhigh
- HardBreacher PoC Exploit Targets Kaspersky Endpoint Security Zero-Day for Windows 11 Local Privilege…medium
- Unisoc T612/T606/T7250 Modem Exploit Chain: Malicious VoLTE Video Call Enables Full Android Kernel Access…high
- CVE-2026-53362 ("ipv6_frag_escape"): Linux Kernel IPv6 Fragmentation Flaw Enables Container-to-Host…high
- Cosmos EVM Balance-Handling Flaw (GHSA-7g4w-cg88-2cq2) Actively Exploited Across Six Blockchainscritical
- Suspected Chinese-Speaking Threat Actor Exploits ownCloud and WordPress Flaws to Steal Philippine Nuclear…critical
- Chrome 152.0.7977.64/.65 Fixes Critical V8 Use-After-Free (CVE-2026-78899) and ANGLE RCE (CVE-2026-79282)critical
- Critical Type Confusion in isolated-vm (GHSA-864f-rcv7-6rh4) Enables Sandbox Escape and RCE on Hostcritical
Detection coverage
Threadlinqs maintains 78 detection rules mapped to T1587.004 (SPL 24, KQL 23, Sigma 31). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1587 Develop Capabilities — 402 tracked threats at the technique level.