Activity timeline
T1588.006 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-08 with 46 reports, and 125 of the 125 threats were reported in the twelve months to 2026-10.
How adversaries use it
T1588.006 Vulnerabilities is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of T1588 Obtain Capabilities. Threadlinqs maps 125 of 2623 tracked threats (4.8%) to it; by severity that is 69 critical, 38 high, 12 medium.
Threats that use T1588.006 most often also use T1190 Exploit Public-Facing Application (86 threats), T1595.002 Vulnerability Scanning (66 threats), T1587.004 Exploits (53 threats), T1588.005 Exploits (53 threats), T1068 Exploitation for Privilege Escalation (52 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
8 tracked threat actors appear in the threats that use T1588.006; the most frequent are Cl0p (2), Nightmare Eclipse (2), Chaotic Eclipse (1), Hacktron AI (1), Intellexa Consortium (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1588.006.
Threat actors using it
Tracked threats
The 30 most recent of 125 tracked threats that use T1588.006.
- Desktop AI Supercomputers, Uncensored Models and Agentic Frameworks (HexStrike-AI) Enable Automated…high
- Apple CoreGraphics Out-of-Bounds Write (CVE-2026-86950) Possibly Exploited in Targeted Attackshigh
- CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalogcritical
- Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)critical
- Two Unpatched Citrix NetScaler ADC/Gateway RCE Zero-Days Under Active Exploitationcritical
- Check Point Security Gateway VPN Pre-Auth RCE (CVE-2026-85102) and Management Path Traversal Zero-Day…critical
- Multiple Vulnerabilities in Google Chrome Patched in Stable Channel Update 154.0.8037.57 (GovCERT.HK…medium
- Microsoft Office / Microsoft 365 Apps for Enterprise Remote Code Execution Vulnerability (CVE-2026-70125)high
- CISA Adds Actively Exploited WSO2 API Manager and Adobe Commerce Flaws to KEV Catalog, Warns on SharePoint…critical
- Multiple PHP Vulnerabilities Enable Denial of Service, TLS Verification Bypass, and Credential Leakage…medium
- Vulnerability in F5 Products (CVE-2026-42015) — BIG-IP Next CNF, BIG-IP Next for Kubernetes, F5OSmedium
- CVE-2026-94127: Critical F5 BIG-IP APM Zero-Day Heap Overflow in OAuth Authorization Server Exploited for…critical
- CVE-2026-87902: Critical Unauthenticated Local File Inclusion in WordPress Core (Conditional RCE)critical
- ShinyHunters Claims FBI Breach via Unpatched Oracle PeopleSoft Zero-Day, Threatens 2-3TB of PII/PHI Leakcritical
- Click2Shell: WordPress Theme-Preview CSRF/Selector-Injection Chain to Forced Theme Installcritical
- F5 BIG-IP DNS Denial of Service via BIND DNSSEC Random Subdomain Attack (CVE-2026-11622)high
- SolarWinds Access Rights Manager Hard-Coded Cryptographic Key (CVE-2026-28326) Enables Unauthenticated RCEcritical
- CISA Flags Three Actively Exploited Linux Kernel Vulnerabilities: kTLS Receive-Path Disclosure/DoS, ebtables…critical
- Critical Pre-Auth RCE in Orkes Conductor Workflow Platform (CVE-2026-58138) Exploited in the Wildcritical
- AI-Driven Exploit Chain Against OpenAI Community Forum via libheif Flaw (CVE-2026-32882)high
- CVE-2026-87886: Actively Exploited Privilege Escalation Flaw in Acronis cPanel Backup Pluginhigh
- Red Heron Weaponizes Gitea RCE (CVE-2026-60004) with JITTERLY Implant and SIXZUT Rootkitcritical
- CISA Adds Actively Exploited Cisco Secure Email Gateway SQL Injection (CVE-2026-76461) to KEV Catalogcritical
- CVE-2025-37947: Out-of-Bounds Write in Linux ksmbd Kernel SMB Server Enables Local Privilege Escalationhigh
- VLC Media Player: Integer Overflow in AllocatePicture (CVE-2026-56711) and RTSP Heap Out-of-Bounds Read…high
- GitLab Patches Max-Severity Unauthenticated Path Traversal Flaw in Repository Commits API (CVE-2026-85706…critical
- Tesla Wall Connector Gen 3: Anti-Downgrade (Security Ratchet) Bypass via Charge Port Connectorhigh
- Google Patches Chrome Zero-Day CVE-2026-85046 (6th of 2026), Actively Exploited V8 Type Confusionhigh
- CVE-2026-20212: Critical Unauthenticated RCE in Cisco Nexus 9000 Series Switches (Silicon One ASIC)critical
- SonicWall SMA1000 Chained Vulnerabilities (CVE-2026-83548, CVE-2026-83549) Exploited in the Wildcritical
Detection coverage
Threadlinqs maintains 88 detection rules mapped to T1588.006 (SPL 30, KQL 27, Sigma 31). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1588 Obtain Capabilities — 363 tracked threats at the technique level.