# T1588.006 Vulnerabilities

> As of 2026-10-05, T1588.006 (Vulnerabilities) appears in 125 tracked threats, first reported 2026-02-16 and most recently 2026-10-03, with linked actors including Cl0p, Nightmare Eclipse, Chaotic Eclipse; it most often appears alongside T1190 (Exploit Public-Facing Application).

- **Tracked threats:** 125 (69 critical, 38 high, 12 medium)
- **First seen:** 2026-02-16
- **Last seen:** 2026-10-03
- **Threat actors:** 8
- **Detection rules:** 88 (counts only; Blue tier and above)

## Key facts

- **ID:** T1588.006
- **Framework:** MITRE ATT&CK
- **Tactics:** Resource Development
- **Matrix:** Enterprise
- **Parent:** T1588
- **Data as of:** 2026-10-05
- **MITRE:** https://attack.mitre.org/techniques/T1588/006/

## Activity timeline

T1588.006 first appeared in tracked threats on 2026-02-16 and was most recently reported on 2026-10-03. The busiest month was 2026-08 with 46 reports, and 125 of the 125 threats were reported in the twelve months to 2026-10.

## How adversaries use it

T1588.006 Vulnerabilities is catalogued by MITRE ATT&CK under the Resource Development tactic in the Enterprise matrix, as a sub-technique of [T1588 Obtain Capabilities](https://intel.threadlinqs.com/technique/T1588). Threadlinqs maps 125 of 2623 tracked threats (4.8%) to it; by severity that is 69 critical, 38 high, 12 medium.

Threats that use T1588.006 most often also use [T1190 Exploit Public-Facing Application](https://intel.threadlinqs.com/technique/T1190) (86 threats), [T1595.002 Vulnerability Scanning](https://intel.threadlinqs.com/technique/T1595.002) (66 threats), [T1587.004 Exploits](https://intel.threadlinqs.com/technique/T1587.004) (53 threats), [T1588.005 Exploits](https://intel.threadlinqs.com/technique/T1588.005) (53 threats), [T1068 Exploitation for Privilege Escalation](https://intel.threadlinqs.com/technique/T1068) (52 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.

8 tracked threat actors appear in the threats that use T1588.006; the most frequent are [Cl0p](https://intel.threadlinqs.com/actor/Cl0p) (2), [Nightmare Eclipse](https://intel.threadlinqs.com/actor/Nightmare%20Eclipse) (2), [Chaotic Eclipse](https://intel.threadlinqs.com/actor/Chaotic%20Eclipse) (1), [Hacktron AI](https://intel.threadlinqs.com/actor/Hacktron%20AI) (1), [Intellexa Consortium](https://intel.threadlinqs.com/actor/Intellexa%20Consortium) (1).

## Mitigations

MITRE ATT&CK lists 1 mitigation for T1588.006.

- [M1056 Pre-compromise](https://attack.mitre.org/mitigations/M1056/)

## Threat actors using it

- [Cl0p](https://intel.threadlinqs.com/actor/Cl0p) — 2
- [Nightmare Eclipse](https://intel.threadlinqs.com/actor/Nightmare%20Eclipse) — 2
- [Chaotic Eclipse](https://intel.threadlinqs.com/actor/Chaotic%20Eclipse) — 1
- [Hacktron AI](https://intel.threadlinqs.com/actor/Hacktron%20AI) — 1
- [Intellexa Consortium](https://intel.threadlinqs.com/actor/Intellexa%20Consortium) — 1
- [ShinyHunters](https://intel.threadlinqs.com/actor/ShinyHunters) — 1
- [The Gentlemen](https://intel.threadlinqs.com/actor/The%20Gentlemen) — 1
- [UAT-9686](https://intel.threadlinqs.com/actor/UAT-9686) — 1

## Tracked threats

The 30 most recent of 125 tracked threats that use T1588.006.

- [Desktop AI Supercomputers, Uncensored Models and Agentic Frameworks (HexStrike-AI) Enable Automated…](https://intel.threadlinqs.com/threat/TL-2026-2881) — high — 2026-10-03
- [Apple CoreGraphics Out-of-Bounds Write (CVE-2026-86950) Possibly Exploited in Targeted Attacks](https://intel.threadlinqs.com/threat/TL-2026-2745) — high — 2026-09-28
- [CISA Adds Two Citrix NetScaler Vulnerabilities (CVE-2026-88771, CVE-2026-88772) to KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2711) — critical — 2026-09-27
- [Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)](https://intel.threadlinqs.com/threat/TL-2026-2703) — critical — 2026-09-27
- [Two Unpatched Citrix NetScaler ADC/Gateway RCE Zero-Days Under Active Exploitation](https://intel.threadlinqs.com/threat/TL-2026-2688) — critical — 2026-09-27
- [Check Point Security Gateway VPN Pre-Auth RCE (CVE-2026-85102) and Management Path Traversal Zero-Day…](https://intel.threadlinqs.com/threat/TL-2026-2677) — critical — 2026-09-26
- [Multiple Vulnerabilities in Google Chrome Patched in Stable Channel Update 154.0.8037.57 (GovCERT.HK…](https://intel.threadlinqs.com/threat/TL-2026-2662) — medium — 2026-09-26
- [Microsoft Office / Microsoft 365 Apps for Enterprise Remote Code Execution Vulnerability (CVE-2026-70125)](https://intel.threadlinqs.com/threat/TL-2026-2659) — high — 2026-09-26
- [CISA Adds Actively Exploited WSO2 API Manager and Adobe Commerce Flaws to KEV Catalog, Warns on SharePoint…](https://intel.threadlinqs.com/threat/TL-2026-2680) — critical — 2026-09-25
- [Multiple PHP Vulnerabilities Enable Denial of Service, TLS Verification Bypass, and Credential Leakage…](https://intel.threadlinqs.com/threat/TL-2026-2658) — medium — 2026-09-25
- [Vulnerability in F5 Products (CVE-2026-42015) — BIG-IP Next CNF, BIG-IP Next for Kubernetes, F5OS](https://intel.threadlinqs.com/threat/TL-2026-2660) — medium — 2026-09-24
- [CVE-2026-94127: Critical F5 BIG-IP APM Zero-Day Heap Overflow in OAuth Authorization Server Exploited for…](https://intel.threadlinqs.com/threat/TL-2026-2632) — critical — 2026-09-23
- [CVE-2026-87902: Critical Unauthenticated Local File Inclusion in WordPress Core (Conditional RCE)](https://intel.threadlinqs.com/threat/TL-2026-2623) — critical — 2026-09-22
- [ShinyHunters Claims FBI Breach via Unpatched Oracle PeopleSoft Zero-Day, Threatens 2-3TB of PII/PHI Leak](https://intel.threadlinqs.com/threat/TL-2026-2620) — critical — 2026-09-22
- [Click2Shell: WordPress Theme-Preview CSRF/Selector-Injection Chain to Forced Theme Install](https://intel.threadlinqs.com/threat/TL-2026-2597) — critical — 2026-09-21
- [F5 BIG-IP DNS Denial of Service via BIND DNSSEC Random Subdomain Attack (CVE-2026-11622)](https://intel.threadlinqs.com/threat/TL-2026-2596) — high — 2026-09-21
- [SolarWinds Access Rights Manager Hard-Coded Cryptographic Key (CVE-2026-28326) Enables Unauthenticated RCE](https://intel.threadlinqs.com/threat/TL-2026-2585) — critical — 2026-09-19
- [CISA Flags Three Actively Exploited Linux Kernel Vulnerabilities: kTLS Receive-Path Disclosure/DoS, ebtables…](https://intel.threadlinqs.com/threat/TL-2026-2582) — critical — 2026-09-19
- [Critical Pre-Auth RCE in Orkes Conductor Workflow Platform (CVE-2026-58138) Exploited in the Wild](https://intel.threadlinqs.com/threat/TL-2026-2574) — critical — 2026-09-19
- [AI-Driven Exploit Chain Against OpenAI Community Forum via libheif Flaw (CVE-2026-32882)](https://intel.threadlinqs.com/threat/TL-2026-2558) — high — 2026-09-18
- [CVE-2026-87886: Actively Exploited Privilege Escalation Flaw in Acronis cPanel Backup Plugin](https://intel.threadlinqs.com/threat/TL-2026-2523) — high — 2026-09-15
- [Red Heron Weaponizes Gitea RCE (CVE-2026-60004) with JITTERLY Implant and SIXZUT Rootkit](https://intel.threadlinqs.com/threat/TL-2026-2516) — critical — 2026-09-14
- [CISA Adds Actively Exploited Cisco Secure Email Gateway SQL Injection (CVE-2026-76461) to KEV Catalog](https://intel.threadlinqs.com/threat/TL-2026-2508) — critical — 2026-09-14
- [CVE-2025-37947: Out-of-Bounds Write in Linux ksmbd Kernel SMB Server Enables Local Privilege Escalation](https://intel.threadlinqs.com/threat/TL-2026-2477) — high — 2026-09-13
- [VLC Media Player: Integer Overflow in AllocatePicture (CVE-2026-56711) and RTSP Heap Out-of-Bounds Read…](https://intel.threadlinqs.com/threat/TL-2026-2464) — high — 2026-09-12
- [GitLab Patches Max-Severity Unauthenticated Path Traversal Flaw in Repository Commits API (CVE-2026-85706…](https://intel.threadlinqs.com/threat/TL-2026-2442) — critical — 2026-09-11
- [Tesla Wall Connector Gen 3: Anti-Downgrade (Security Ratchet) Bypass via Charge Port Connector](https://intel.threadlinqs.com/threat/TL-2026-2425) — high — 2026-09-09
- [Google Patches Chrome Zero-Day CVE-2026-85046 (6th of 2026), Actively Exploited V8 Type Confusion](https://intel.threadlinqs.com/threat/TL-2026-2326) — high — 2026-09-04
- [CVE-2026-20212: Critical Unauthenticated RCE in Cisco Nexus 9000 Series Switches (Silicon One ASIC)](https://intel.threadlinqs.com/threat/TL-2026-2319) — critical — 2026-09-03
- [SonicWall SMA1000 Chained Vulnerabilities (CVE-2026-83548, CVE-2026-83549) Exploited in the Wild](https://intel.threadlinqs.com/threat/TL-2026-2307) — critical — 2026-09-03

## Related CVEs

CVEs referenced by the tracked threats that use T1588.006, most frequent first.

- [CVE-2026-12569](https://intel.threadlinqs.com/cve/CVE-2026-12569)
- [CVE-2026-20230](https://intel.threadlinqs.com/cve/CVE-2026-20230)
- [CVE-2026-42945](https://intel.threadlinqs.com/cve/CVE-2026-42945)
- [CVE-2026-46817](https://intel.threadlinqs.com/cve/CVE-2026-46817)
- [CVE-2026-88771](https://intel.threadlinqs.com/cve/CVE-2026-88771)
- [CVE-2026-88772](https://intel.threadlinqs.com/cve/CVE-2026-88772)
- [CVE-2020-17103](https://intel.threadlinqs.com/cve/CVE-2020-17103)
- [CVE-2021-29441](https://intel.threadlinqs.com/cve/CVE-2021-29441)
- [CVE-2021-30860](https://intel.threadlinqs.com/cve/CVE-2021-30860)
- [CVE-2024-37085](https://intel.threadlinqs.com/cve/CVE-2024-37085)
- [CVE-2024-55591](https://intel.threadlinqs.com/cve/CVE-2024-55591)
- [CVE-2025-1218](https://intel.threadlinqs.com/cve/CVE-2025-1218)
- [CVE-2025-14181](https://intel.threadlinqs.com/cve/CVE-2025-14181)
- [CVE-2025-26125](https://intel.threadlinqs.com/cve/CVE-2025-26125)
- [CVE-2025-30208](https://intel.threadlinqs.com/cve/CVE-2025-30208)
- [CVE-2025-31718](https://intel.threadlinqs.com/cve/CVE-2025-31718)
- [CVE-2025-32433](https://intel.threadlinqs.com/cve/CVE-2025-32433)
- [CVE-2025-32463](https://intel.threadlinqs.com/cve/CVE-2025-32463)
- [CVE-2025-3248](https://intel.threadlinqs.com/cve/CVE-2025-3248)
- [CVE-2025-33073](https://intel.threadlinqs.com/cve/CVE-2025-33073)
- [CVE-2025-43200](https://intel.threadlinqs.com/cve/CVE-2025-43200)
- [CVE-2025-55182](https://intel.threadlinqs.com/cve/CVE-2025-55182)
- [CVE-2025-5777](https://intel.threadlinqs.com/cve/CVE-2025-5777)
- [CVE-2025-7775](https://intel.threadlinqs.com/cve/CVE-2025-7775)
- [CVE-2025-8321](https://intel.threadlinqs.com/cve/CVE-2025-8321)
- [CVE-2026-10520](https://intel.threadlinqs.com/cve/CVE-2026-10520)
- [CVE-2026-11622](https://intel.threadlinqs.com/cve/CVE-2026-11622)
- [CVE-2026-15409](https://intel.threadlinqs.com/cve/CVE-2026-15409)
- [CVE-2026-15410](https://intel.threadlinqs.com/cve/CVE-2026-15410)
- [CVE-2026-16723](https://intel.threadlinqs.com/cve/CVE-2026-16723)

## Detection coverage

Threadlinqs maintains 88 detection rules mapped to T1588.006 (SPL 30, KQL 27, Sigma 31). Rule content is available to Blue tier accounts and above; this page shows counts only.

88 detection rules (SPL/KQL/Sigma), Blue and above: https://threadlinqs.com/pricing

## Parent technique

[T1588 Obtain Capabilities](https://intel.threadlinqs.com/technique/T1588) — 363 tracked threats at the technique level.

## Links

- Canonical page: https://intel.threadlinqs.com/technique/T1588.006
- All techniques: https://intel.threadlinqs.com/techniques
- Full detection coverage and IOCs: https://intel.threadlinqs.com/mcp (Purple tier)
