Activity timeline
T1592.002 first appeared in tracked threats on and was most recently reported on . The busiest month was 2026-07 with 27 reports, and 68 of the 68 threats were reported in the twelve months to 2026-09.
How adversaries use it
T1592.002 Software is catalogued by MITRE ATT&CK under the Reconnaissance tactic in the Enterprise matrix, as a sub-technique of T1592 Gather Victim Host Information. Threadlinqs maps 68 of 2623 tracked threats (2.6%) to it; by severity that is 38 critical, 14 high, 12 medium.
Threats that use T1592.002 most often also use T1190 Exploit Public-Facing Application (54 threats), T1595.002 Vulnerability Scanning (50 threats), T1588.006 Vulnerabilities (39 threats), T1588.005 Exploits (34 threats), T1068 Exploitation for Privilege Escalation (29 threats). These are the techniques an intrusion set tends to chain with it, so they are the natural next places to look when it is observed.
2 tracked threat actors appear in the threats that use T1592.002; the most frequent are Hacktron AI (1), ShinyHunters (1).
Mitigations
MITRE ATT&CK lists 1 mitigation for T1592.002.
Data sources
Telemetry that can reveal T1592.002, per MITRE ATT&CK.
- Internet Scan — Response Content
Threat actors using it
Tracked threats
The 30 most recent of 68 tracked threats that use T1592.002.
- Citrix Patches Two Actively Exploited NetScaler Zero-Days (CVE-2026-88771, CVE-2026-88772)critical
- ShinyHunters Exploit Grav CMS Path Traversal (CVE-2026-42608) to Hack Clop Ransomware Gang's Leak Sitecritical
- Multiple PHP Vulnerabilities Enable Denial of Service, TLS Verification Bypass, and Credential Leakage…medium
- Vulnerability in F5 Products (CVE-2026-42015) — BIG-IP Next CNF, BIG-IP Next for Kubernetes, F5OSmedium
- CVE-2026-94127: Critical F5 BIG-IP APM Zero-Day Heap Overflow in OAuth Authorization Server Exploited for…critical
- CVE-2026-87902: Critical Unauthenticated Local File Inclusion in WordPress Core (Conditional RCE)critical
- F5 BIG-IP DNS Denial of Service via BIND DNSSEC Random Subdomain Attack (CVE-2026-11622)high
- AI-Built Exploit Chain Turns Unpatched libheif Flaw and OpenAI Forum Sign-In Bug into Internal Code Accesshigh
- Critical Check Point Management Server Flaw (CVE-2026-91843) Lets Unauthenticated Attackers Run Code as Rootcritical
- Dutch NCSC Warns of Critical Check Point VPN Flaws (CVE-2026-85102, CVE-2026-85103) — Exploitation Expected…critical
- Cronos Blockchain Halted After $74M Price-Manipulation Exploit of Tectonic Lending Protocolcritical
- GiveWP WordPress Donation Plugin Flaw (CVE-2026-82222) Lets Attackers Execute Server Commandscritical
- Apache Tomcat 11.0.25 Fixes 11 Vulnerabilities Including HTTP/2 DoS, Authorization Bypass, and Auth…critical
- Adobe and Nvidia Patch Dozens of Vulnerabilities Across Multiple Products, Including Two Critical Flaws in…critical
- CVE-2026-19490 — Critical Authentication Bypass in Citrix NetScaler ADC and Gateway (CVSS 9.3) with…critical
- CVE-2026-15748: Forminator WordPress Plugin Arbitrary File Upload Enables Unauthenticated RCEcritical
- Critical GitLab GraphQL Flaw (CVE-2026-19478, CVSS 9.4) Could Let Unauthenticated Attackers Delete Public…critical
- CVE-2026-40126: DOM-based XSS in OutSystems Service Center via malicious file upload filenamesmedium
- Unpatched GeoServer Zero-Day SQL Injection (jsonArrayContains, GHSA-mqjf-5f49-2fjh) Under Active Exploitationcritical
- Cisco Secure Firewall ASA/FTD Zero-Day (CVE-2026-20349) Exploited for DoS via Crafted HTTP Requests to…high
- Adobe Patches Critical RCE Flaws in ColdFusion, Campaign Classic, and Commerce (CVE-2026-48362, CVSS 10.0)critical
- Metabase Unauthenticated SQL Injection Zero-Day (GHSA-vwf4-m7j8-wcjf, CVSS 10.0) Exploited to Steal…critical
- Claude-Powered OpenClaw AI Agent Autonomously Exploits Gym Booking API Authorization Flawmedium
- AI-Assisted "HTTP Terminator" Uncovers Novel HTTP Desync Techniques and Apache Traffic Server Zero-Day…high
- Bendix EC80 Truck Brake Controller: 2024 Safety Recall Covertly Patched RCE and DoS Vulnerabilitieshigh
- Coldcard Hardware Wallet RNG Flaw Enables $88.6M Bitcoin Theft from 4,585 Addressescritical
- Heap Overflow Chain in Titan Quest: Anniversary Edition via Malicious Custom Map/Particle Fileshigh
- CVE-2025-67649: Unauthenticated SQL Injection in PHP Jabbers Car Rental Script (<4.1)critical
- Multiple Vulnerabilities in Citrix XenServer 8.4 and 9 Enable Guest-to-Host Escalation and Denial of Service…high
- Google Chrome 151 (151.0.7922.71/.72) Patches 370 Security Flaws Including 7 Critical Sandbox-Escape /…critical
Detection coverage
Threadlinqs maintains 74 detection rules mapped to T1592.002 (SPL 24, KQL 22, Sigma 28). Rule content is available to Blue tier accounts and above; this page shows counts only.
Parent technique
T1592 Gather Victim Host Information — 153 tracked threats at the technique level.