Threat Actor SpotlightWeekly
Threat actor spotlight: PROMETHIUM
Updated 12 August 2026 · Timeframe: All tracked history to date
PROMETHIUM (state) is linked to 12 CVEs in our corpus, and targets Government Activity, Telecommunications Services (TRBC); Public Administration, Telecommunications (NAICS).
Why it matters
Defending against an adversary is more actionable than defending against a CVE list. Knowing who is active and who they hunt lets teams prioritize by likelihood, not just severity.
What to do
- Security leaders. Check whether this actor targets your sector; if so, brief the board on the specific threat, not generic risk.
- Lean IT orgs. Map the actor's known CVEs against your stack — a short, prioritized patch list.
- MSPs. Flag clients in the actor's target sectors for a proactive check.
Our take
Adversary-centric storytelling — who, why, and how to defend — is far stickier than another vulnerability roundup.
Earlier issues
Past states of this signal, most recent first.
06 August 2026 Threat actor spotlight: PROMETHIUM
Timeframe: All tracked history to date
PROMETHIUM (state) is linked to 12 CVEs in our corpus, and targets Government Activity, Telecommunications Services (TRBC); Public Administration, Telecommunications (NAICS).
31 July 2026 Threat actor spotlight: Lazarus Group
Timeframe: All tracked history to date
Lazarus Group (state) is linked to 12 CVEs in our corpus, 2 named victims, and targets Cyclical Consumer Services, Banking & Investment Services (TRBC); Arts, Entertainment & Recreation, Credit Intermediation & Related Activities (Banking), Securities, Commodity Contracts & Other Financial Investments (NAICS).
25 July 2026 Threat actor spotlight: NEODYMIUM
Timeframe: All tracked history to date
NEODYMIUM (unknown) is linked to 12 CVEs in our corpus.