<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" version="2.0">
  <channel>
    <title>SA Cyber Threat Intelligence | Digital Progression</title>
    <link>https://www.threatintelligence.co.za/</link>
    <description>Weekly South African cyber threat intelligence. Ransomware activity, critical CVEs, data breaches and POPIA developments affecting SA organisations — published free every week.</description>
    <atom:link href="https://www.threatintelligence.co.za/feed.xml" rel="self" type="application/rss+xml" />
    <language>en-za</language>
    <copyright>© 2026 Digital Progression</copyright>
    <managingEditor>info@dpcyber.co.za (Digital Progression)</managingEditor>
    <category>Cyber Threat Intelligence</category>
    <pubDate>Mon, 05 Oct 2026 06:00:00 +0200</pubDate>
    <lastBuildDate>Mon, 05 Oct 2026 06:00:00 +0200</lastBuildDate>
    <docs>https://www.rssboard.org/rss-specification</docs>
    <image>
      <url>https://www.threatintelligence.co.za/images/favicon.png</url>
      <title>SA Cyber Threat Intelligence | Digital Progression</title>
      <link>https://www.threatintelligence.co.za/</link>
      <width>64</width>
      <height>64</height>
    </image>
    <item>
      <title>Weekly Threat Intel: South Africa Week 41 (27 September – 3 October 2026)</title>
      <link>https://www.threatintelligence.co.za/reports/threat-intel-w41-26.html</link>
      <guid isPermaLink="true">https://www.threatintelligence.co.za/reports/threat-intel-w41-26.html</guid>
      <pubDate>Mon, 05 Oct 2026 06:00:00 +0200</pubDate>
      <description>HIGH Threat Level: the state air navigation operator discloses ransomware-linked malware in airport OT through a tender, INC Ransom lists BCX, and the MIP breach reaches a second insurer through a binder holder.</description>
      <category>ATNS</category>
      <category>OperationalTechnology</category>
      <category>BCX</category>
      <category>INCRansom</category>
      <category>Guardrisk</category>
      <category>CoverCubed</category>
      <category>TheGentlemen</category>
      <category>LegalWise</category>
      <category>CitrixNetScaler</category>
      <category>POPIASection22</category>
      <enclosure url="https://www.threatintelligence.co.za/pdf/sa_threat_intel_report_2026_w41.pdf" length="803852" type="application/pdf" />
    </item>
    <item>
      <title>Weekly Threat Intel: South Africa Week 40 (20 – 26 September 2026)</title>
      <link>https://www.threatintelligence.co.za/reports/threat-intel-w40-26.html</link>
      <guid isPermaLink="true">https://www.threatintelligence.co.za/reports/threat-intel-w40-26.html</guid>
      <pubDate>Mon, 28 Sep 2026 06:00:00 +0200</pubDate>
      <description>HIGH Threat Level: the regulators rule that the insurer owes the notification whatever the supplier did and that paying a ransom does not discharge it, while a second South African insurer is listed in three weeks.</description>
      <category>Guardrisk</category>
      <category>TheGentlemen</category>
      <category>MIPHoldings</category>
      <category>BidvestBank</category>
      <category>RelyComply</category>
      <category>TelkomBCX</category>
      <category>GautengEPanic</category>
      <category>CheckPoint</category>
      <category>MikroTik</category>
      <category>POPIASection22</category>
      <enclosure url="https://www.threatintelligence.co.za/pdf/sa_threat_intel_report_2026_w40.pdf" length="761206" type="application/pdf" />
    </item>
    <item>
      <title>Weekly Threat Intel: South Africa Week 39 (13 – 19 September 2026)</title>
      <link>https://www.threatintelligence.co.za/reports/threat-intel-w39-26.html</link>
      <guid isPermaLink="true">https://www.threatintelligence.co.za/reports/threat-intel-w39-26.html</guid>
      <pubDate>Mon, 21 Sep 2026 06:00:00 +0200</pubDate>
      <description>HIGH Threat Level: one policy-administration vendor held identity numbers for the customers of 45 insurers, one compliance platform held the FICA records of six regulated institutions — and a paid ransom did not stop publication.</description>
      <category>MIPHoldings</category>
      <category>RelyComply</category>
      <category>Hollard</category>
      <category>TheGentlemen</category>
      <category>DireWolf</category>
      <category>EasyEquities</category>
      <category>SupplyChain</category>
      <category>CiscoISE</category>
      <category>POPIASection22</category>
      <category>CybercrimesAct</category>
      <enclosure url="https://www.threatintelligence.co.za/pdf/sa_threat_intel_report_2026_w39.pdf" length="1172858" type="application/pdf" />
    </item>
    <item>
      <title>Weekly Threat Intel: South Africa Week 38 (6 – 12 September 2026)</title>
      <link>https://www.threatintelligence.co.za/reports/threat-intel-w38-26.html</link>
      <guid isPermaLink="true">https://www.threatintelligence.co.za/reports/threat-intel-w38-26.html</guid>
      <pubDate>Mon, 14 Sep 2026 06:00:00 +0200</pubDate>
      <description>HIGH Threat Level: two financial institutions notify customers over a supplier's breach, South Africa's largest private insurer is listed on a leak site, and three vendor advisories contradict the exploitation catalogue.</description>
      <category>BidvestBank</category>
      <category>EasyEquities</category>
      <category>Hollard</category>
      <category>TheGentlemen</category>
      <category>LockBit</category>
      <category>Cartrack</category>
      <category>CitrixNetScaler</category>
      <category>CiscoFMC</category>
      <category>MikroTik</category>
      <category>FSCA</category>
      <enclosure url="https://www.threatintelligence.co.za/pdf/sa_threat_intel_report_2026_w38.pdf" length="1202714" type="application/pdf" />
    </item>
    <item>
      <title>Weekly Threat Intel: South Africa Week 37 (30 August – 5 September 2026)</title>
      <link>https://www.threatintelligence.co.za/reports/threat-intel-w37-26.html</link>
      <guid isPermaLink="true">https://www.threatintelligence.co.za/reports/threat-intel-w37-26.html</guid>
      <pubDate>Mon, 07 Sep 2026 06:00:00 +0200</pubDate>
      <description>HIGH Threat Level: Africa's largest bulk water utility confirms a breach, the Information Regulator reveals it holds over 8,000 unpublished breach notifications, and SonicWall tells customers to re-image rather than patch.</description>
      <category>RandWater</category>
      <category>CriticalInfrastructure</category>
      <category>InformationRegulator</category>
      <category>SABS</category>
      <category>SonicWall</category>
      <category>PaperCut</category>
      <category>Cartrack</category>
      <category>DireWolf</category>
      <category>FSCA</category>
      <category>POPIACompliance</category>
      <enclosure url="https://www.threatintelligence.co.za/pdf/sa_threat_intel_report_2026_w37.pdf" length="1199022" type="application/pdf" />
    </item>
    <item>
      <title>Weekly Threat Intel: South Africa Week 36 (23 – 29 August 2026)</title>
      <link>https://www.threatintelligence.co.za/reports/threat-intel-w36-26.html</link>
      <guid isPermaLink="true">https://www.threatintelligence.co.za/reports/threat-intel-w36-26.html</guid>
      <pubDate>Mon, 31 Aug 2026 06:00:00 +0200</pubDate>
      <description>HIGH Threat Level: a statutory council publishes its own ransomware notice, the Lengau supercomputer crypto-mining cause reaches Parliament, and AI appears on both sides of the vulnerability.</description>
      <category>FurnitureBargainingCouncil</category>
      <category>Deadlock</category>
      <category>LengauSupercomputer</category>
      <category>CHPC</category>
      <category>UAT10147</category>
      <category>OracleWebLogic</category>
      <category>SharePoint</category>
      <category>INTERPOL</category>
      <category>CISAKEV</category>
      <category>InformationRegulator</category>
      <enclosure url="https://www.threatintelligence.co.za/pdf/sa_threat_intel_report_2026_w36.pdf" length="1134366" type="application/pdf" />
    </item>
    <item>
      <title>Weekly Threat Intel: South Africa Week 35 (16 – 22 August 2026)</title>
      <link>https://www.threatintelligence.co.za/reports/threat-intel-w35-26.html</link>
      <guid isPermaLink="true">https://www.threatintelligence.co.za/reports/threat-intel-w35-26.html</guid>
      <pubDate>Mon, 24 Aug 2026 06:00:00 +0200</pubDate>
      <description>HIGH Threat Level: two South African companies named by ransomware groups with no acknowledgment from either, while nine KEV additions land in five days and six are already overdue.</description>
      <category>TheCourierGuy</category>
      <category>MedusaLocker</category>
      <category>Babcock</category>
      <category>TheGentlemen</category>
      <category>SharePoint</category>
      <category>VMwarevCenter</category>
      <category>WindowsIKE</category>
      <category>Zimbra</category>
      <category>CISAKEV</category>
      <category>POPIASection22</category>
      <enclosure url="https://www.threatintelligence.co.za/pdf/sa_threat_intel_report_2026_w35.pdf" length="1161495" type="application/pdf" />
    </item>
    <item>
      <title>Weekly Threat Intel: South Africa Week 34 (9 – 15 August 2026)</title>
      <link>https://www.threatintelligence.co.za/reports/threat-intel-w34-26.html</link>
      <guid isPermaLink="true">https://www.threatintelligence.co.za/reports/threat-intel-w34-26.html</guid>
      <pubDate>Mon, 17 Aug 2026 06:00:00 +0200</pubDate>
      <description>HIGH Threat Level: three South African confirmations, every one of them on a supply chain — including a retailer breached through a reporting tool two companies further down the chain.</description>
      <category>LEGOCertifiedStores</category>
      <category>Metabase</category>
      <category>Marsello</category>
      <category>ToyotaSA</category>
      <category>EuphoriaTelecom</category>
      <category>SupplyChain</category>
      <category>Storm1175</category>
      <category>CiscoASA</category>
      <category>POPIASection22</category>
      <category>InformationRegulator</category>
      <enclosure url="https://www.threatintelligence.co.za/pdf/sa_threat_intel_report_2026_w34.pdf" length="1109564" type="application/pdf" />
    </item>
    <item>
      <title>Weekly Threat Intel: South Africa Week 33 (2 – 8 August 2026)</title>
      <link>https://www.threatintelligence.co.za/reports/threat-intel-w33-26.html</link>
      <guid isPermaLink="true">https://www.threatintelligence.co.za/reports/threat-intel-w33-26.html</guid>
      <pubDate>Mon, 10 Aug 2026 06:00:00 +0200</pubDate>
      <description>HIGH Threat Level: a regulated payment distribution agency confirms ransomware, Fidelity's breach is confirmed and published, and INTERPOL puts South Africa at 92% of Africa's ransomware detections.</description>
      <category>DCPartner</category>
      <category>Krybit</category>
      <category>FidelityServices</category>
      <category>RansomHouse</category>
      <category>INTERPOL</category>
      <category>SABRIC</category>
      <category>NAbleNCentral</category>
      <category>Langflow</category>
      <category>ApacheTomcat</category>
      <category>POPIASection22</category>
      <enclosure url="https://www.threatintelligence.co.za/pdf/sa_threat_intel_report_2026_w33.pdf" length="1603589" type="application/pdf" />
    </item>
    <item>
      <title>Weekly Threat Intel: South Africa Week 32 (26 July – 2 August 2026)</title>
      <link>https://www.threatintelligence.co.za/reports/threat-intel-w32-26.html</link>
      <guid isPermaLink="true">https://www.threatintelligence.co.za/reports/threat-intel-w32-26.html</guid>
      <pubDate>Mon, 03 Aug 2026 06:00:00 +0200</pubDate>
      <description>HIGH Threat Level: four South African ransomware victims surface at once including the region's largest security services provider, while SARS confirms taxpayer phishing is now AI-generated.</description>
      <category>FidelityServices</category>
      <category>RansomHouse</category>
      <category>IncRansom</category>
      <category>SARS</category>
      <category>AIPhishing</category>
      <category>AristaVeloCloud</category>
      <category>CiscoFMC</category>
      <category>Fastjson</category>
      <category>CISAKEV</category>
      <category>POPIASection22</category>
      <enclosure url="https://www.threatintelligence.co.za/pdf/sa_threat_intel_report_2026_w32.pdf" length="512568" type="application/pdf" />
    </item>
    <item>
      <title>Weekly Threat Intel: South Africa Week 31 (19 – 26 July 2026)</title>
      <link>https://www.threatintelligence.co.za/reports/threat-intel-w31-26.html</link>
      <guid isPermaLink="true">https://www.threatintelligence.co.za/reports/threat-intel-w31-26.html</guid>
      <pubDate>Mon, 27 Jul 2026 06:00:00 +0200</pubDate>
      <description>HIGH Threat Level: Rectron confirms a DragonForce breach and notifies the Regulator, the SA ransomware tally corrects upward to 115, and two new KEV entries defeat patch-only remediation.</description>
      <category>Rectron</category>
      <category>DragonForce</category>
      <category>Qilin</category>
      <category>SharePoint</category>
      <category>CheckPoint</category>
      <category>WordPress</category>
      <category>OracleCPU</category>
      <category>CISAKEV</category>
      <category>POPIASection22</category>
      <category>FICDeadline</category>
      <enclosure url="https://www.threatintelligence.co.za/pdf/sa_threat_intel_report_2026_w31.pdf" length="479670" type="application/pdf" />
    </item>
    <item>
      <title>Weekly Threat Intel: South Africa Week 30 (12 – 19 July 2026)</title>
      <link>https://www.threatintelligence.co.za/reports/threat-intel-w30-26.html</link>
      <guid isPermaLink="true">https://www.threatintelligence.co.za/reports/threat-intel-w30-26.html</guid>
      <pubDate>Mon, 20 Jul 2026 06:00:00 +0200</pubDate>
      <description>HIGH Threat Level: South Africa's six-week quiet ends with two confirmed incidents, a probable breach at a top-four technology distributor, and the largest Microsoft patch release ever recorded.</description>
      <category>BETravel</category>
      <category>ArcusMedia</category>
      <category>GautengBreach</category>
      <category>Rectron</category>
      <category>DragonForce</category>
      <category>PatchTuesday</category>
      <category>ADFS</category>
      <category>SharePoint</category>
      <category>CISAKEV</category>
      <category>POPIACompliance</category>
      <enclosure url="https://www.threatintelligence.co.za/pdf/sa_threat_intel_report_2026_w30.pdf" length="504429" type="application/pdf" />
    </item>
    <item>
      <title>Weekly Threat Intel: South Africa Week 29 (5 – 12 July 2026)</title>
      <link>https://www.threatintelligence.co.za/reports/threat-intel-w29-26.html</link>
      <guid isPermaLink="true">https://www.threatintelligence.co.za/reports/threat-intel-w29-26.html</guid>
      <pubDate>Mon, 13 Jul 2026 06:00:00 +0200</pubDate>
      <description>HIGH Threat Level: six KEV additions in seven days on three-day fuses, four of them Joomla extension flaws targeting the unmanaged SA web estate, while SA breach volume goes public at 3,219 notifications and R141.96 billion.</description>
      <category>Joomla</category>
      <category>SPPageBuilder</category>
      <category>ColdFusion</category>
      <category>Gitea</category>
      <category>OracleEBS</category>
      <category>CISAKEV</category>
      <category>ICASA</category>
      <category>SIMBoxing</category>
      <category>POPIACompliance</category>
      <category>InformationRegulator</category>
      <enclosure url="https://www.threatintelligence.co.za/pdf/sa_threat_intel_report_2026_w29.pdf" length="1182236" type="application/pdf" />
    </item>
    <item>
      <title>Weekly Threat Intel: South Africa Week 28 (28 June – 5 July 2026)</title>
      <link>https://www.threatintelligence.co.za/reports/threat-intel-w28-26.html</link>
      <guid isPermaLink="true">https://www.threatintelligence.co.za/reports/threat-intel-w28-26.html</guid>
      <pubDate>Mon, 06 Jul 2026 06:00:00 +0200</pubDate>
      <description>HIGH Threat Level: Capitec replaces cards over the Pick n Pay legacy-app breach, the mystery medical-aid breach resolves to Profmed via PPSHA with a five-scheme blast radius, and Oracle EBS Payments is exploited before it even reaches the KEV.</description>
      <category>PicknPay</category>
      <category>Capitec</category>
      <category>Profmed</category>
      <category>PPSHA</category>
      <category>SimpleHelp</category>
      <category>SharePoint</category>
      <category>OracleEBS</category>
      <category>BlueHammer</category>
      <category>FICA</category>
      <category>POPIACompliance</category>
      <enclosure url="https://www.threatintelligence.co.za/pdf/dp-sa-threat-intel-2026-w28.pdf" length="1154974" type="application/pdf" />
    </item>
    <item>
      <title>Weekly Threat Intel: South Africa Week 27 (21–28 June 2026)</title>
      <link>https://www.threatintelligence.co.za/reports/threat-intel-w27-26.html</link>
      <guid isPermaLink="true">https://www.threatintelligence.co.za/reports/threat-intel-w27-26.html</guid>
      <pubDate>Mon, 29 Jun 2026 06:00:00 +0200</pubDate>
      <description>HIGH Threat Level: Hacktivists breach two SA state entities into a 30 June flashpoint, IR serves notices on both major credit bureaus, Standard Bank leak attributed to Prinz Eugen/ROOTBOY publishing 100,000 rows/day.</description>
      <category>OpSouthAfrica</category>
      <category>Hacktivism</category>
      <category>CorrectionalServices</category>
      <category>TransUnion</category>
      <category>Experian</category>
      <category>PrinzEugen</category>
      <category>ROOTBOY</category>
      <category>StandardBank</category>
      <category>FortiBleed</category>
      <category>FICA</category>
      <enclosure url="https://www.threatintelligence.co.za/pdf/dp-sa-threat-intel-2026-w27.pdf" length="657725" type="application/pdf" />
    </item>
    <item>
      <title>Weekly Threat Intel: South Africa Week 26 (14–21 June 2026)</title>
      <link>https://www.threatintelligence.co.za/reports/threat-intel-w26-26.html</link>
      <guid isPermaLink="true">https://www.threatintelligence.co.za/reports/threat-intel-w26-26.html</guid>
      <pubDate>Mon, 22 Jun 2026 06:00:00 +0200</pubDate>
      <description>HIGH Threat Level: FortiBleed exposes ~74,000 FortiGate firewalls with plaintext credentials, Splunk pre-auth RCE under active exploitation, and the year's biggest supply-chain campaign attributed to a SA-based operator.</description>
      <category>FortiBleed</category>
      <category>Fortinet</category>
      <category>Splunk</category>
      <category>TeamPCP</category>
      <category>SupplyChain</category>
      <category>JoomlaJCE</category>
      <category>PeopleSoft</category>
      <category>AVBOB</category>
      <category>CannaLeaks</category>
      <category>POPIACompliance</category>
      <enclosure url="https://www.threatintelligence.co.za/pdf/dp-sa-threat-intel-2026-w26.pdf" length="647401" type="application/pdf" />
    </item>
    <item>
      <title>Weekly Threat Intel: South Africa Week 25 (7–14 June 2026)</title>
      <link>https://www.threatintelligence.co.za/reports/threat-intel-w25-26.html</link>
      <guid isPermaLink="true">https://www.threatintelligence.co.za/reports/threat-intel-w25-26.html</guid>
      <pubDate>Mon, 15 Jun 2026 06:00:00 +0200</pubDate>
      <description>HIGH Threat Level: AVBOB knocked offline (350+ branches), record 208-CVE Patch Tuesday led by a wormable kernel RCE, SAPS WC medical records breach, PeopleSoft 0-day mass-compromise, Ivanti Sentry 10.0 weaponised in under 24h.</description>
      <category>AVBOB</category>
      <category>PatchTuesday</category>
      <category>WormableRCE</category>
      <category>ExchangeOWA</category>
      <category>SAPS</category>
      <category>PeopleSoft</category>
      <category>ShinyHunters</category>
      <category>IvantiSentry</category>
      <category>OpenSSL</category>
      <category>POPIACompliance</category>
      <enclosure url="https://www.threatintelligence.co.za/pdf/dp-sa-threat-intel-2026-w25.pdf" length="593799" type="application/pdf" />
    </item>
    <item>
      <title>Weekly Threat Intel: South Africa Week 24 (31 May – 7 June 2026)</title>
      <link>https://www.threatintelligence.co.za/reports/threat-intel-w24-26.html</link>
      <guid isPermaLink="true">https://www.threatintelligence.co.za/reports/threat-intel-w24-26.html</guid>
      <pubDate>Mon, 08 Jun 2026 06:00:00 +0200</pubDate>
      <description>HIGH Threat Level: National supercomputer Lengau offline after credential breach, Standard Bank 1.2 TB publicly released, SA confirmed #1 globally for DDoS against banking, Cisco SD-WAN 7th zero-day with no patch.</description>
      <category>Lengau</category>
      <category>CSIR</category>
      <category>StandardBank</category>
      <category>ROOTBOY</category>
      <category>NETSCOUT</category>
      <category>DDoS</category>
      <category>CiscoSDWAN</category>
      <category>CitrixNetScaler</category>
      <category>PatchTuesday</category>
      <category>POPIACompliance</category>
      <enclosure url="https://www.threatintelligence.co.za/pdf/dp-sa-threat-intel-2026-w24.pdf" length="592388" type="application/pdf" />
    </item>
    <item>
      <title>Weekly Threat Intel: South Africa Week 23 (24–31 May 2026)</title>
      <link>https://www.threatintelligence.co.za/reports/threat-intel-w23-26.html</link>
      <guid isPermaLink="true">https://www.threatintelligence.co.za/reports/threat-intel-w23-26.html</guid>
      <pubDate>Mon, 01 Jun 2026 06:00:00 +0200</pubDate>
      <description>HIGH Threat Level: PAN-OS GlobalProtect CVSS 9.3 mass exploitation, Pick n Pay/Bottles breach confirmed, first China-APT compromise of a SA university, Exchange OWA deadline passes unpatched, ransomware tally flat at 111.</description>
      <category>PANOS</category>
      <category>GlobalProtect</category>
      <category>PicknPay</category>
      <category>Webworm</category>
      <category>ChinaAPT</category>
      <category>ExchangeOWA</category>
      <category>OracleORDS</category>
      <category>0daySyndicate</category>
      <category>SupplyChain</category>
      <category>POPIACompliance</category>
      <enclosure url="https://www.threatintelligence.co.za/pdf/dp-sa-threat-intel-2026-w23.pdf" length="577367" type="application/pdf" />
    </item>
    <item>
      <title>Weekly Threat Intel: South Africa Week 22 (17–24 May 2026)</title>
      <link>https://www.threatintelligence.co.za/reports/threat-intel-w22-26.html</link>
      <guid isPermaLink="true">https://www.threatintelligence.co.za/reports/threat-intel-w22-26.html</guid>
      <pubDate>Mon, 25 May 2026 06:00:00 +0200</pubDate>
      <description>HIGH Threat Level: SA ISP/hosting RDoS wave peaks 676Gbit/s, Defender OOB patches after 7+ weeks, new CVSS 10.0 cPanel vuln, SA added to Lazarus APT target geography, ransomware tally holds at 111.</description>
      <category>RDoS</category>
      <category>1Grid</category>
      <category>Xneelo</category>
      <category>Seacom</category>
      <category>BlackMatter</category>
      <category>DefenderOOB</category>
      <category>cPanelCVSS10</category>
      <category>Lazarus</category>
      <category>ExchangeOWA</category>
      <category>POPIACompliance</category>
      <enclosure url="https://www.threatintelligence.co.za/pdf/dp-sa-threat-intel-2026-w22.pdf" length="572079" type="application/pdf" />
    </item>
    <item>
      <title>Weekly Threat Intel: South Africa Week 21 (10–17 May 2026)</title>
      <link>https://www.threatintelligence.co.za/reports/threat-intel-w21-26.html</link>
      <guid isPermaLink="true">https://www.threatintelligence.co.za/reports/threat-intel-w21-26.html</guid>
      <pubDate>Mon, 18 May 2026 06:00:00 +0200</pubDate>
      <description>HIGH Threat Level: 3 new SA victims (SANBS unverified, Merensky Timber, Sew Treat), tally hits 111, Cisco SD-WAN CVSS 10.0 KEV deadline passes, Exchange OWA zero-day with no permanent patch.</description>
      <category>SANBS</category>
      <category>KillSec</category>
      <category>BlackSuit</category>
      <category>MerenskyTimber</category>
      <category>ExchangeOWA</category>
      <category>CiscoSDWAN</category>
      <category>Canvas</category>
      <category>ShinyHunters</category>
      <category>DefenderZeroDay</category>
      <category>POPIACompliance</category>
      <enclosure url="https://www.threatintelligence.co.za/pdf/dp-sa-threat-intel-2026-w21.pdf" length="821118" type="application/pdf" />
    </item>
    <item>
      <title>Weekly Threat Intel: South Africa Week 20 (3–10 May 2026)</title>
      <link>https://www.threatintelligence.co.za/reports/threat-intel-w20-26.html</link>
      <guid isPermaLink="true">https://www.threatintelligence.co.za/reports/threat-intel-w20-26.html</guid>
      <pubDate>Mon, 11 May 2026 06:00:00 +0200</pubDate>
      <description>HIGH Threat Level: Standard Bank on ransomware.live (108th victim), Ekurhuleni R2B fraud at SCOPA, ShinyHunters 12 May Canvas deadline hits 5 SA institutions, APT28 SAMA financial expansion flagged.</description>
      <category>StandardBank</category>
      <category>Ekurhuleni</category>
      <category>ShinyHunters</category>
      <category>Canvas</category>
      <category>Polmed</category>
      <category>APT28</category>
      <category>SAMA</category>
      <category>PANOS</category>
      <category>DefenderZeroDay</category>
      <category>POPIACompliance</category>
      <enclosure url="https://www.threatintelligence.co.za/pdf/dp-sa-threat-intel-2026-w20.pdf" length="750470" type="application/pdf" />
    </item>
    <item>
      <title>Weekly Threat Intel: South Africa Week 19 (27 April – 3 May 2026)</title>
      <link>https://www.threatintelligence.co.za/reports/threat-intel-w19-26.html</link>
      <guid isPermaLink="true">https://www.threatintelligence.co.za/reports/threat-intel-w19-26.html</guid>
      <pubDate>Mon, 04 May 2026 06:00:00 +0200</pubDate>
      <description>HIGH Threat Level: Stormous claims CGCSA (151K+ docs, Unilever/Nestlé partner data), SA victim count 107, IR files first major court action against Blouberg Municipality, 15 CISA KEV entries.</description>
      <category>CGCSA</category>
      <category>Stormous</category>
      <category>StandardBank</category>
      <category>BloubergMunicipality</category>
      <category>POPIAEnforcement</category>
      <category>ConnectWise</category>
      <category>MedusaRansomware</category>
      <category>APT28</category>
      <category>NTLMExploit</category>
      <category>DefenderZeroDay</category>
      <enclosure url="https://www.threatintelligence.co.za/pdf/dp-sa-threat-intel-2026-w19.pdf" length="748607" type="application/pdf" />
    </item>
    <item>
      <title>Weekly Threat Intel: South Africa Week 18 (20–26 April 2026)</title>
      <link>https://www.threatintelligence.co.za/reports/threat-intel-w18-26.html</link>
      <guid isPermaLink="true">https://www.threatintelligence.co.za/reports/threat-intel-w18-26.html</guid>
      <pubDate>Mon, 27 Apr 2026 06:00:00 +0200</pubDate>
      <description>HIGH Threat Level: Standard Bank scope expands to cards/passports, XP95 deadline lapsed, Polmed breaks publicly, Defender zero-day trilogy, 13 new CISA KEV entries.</description>
      <category>StandardBank</category>
      <category>XP95</category>
      <category>Polmed</category>
      <category>ShinyHunters</category>
      <category>DefenderZeroDay</category>
      <category>BitwardenSupplyChain</category>
      <category>CISAKOV</category>
      <category>OracleCPU</category>
      <category>POPIACompliance</category>
      <enclosure url="https://www.threatintelligence.co.za/pdf/dp-sa-threat-intel-2026-w18.pdf" length="725107" type="application/pdf" />
    </item>
    <item>
      <title>Weekly Threat Intel: South Africa Week 17 (13–19 April 2026)</title>
      <link>https://www.threatintelligence.co.za/reports/threat-intel-w17-26.html</link>
      <guid isPermaLink="true">https://www.threatintelligence.co.za/reports/threat-intel-w17-26.html</guid>
      <pubDate>Mon, 20 Apr 2026 06:00:00 +0200</pubDate>
      <description>CRITICAL Threat Level: Standard Bank 1.2TB released, XP95 deadline arrives, Polmed/SAPS data exposed, Adumo POS on dark web, Cisco IOS-XE zero-day. SA's most severe concurrent cyber crisis on record.</description>
      <category>StandardBank</category>
      <category>ROOTBOY</category>
      <category>Polmed</category>
      <category>ShinyHunters</category>
      <category>Adumo</category>
      <category>XP95</category>
      <category>CiscoIOSXE</category>
      <category>SaltTyphoon</category>
      <category>POPIACompliance</category>
      <category>CriticalThreat</category>
      <enclosure url="https://www.threatintelligence.co.za/pdf/dp-sa-threat-intel-2026-w17.pdf" length="709385" type="application/pdf" />
    </item>
    <item>
      <title>Weekly Threat Intel: South Africa Week 16 (6–12 April 2026)</title>
      <link>https://www.threatintelligence.co.za/reports/threat-intel-w16-26.html</link>
      <guid isPermaLink="true">https://www.threatintelligence.co.za/reports/threat-intel-w16-26.html</guid>
      <pubDate>Mon, 13 Apr 2026 06:00:00 +0200</pubDate>
      <description>HIGH Threat Level: XP95 deadline 7 days away, Salt Typhoon first SA telecom breach confirmed, Krybit claims Megasurf, IR compels dual-entity Liberty/Standard Bank disclosure.</description>
      <category>XP95</category>
      <category>SaltTyphoon</category>
      <category>StatsSA</category>
      <category>GCRA</category>
      <category>Megasurf</category>
      <category>Krybit</category>
      <category>LibertyBreach</category>
      <category>StandardBank</category>
      <category>POPIACompliance</category>
      <category>NationState</category>
      <enclosure url="https://www.threatintelligence.co.za/pdf/dp-sa-threat-intel-2026-w16.pdf" length="593006" type="application/pdf" />
    </item>
    <item>
      <title>Weekly Threat Intel: South Africa Week 15 (Mar 30–Apr 5, 2026)</title>
      <link>https://www.threatintelligence.co.za/reports/threat-intel-w15-26.html</link>
      <guid isPermaLink="true">https://www.threatintelligence.co.za/reports/threat-intel-w15-26.html</guid>
      <pubDate>Mon, 06 Apr 2026 06:00:00 +0200</pubDate>
      <description>HIGH Threat Level: XP95 claims Stats SA and GCRA, DragonForce hits Singita, three critical edge-device CVEs actively exploited, SA victim count reaches 103, and Liberty investigation escalates to CEO level.</description>
      <category>XP95</category>
      <category>StatsSA</category>
      <category>GCRA</category>
      <category>DragonForce</category>
      <category>Singita</category>
      <category>F5BIGIP</category>
      <category>CitrixNetScaler</category>
      <category>FortiClientEMS</category>
      <category>LibertyBreach</category>
      <category>POPIACompliance</category>
      <enclosure url="https://www.threatintelligence.co.za/pdf/dp-sa-threat-intel-2026-w15.pdf" length="565899" type="application/pdf" />
    </item>
    <item>
      <title>Weekly Threat Intel: South Africa Week 14 (Mar 23-29, 2026)</title>
      <link>https://www.threatintelligence.co.za/reports/threat-intel-w14-26.html</link>
      <guid isPermaLink="true">https://www.threatintelligence.co.za/reports/threat-intel-w14-26.html</guid>
      <pubDate>Mon, 06 Apr 2026 06:00:00 +0200</pubDate>
      <description>HIGH Threat Level: XP95 claims Stats SA, Liberty breach hits 3.2M customers, DragonForce leak volume confirmed at 316GB, F5 BIG-IP RCE exploited by Chinese state actors, and AI-powered banking fraud surges.</description>
      <category>XP95</category>
      <category>StatsSA</category>
      <category>LibertyBreach</category>
      <category>DragonForce</category>
      <category>F5BIGIP</category>
      <category>AIBankingFraud</category>
      <category>Tycoon2FA</category>
      <category>POPIAEnforcement</category>
      <enclosure url="https://www.threatintelligence.co.za/pdf/dp-sa-threat-intel-2026-w14.pdf" length="522744" type="application/pdf" />
    </item>
    <item>
      <title>Weekly Threat Intel: South Africa Week 13 (Mar 16-22, 2026)</title>
      <link>https://www.threatintelligence.co.za/reports/threat-intel-w13-26.html</link>
      <guid isPermaLink="true">https://www.threatintelligence.co.za/reports/threat-intel-w13-26.html</guid>
      <pubDate>Thu, 26 Mar 2026 06:00:00 +0200</pubDate>
      <description>HIGH Threat Level: Cisco FMC CVSS 10.0 actively exploited by Interlock ransomware, SA insurance sector hit, and POPIA enforcement escalates to real fines.</description>
      <category>InterlockRansomware</category>
      <category>CiscoFMC</category>
      <category>DragonForce</category>
      <category>POPIAEnforcement</category>
      <category>BECFraud</category>
      <category>AIVoiceSpoofing</category>
      <category>GautengBreach</category>
      <category>NFCScam</category>
      <enclosure url="https://www.threatintelligence.co.za/pdf/dp-sa-threat-intel-2026-w13.pdf" length="509465" type="application/pdf" />
    </item>
    <item>
      <title>Weekly Threat Intel: South Africa Week 12 (Mar 9-15, 2026)</title>
      <link>https://www.threatintelligence.co.za/reports/threat-intel-w12-26.html</link>
      <guid isPermaLink="true">https://www.threatintelligence.co.za/reports/threat-intel-w12-26.html</guid>
      <pubDate>Mon, 23 Mar 2026 06:00:00 +0200</pubDate>
      <description>HIGH Threat Level: Gauteng 3.8TB data breach, Chinese state-sponsored telecom espionage, and new POPIA health regulations now in force with R10M penalties.</description>
      <category>GautengBreach</category>
      <category>SaltTyphoon</category>
      <category>Ransomware</category>
      <category>POPIAHealth</category>
      <category>ChromeZeroDay</category>
      <category>CiscoAlert</category>
      <category>PatchTuesday</category>
      <category>BECFraud</category>
      <enclosure url="https://www.threatintelligence.co.za/pdf/dp-sa-threat-intel-2026-w12.pdf" length="503408" type="application/pdf" />
    </item>
    <item>
      <title>Weekly Threat Intel: South Africa Week 11 (Mar 07-13, 2026)</title>
      <link>https://www.threatintelligence.co.za/reports/threat-intel-W11-26.html</link>
      <guid isPermaLink="true">https://www.threatintelligence.co.za/reports/threat-intel-W11-26.html</guid>
      <pubDate>Fri, 13 Mar 2026 06:00:00 +0200</pubDate>
      <description>ELEVATED Threat Level: Analysis of critical CVSS 10.0 vulnerabilities in Cisco infrastructure and new POPIA enforcement trends.</description>
      <category>CiscoAlert</category>
      <category>ChromeZeroDay</category>
      <category>POPIAHealth</category>
      <category>PatchTuesday</category>
      <enclosure url="https://www.threatintelligence.co.za/pdf/dp-sa-threat-intel-2026-w11.pdf" length="232841" type="application/pdf" />
    </item>
  </channel>
</rss>
