The United States is facing an escalating threat landscape, with cyberattacks from nation-state adversaries such as China, Russia, North Korea, and Iran becoming more sophisticated and coordinated. These adversaries are not only sharing cyber intelligence and best practices among themselves but are also leveraging advanced tactics, including exploiting third-party vulnerabilities and supply chain weaknesses. Recent high-profile incidents, such as the SolarWinds, MOVEit, and Crowdstrike Linux breaches, have demonstrated the devastating impact that a single compromised vendor can have on thousands of organizations. The traditional approach to third-party risk management, which relies on static checklists and periodic audits, is no longer sufficient, as attackers exploit the gaps between assessments. Intelligence-led, continuous monitoring of vendor ecosystems is now essential to detect and respond to emerging threats in real time. The speed at which attackers weaponize vulnerabilities has dramatically increased, with the average time to exploit (TTE) dropping from 63 days in 2019 to about 5 days in 2023, and even turning negative in 2024. This means attackers are now exploiting vulnerabilities before patches are even available, often by infiltrating disclosure pipelines or accessing leaked code repositories. As a result, organizations can no longer rely solely on timely patching and must instead focus on engineering resilience, rapid detection, containment, and recovery. The need for robust, real-time threat information sharing between the private sector and the federal government is more urgent than ever. Legislative efforts, such as the Protecting America from Cyber Threats Act, aim to reauthorize and expand the Cybersecurity Information Sharing Act of 2015, providing modernized legal protections and clarifying roles to facilitate more effective collaboration. Information sharing not only enhances technical defenses but also supports the mental resilience of CISOs, who benefit from peer collaboration and early warnings about emerging threats. The collective defense enabled by information sharing allows organizations to better understand the scale and scope of threats, prioritize responses, and reduce the cost and impact of breaches. As adversaries continue to innovate and accelerate their attacks, the U.S. must adapt by fostering a culture of proactive intelligence sharing, continuous monitoring, and cyber resilience across both public and private sectors.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
1 event from the most recent confirmed update back to the earliest known activity.
Initial story creation
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcerecordedfuture.com
Open sourcecio.com
Open sourcescworld.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.