Open Knowledge
Threat analysis by The RabitaNoor (RBTN) Cyber Research Center
Overview of the Platform
Open Knowledge is an open‐source sharing platform that enables tenants of the RBTN - CYOI Pulpit to anonymously contribute threat analyses. This model encourages the open exchange of critical security information, improving situational awareness and collective defense.
The RBTN Ecosystem
RBTN as a Community or Network: The platform is part of the broader RBTN ecosystem—a network that values transparency, community participation, and decentralized decision-making based on open-source principles.
CYOI - RBTN Pulpit: The CYOI - RBTN Pulpit is an AI and big data analytics platform where users create their own CTI to bypass bias. Open Knowledge is a dedicated channel within the RBTN ecosystem for sharing structured threat analyses publicly.
Rubrics (Threat Analysis)
-
Exploitation of FortiGate Authentication Vulnerability CVE-2025-59718
Attackers exploiting FortiGate vulnerability CVE-2025-59718
-
CVE-2026-20929: Windows Kerberos CNAME Vulnerability Exploitation
Threat actors exploiting CVE-2026-20929 to conduct credential-relay attacks.
-
Cyberattack on Petróleos de Venezuela (PDVSA) Disrupts Export Operations
The adversary is suspected to be foreign interests in collusion with domestic conspirators, possibly linked to the United States.
-
Motex Lanscope Flaw Exploited by Tick Group to Deploy Gokcpdoor
The Tick group is a suspected Chinese cyber espionage actor known for targeting sectors aligned with their intelligence objectives.
-
Russian Influence Operations Targeting Moldova's 2025 Parliamentary Elections
Russian state-linked actors conducting influence operations to destabilize Moldova's elections.
-
Google Urges Gmail Users to Reset Passwords After Salesforce Breach
The cybercriminal group UNC6040 is responsible for the breach, using voice phishing to impersonate IT support.
-
Elastic EDR 0-Day Flaw: A Security Tool Turned Threat
The adversary exploits a zero-day vulnerability in Elastic's EDR software.
-
Gunra Ransomware Expands to Cross-Platform with Enhanced Encryption
Gunra ransomware group, known for cross-platform attacks.
-
BERT Ransomware Expands to Linux with Weaponized ELF Files
The BERT ransomware group is a sophisticated adversary targeting both Windows and Linux systems.
-
Operation Checkmate: BlackSuit Ransomware Sites Seized
The BlackSuit ransomware group, previously known as Royal and Quantum, is involved in extortion and data breaches.