Threat+Constellation
Live UTC

Emerging Signals

Weak signals before they become incidents.

Weak signal → Emerging pattern → Active campaign → Confirmed incident

Signal examples shown in this preview are illustrative.

SIGNAL 088Network anomaly

DDoS spike against public portals

Short, repeated volumetric bursts targeting public portals.

Confidence 69%210% / 24h
UkraineUnited KingdomGovernmentFinance
Hacktivist cluster
First observed 00:40 UTCConstellation →
SIGNAL 103Emerging signal

Credential abuse in healthcare

Valid-account logins from atypical geographies suggest infostealer-sourced credentials.

Confidence 58%88% / 24h
United StatesHealthcare
CVE-2026-5177
First observed 23:05 UTCConstellation →
SIGNAL 067Active campaign

Shared remote-access infrastructure

The same VPN architecture appears across manufacturing and energy operators.

Confidence 77%63% / 24h
JapanGermanyManufacturingEnergy
CVE-2026-4821APT-XX
First observed 03:12 UTCConstellation →
SIGNAL 042Emerging signal

VPN exploitation activity accelerating

Exploitation attempts against exposed VPN concentrators are rising well above the 30-day baseline across three regions.

Confidence 84%218% / 24h
JapanGermanyTaiwanEnergyManufacturing
CVE-2026-4821APT-XX
First observed 08:42 UTCConstellation →
SIGNAL 110Active campaign

Phishing surge targeting finance

Finance-themed lures deploying a loader associated with a known campaign cluster.

Confidence 74%121% / 24h
United KingdomFinance
APT-Meridian
First observed 22:10 UTCConstellation →
SIGNAL 037Active campaign

Credential phishing targeting logistics

Lookalike domains harvesting freight-operator credentials across East Asian logistics firms.

Confidence 79%121% / 24h
South KoreaSingaporeLogistics
APT-Meridian
First observed 06:10 UTCConstellation →