IBM X-Force
ibm-xforce · B · active
https://www.ibm.com/think/x-force
IBM X-Force Threat Intelligence; annual X-Force Threat Index. URL CORRECTED 2026-05-08: legacy securityintelligence.com 301-redirects to www.ibm.com/think/security; the X-Force-specific sub-page is /think/x-force. The hub is a marketing portal rather than a dated blog; sub-agents reliably mis-report 'no items' because per-post dates are sparse in the listing. Drill into the X-Force Threat Intelligence Index (annual) and any podcast/webinar entries with explicit dates. Reliability MEDIUM until IBM publishes a clean dated archive again. | 2026-06-20 full audit (v2.62): live=Y, drill=Y. FETCH → bridge: python3 tools/fetch_source.py url https://www.ibm.com/think/x-force (listing) then bridge url <article /think/x-force/<slug>> for body. AVOID: WebFetch now 403s on BOTH the /think/x-force index AND article pages, skip WebFetch, go straight to the bridge. Listing has no inline per-post dates; read dateModified from the article HTML.. | 2026-07-05 admiralty audit: B, original vendor threat research; listing lacks inline dates so read dateModified from the article HTML via bridge. MEDIUM->B, stays active. | 2026-09-13 quality audit (G3 broken-recipe duty, closing 2026-09-06 recommendation 3): STILL BROKEN, same diagnosis as reliaquest: extract, jina and bridge url all return a marketing/nav shell with no drillable dated listing. Not a 403. Left active and NOT demoted; raised as an audit recommendation. At 3 consecutive quiet periods. | 2026-09-20 quality audit (G3 re-probe): still dark. url / extract / sitemap guesses / two RSS candidates all return a content-free template shell or pre-window content only. Not demoted (a 403 or a shell is not death, and demoting a vendor research feed widens the blind spot it exists to close); carried as a known gap.
Cited in 5 entries
Citation cadence
Citation days per ISO week (12 weeks of coverage span, total 4).
- Mustang Panda's CoolClient backdoor gains a kernel driver signed with a 2013 certificate that expired in 2014, and it hides the malware's own C2 traffic by hooking the driver Windows uses to report network state2026-08-15
- CVE-2026-14512 / CVE-2026-14446, IBM WebSphere Application Server: two pre-auth CVSS 9.8 flaws with no workaround and no fix pack until 3Q2026 (interim APARs only)2026-08-01
- CVE-2026-0770, Langflow: CISA confirms active exploitation of an unauthenticated exec_globals RCE the same day a 15-CVE batch (incl. unauthenticated account creation) is patched in 1.10.12026-07-22
- CVE-2026-9170, IBM HTTP Server / WebSphere Application Server: pre-auth RCE via improper input validation (CVSS 9.8)2026-05-29
- CVE-2026-32996 & CVE-2026-32997, Veeam Backup & Replication KB4852: LPE in Windows Agent, arbitrary file write in Linux appliance2026-05-29