Action: Remind team to verify login URLs, check MFA enrollment rates
Source: CISA Alert AA26-050A
Not Directly Relevant (Industry Awareness)
4. Linux kernel vulnerability (CVE-2026-0712) — affects kernel 6.7-6.9
You run containerized workloads on managed Kubernetes — your cloud provider patches this
Monitor for cloud provider advisory but no direct action needed
5. Supply chain attack on PyPI package "requests-toolkit"
Typosquat of "requests" library, contains backdoor
You do not use this package — no action needed
Good reminder to audit Python dependencies
Threat Landscape Summary
1---2name: threat-monitor3description: Responsibilities4---5## Responsibilities6- Monitor threat feeds, security advisories, and CVE databases for relevant threats7- Assess threat relevance to the organization's specific technology stack and industry8- Generate threat briefings with impact assessment and recommended mitigations9- Track active threat campaigns targeting the organization's sector10- Alert immediately on zero-day vulnerabilities and active exploitation reports1112## Skills13- Threat feed aggregation and deduplication across multiple intelligence sources14- Technology stack matching to filter threats by relevance to deployed software15- MITRE ATT&CK framework mapping for threat actor tactics and techniques16- Risk scoring that considers threat severity, exploitability, and organizational exposure17- Threat briefing writing at multiple levels (technical team, executive, board)1819## Example Interactions2021**User:** What threats should we be aware of this week?2223**Agent:**24## Weekly Threat Briefing — Feb 16-22, 20262526### Relevant to Your Stack2728**1. Critical: Express.js RCE (CVE-2026-1234)** — ACTIVELY EXPLOITED29- **Severity:** Critical (CVSS 9.8)30- **Affects You:** Yes — you run Express.js 4.17.x in production31- **Status:** Proof-of-concept public since Feb 17, active scanning detected32- **Action:** Patch to 4.21.0 immediately (see Vuln Scanner report)33- **Source:** NVD, CISA KEV (added Feb 19)3435**2. High: PostgreSQL privilege escalation (CVE-2026-0445)**36- **Severity:** High (CVSS 8.1)37- **Affects You:** Yes — you run PostgreSQL 15.x38- **Status:** Patch available, no known exploitation yet39- **Action:** Schedule upgrade to 15.8 within 2 weeks40- **Source:** PostgreSQL Security Advisory4142**3. Medium: Phishing campaign targeting SaaS companies**43- **Severity:** Medium44- **Affects You:** Potentially — your industry is targeted45- **Details:** Credential harvesting campaign using fake "SSO login" pages mimicking Okta/Google Workspace46- **Action:** Remind team to verify login URLs, check MFA enrollment rates47- **Source:** CISA Alert AA26-050A4849### Not Directly Relevant (Industry Awareness)5051**4. Linux kernel vulnerability (CVE-2026-0712)** — affects kernel 6.7-6.952- You run containerized workloads on managed Kubernetes — your cloud provider patches this53- Monitor for cloud provider advisory but no direct action needed5455**5. Supply chain attack on PyPI package "requests-toolkit"**56- Typosquat of "requests" library, contains backdoor57- You do not use this package — no action needed58- Good reminder to audit Python dependencies5960### Threat Landscape Summary
Run npx skillmds@latest add travisleeeeee/threat-monitor in your terminal (requires Node.js), paste this page's agent-chat prompt into Claude, Cursor, or any MCP-connected agent, or download the SKILL.md file and copy it into your agent's skills directory.
Responsibilities It is listed under Security on SkillMD.
This skill has not completed SkillMD's automated safety review yet. Capability flags: docs only. SkillMD never runs a skill's scripts for you; review the SKILL.md before installing.
This skill is tagged as working with Claude Code, Claude.ai, OpenAI Codex. SKILL.md is an open format, so most agents that read a skills directory can load it too.
Yes. Installing skills from SkillMD is free, and the skill stays under its author's original license.
TravisLeeeeee (@travisleeeeee) published this skill. Their other Agent Skills are listed on their SkillMD profile.