Firewall integrations

Fortinet

Elevate the power of your Fortinet Fortigate Firewall using by adding our Intelligence.

Palo Alto

Palo Alto Firewalls can be hardened with our threat intelligence as well.

Sophos XGS

Enhance the Sophos XGS Firewall with our threat intelligence.

OPNsense

Enhance your OPNsense Firewall with our threat intelligence using the native plugin.

SIEM integrations

Splunk

Splunk is a great platform, but without the right Threat Intelligence it's just a log server. Try our threat intelligence today. 

Microsoft Sentinel

One of the most used SIEM solutions should be enriched with the right Intelligence. At Q-Feeds you're at the right place!

Other

Luckily there are many other SIEM vendors whom support 3rd party threat intelligence.

Threat Intelligence Portal

Darkweb Monitoring

Darkweb monitoring is one of our services, not only for threat intelligence but also for you most important assets.

Threat Lookup

With Threat Lookup you get full insights in our IOC database, including full MITRE ATT&K mapping.

External Attack Surface Management

A toolset to check your external facing assets exposed on the internet

Vulnerability Scanner

A comprehensive vulnerability scanner which can scan your infrastructure and web applications

Brand Protection

Protect your brand for look-a-likes and potential phishing attempts

Services

TAXII Feeds & Server Software

TAXII/STIX2.1 standard. Both in form of feeds and server software available

Implementation

Need help with implementations? No worries, we have a strong network of partners who are able to help you.

Solutions

Enrich my SIEM

Elevate the power of your SIEM solution using by adding our Intelligence.

Enrich my Firewall

Firewalls can be hardened with our threat intelligence as well.

Prevent phishing

Enhance your protection against phishing

Achieve compliancy

Achieve compliancy by correlating the best threat intelligence to your logs

Futuristic eye design with circuits and geometric shapes.

Company

About

Read here all about Q-Feeds

News and Updates

Cybersecurity news and updates about us

Publications

All of our media coverage in one place

Become a reseller

Strengthen your portfolio with our comprehensive reseller program

Partner locator

Find our certified partners here

Contact

For all your questions or inquiries

Neural network representation of a human brain

Support

My Account

Access your account and manage your licenses

Downloads & Manuals

On this page you find white papers and manuals

Knowledge base

Our knowledge base full of implementation instructions

Start for free

Start your cyber security intelligence journey here

Abstract geometric wireframe human head

Uncovering the VShell and SparkRAT tactics in the BeyondTrust CVE-2026-1731 exploit

Feb 20, 2026 | Threat Intelligence Research

Critical Vulnerability CVE-2026-1731 in BeyondTrust Software Under Active Exploitation

TL;DR: BeyondTrust has announced a severe pre-authentication remote code execution vulnerability (CVE-2026-1731), affecting its remote support software. This flaw is being actively exploited, particularly targeting multiple sectors globally, with a high risk of data theft and system compromise.

On February 6, 2026, BeyondTrust disclosed CVE-2026-1731, a critical vulnerability that allows unauthorized remote code execution in its remote support software. An attacker can exploit this vulnerability without prior authentication, enabling them to run arbitrary OS commands with elevated privileges. This flaw has been added to the U.S. Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities catalog, indicating the urgency for remediation given its potential for severe impact on system integrity and confidentiality.

Unit 42, part of Palo Alto Networks, is investigating extensive exploitation patterns following the vulnerability’s revelation. Attackers have performed network reconnaissance, deployed web shells, and executed command-and-control (C2) operations. Reports indicate that sectors such as financial services, healthcare, and higher education in the U.S., Canada, and Europe are severely affected. The ongoing campaign has revealed the installation of backdoors, remote management tools, and significant data theft involving sensitive configurations and database exports.

Why this matters: The exploitation of CVE-2026-1731 poses a pronounced risk across critical industries, which may suffer significant data breaches and operational disruptions. Organizations must prioritize security measures to safeguard their assets and prevent further exploitation of such vulnerabilities.

To mitigate risks, defenders should employ proactive measures like threat intelligence to monitor for indicators of compromise and vulnerability scans to identify unpatched systems. Implementing SIEM solutions can facilitate real-time detection of anomalies, while firewalls can help block unauthorized access attempts.

Indicators of Compromise (IOCs): Notable IPs associated with the attacks include:

  • 23.162.40[.]187
  • 68.183.60[.]153
  • 85.155.186[.]121

Malware hashes such as for SparkRAT:

  • 9f431d5549a03aee92cfd2bdbbe90f1c91e965c99e90a0c9ad5a001f4e80c350

These indicators highlight the active threat landscape and emphasize the need for immediate remedial action.

Click here for the full article

Try our Intelligence today!

Streamline your security operations with a free Q-Feeds trial and see the difference.

Other articles