![]()
Black Hat USA 2026 — Lumu, the creators of the Continuous Compromise Assessment® security model, today announced the release of Lumu Threat Observatory™ as part of Maltiverse, its threat intelligence solution. Lumu Threat Observatory is Maltiverse’s live, personalized threat-intelligence experience, providing organizations with a complete, live view of the active threats targeting their specific sector, helping them spot malicious adversaries early, prioritize vulnerabilities, and automatically block them.
While threat intelligence is now a foundational piece of an organization’s security strategy, most IT and security teams have limited visibility into the specific actors targeting their exact industry or region. Instead of actionable clarity, they are left drowning in a sea of generic, noisy data feeds that obscure real risk. The new Lumu Threat Observatory closes that gap. Powered by the global threat intelligence repository of Maltiverse, the Lumu Threat Observatory functions as a live threat dashboard and an open, connected research encyclopedia. It continuously evaluates global attacker behaviors, tracking specific threat groups, the malware families they deploy, the MITRE techniques they use, and the CVEs they actively exploit.
Lumu closely maps out the entire story behind the identified attackers, allowing security teams to instantly look up adversaries targeting organizations like theirs and automatically bundle live threats into custom intelligence feeds to deploy directly into their existing security stack. Instead of overwhelming organizations with a generic catalog of global threats, Lumu Threat Observatory delivers hyper-localized, industry-specific intelligence detailing exactly what is attacking them right now, and how to stop it.
“Today’s security teams don’t suffer from a lack of threat intelligence; they suffer from a lack of context. While threat data has become a standard security component for modern security teams, it remains frustratingly generic, leaving teams to sift through noisy feeds without knowing which specific actors are actively targeting their industry or region. Without targeted visibility, security teams are defending against everything and nothing at the same time, drowning in alert fatigue, missing critical blind spots, and guessing which patches to prioritize. We created the Lumu Threat Observatory to eliminate the guesswork, delivering the precise intelligence security teams need to confidently secure their unique organization against the threats that matter most,” said Ricardo Villadiego, founder and CEO of Lumu.
Lumu Threat Observatory includes:
- Tailored Threat Visibility: The Lumu Threat Observatory enables users to see exactly which threat actors and malware are actively targeting organizations within a customer’s specific vertical and region in real time.
- Connected Threat Research: Users can instantly look up malware families or threat actors to see their history, behavioral patterns, and exploited CVEs for fast, precise action.
- Customized Feeds: Lumu Threat Observatory automatically bundles live threats into a targeted threat feed and deploy it straight to a user’s Firewall, SIEM, or EDR in seconds.
- Vulnerability Prioritization: Pinpoint the exact CVEs actively weaponized against peers, ensuring an organization deploys the patches that matter most.
- Live Telemetry, Validated IoCs: Every indicator is validated by live attack telemetry to stop stale data from wasting firewall and EDR capacity.
Also this week at Def Con in Las Vegas, Mario Lobo Romero, a cyber threat intelligence researcher at Lumu, is presenting Almaru C2 research at 1pm PDT on Friday, August 7 at La Villa Hacker and 2pm PDT on Saturday, August 8 at Red Team Village. AImaru C2 is an AI-driven Red Team framework that automates Living off the Land tactics by subverting Anthropic’s Model Context Protocol to covertly tunnel C2 traffic through legitimate LLM API communications. His research demonstrates how this platform allows operators to execute complex PowerShell actions and evade defenses using high-level natural language prompts rather than manual exploitation syntax.
Available now, Lumu Threat Observatory delivers real-time, personalized threat intelligence that provides a customized briefing to customers. To learn more about Lumu’s industry-leading cybersecurity solutions, visit lumu.io.
About Lumu
Lumu is a cybersecurity company that helps organizations operate cybersecurity proficiently by measuring and understanding compromise in real time. Through its Continuous Compromise Assessment® model, Lumu empowers security teams to act immediately on confirmed compromises and minimize risk exposure. For more information, visit www.lumu.io.
View source version on businesswire.com: https://www.businesswire.com/news/home/20260804892636/en/
Media gallery
