Warning · Severe (Severe Tstm / Red Flag / Winter)
Watch
Advisory · Statement
NEXRAD Radar (animated)
⛈️
National Weather Map
Loading NWS active alerts, NIFC wildfires, NEXRAD radar… If this persists, check the Google Maps API key referrer allowlist for this host. Polygons show active NWS alerts · pins show active wildfires (sized by acres) and major-city forecasts · animated NEXRAD radar overlays via RainViewer.
—
02 · Threat Trajectory
90-Day Trends · Posture Trajectory by Domain
Daily-scored composite indices across four threat domains · annotated with major posture-shifting events · agent-tracked, human-reviewed
7d30d90d
Domain Index · 0–100 · Today / Δ 90d
Cyber71▲ +29
Public Safety54▲ +16
Civil Unrest62▲ +30
Foreign Posture60▲ +9
🎯 Top Trending Targets · 90d
Sector / asset class · activity intensity
01
Telecom Carriers · POPs / Switching Centers
Salt Typhoon · 9 named US carriers · lawful-intercept access
Russia ICS targeting · operational tempo softening post-attribution
−8%
🧩 Pattern Emergence
Cross-domain analytical synthesis
ConvergenceState-actor pre-positioning + domestic accelerationism rising in parallel
Cyber and civil-unrest curves have both climbed steadily over 90 days — cyber driven by PRC tradecraft maturation, unrest driven by summer-cycle mobilization. The pattern that matters: they overlap in target sets we cover in the convergence section.
SeasonalSummer event cycle approaching against rising counter-protest indicators
Civil unrest trajectory is on a cycle-matching curve with similar 2023 and 2024 inflection points. Counter-protest chatter velocity (OSINT Pulse) is leading the curve by ~10 days. Expect peak intensity Jun 28 – Jul 6.
CascadeEastern Med + Sahel L4 cohort consistent with continued deterioration
Foreign posture curve has stepped up 3 times in the 90-day window — Niger (day 45), Lebanon (day 87), and a smaller West Africa adjustment between. Trajectory implies at least one further L4 escalation likely before Q3.
OSINT Pulse · Social Signal Monitoring · X + Telegram + RSS
Volume-velocity + sentiment analysis · 4h rolling window · agent-extracted signals, not raw feeds
✕ X / Beirut
▲ 11× normal
Beirut residents posting Hezbollah-positioned strike imagery from Dahiyeh
Geolocated posts 11× baseline volume in trailing 4 hours. Imagery consistent with prior strike-warning patterns. Sentiment skew: fear + departure-planning indicators rising. Cross-references Lebanon L3→L4 advisory escalation.
Maya · 18mSentiment ▲
▲ Telegram / REMVE
▲ 3.4× normal
Accelerationist channels coordinating around Pride parade routes — 6 city threads active
Patriot Front + Active Club adjacent channels showing coordinated tactical-planning vocabulary against June parade routes in flagged cities. Counter-protest mobilization tempo aligns with FBI national soft-target advisory.
Marcus · 47mThreat ▲
✕ X / Tehran-aligned
▲ 2.8× normal
IRGC-affiliated and Hezbollah-adjacent accounts amplifying retaliation rhetoric
Persian-language influencers and Hezbollah-aligned diaspora accounts amplifying retaliation framing at sustained elevated tempo. Targeting language references former US officials and Israeli-aligned facilities. Cross-references MuddyWater operational tempo.
SJP + JVP affiliated accounts coordinating commencement-day disruption tactics across 4 named encampments. Counter-protest accounts mobilizing in parallel at 3 of those sites — the convergence is the elevation indicator.
Marcus · 2hMixed ◆
📡 Vendor / Cyber
▲ 8× normal
Salt Typhoon disclosure cycle accelerating — carrier confirmations cascading
Vendor and security-journalist accounts confirming 3 additional named carriers compromised in trailing 24h. Sustained reporting velocity suggests further disclosures imminent. Cross-references our convergence finding on telecom POP physical access.
Darius · 3hSeverity ▲
✕ X / Colombia
▼ 0.6× normal
Colombia northern-departments sentiment normalizing as security improvements take hold
Local accounts and journalists reporting reduced threat-condition vocabulary. Travel-industry accounts resuming Northern Colombia promotion. Validates State Dept L3→L2 downgrade we picked up 18 days ago.
Maya · 6hSentiment ▼
⚠ Social signals are indicators not assessments · raw posts are not displayed · all signals require agent extraction + human review before promotion to curated sections · platforms monitored under their public-API terms
Social Pulse · Last 24h · National Feed
Social Pulse hydrates daily at 06:55. Curated national-focus accounts (CISA, federal agencies, named security reporters).
About This Picture · How it's built · Why it's curated
● Live · Daily Refresh · Analyst-Reviewed
What This Is
Curated national operating picture · cross-domain fusion no single source produces: foreign state actors + terror groups + travel posture + civil unrest + cyber + KEVs + physical-cyber overlap, in one analyst-ready view.
Sources
CISA · FBI · NCTC · DHS · State Dept · OFAC · NERC E-ISAC · USMS · state + regional fusion centers · vetted OSINT · CISA KEV catalog. Curation by GSC intelligence agents with named human-analyst review.
Update Cadence
Foreign posture weekly · CONUS unrest + incidents 2× daily · state-aligned cyber + KEV hourly · convergence findings reviewed by human analyst before publication.
Confidence & Workflow
Per-item High/Med/Low assessment. Live product adds analyst search · sector lenses · watchlists · STIX/CSV/PDF export · API. This view is the curated daily synthesis — not the full workspace.
Emerging · Under Assessment
5 items in queue · last review 8m ago · agents auto-promote on confidence threshold
Scout + Research Team · 6 agents feeding the directors continuously
Caleb Brooks
Federal Scout
Rafael Torres
CA / State + Local
Priya Shaw
Commercial Sector
Tessa Monroe
Physical Threat
Noah Kim
Cyber Threat
Amara Wells
Research + Enrichment
Governance. All agents are AI workforce members trained on domain corpora, supervised by named human review. Convergence findings require human analyst sign-off before publication. AI-disclosure standard applied to all outputs. Source attribution carried on every finding.
03 · State Actors
Foreign-State Activity Affecting CONUS
Foreign-state operations and influence campaigns with measurable CONUS effect · IC + open-source synthesis
5 active
14d window
Analyst's Take
The throughline this cycle is patience. China's Volt and Salt operations are textbook state-actor pre-positioning — no kinetic action, just persistence in the right places, with strategic dormancy timed against a future Taiwan-contingency window. Russia is reactivating its 2024-vintage influence playbook 18 months early, which suggests Moscow is anchoring on the 2026 midterm cycle as its primary asymmetric lever; Sandworm energy targeting and APT28 spear-phishing of campaign infrastructure are the two indicators we'd weight most heavily. Iran remains the wildcard — capability is real, the post-Gaza retaliation rhetoric is real, but signal-to-noise on actual operational planning indicators is poor. We're watching former-official targeting, Iranian-American dissident threats, and Jewish/Israeli facility patterns as the leading edge. DPRK is doing what DPRK does: monetizing the West to fund the regime via crypto theft and IT-worker infiltration — Lazarus alone is a $800M+ trailing-12-month exposure across US victims.
People's Republic of China
State · APT
Elev
Volt Typhoon grid + water pre-positioning continues. Salt Typhoon expanding telecom carrier compromise. Tech export-control evasion via shell entities.
Ops ImpactCarrier + utility-vendor engagements carry IC sensitivity. Salt Typhoon IOC sweep at carrier-adjacent assets recommended.
Demonstration coordination via state-affiliated information channels. Russia-aligned narrative amplification. PRC United Front activity on US campuses.
Ops ImpactPre-pulse demonstration channels worth tracking; campus engagement monitoring at named institutions.
The picture this cycle skews domestic. Among the foreign-designated groups, ISIS-K remains the only one demonstrating both intent and capability to induce CONUS lone-actor attacks — the Moscow Crocus model (Mar 2024) confirms operational viability and inspiration material continues to circulate. Al-Qaeda core has degraded; AQAP is publishing but not operating. Iran-aligned (IRGC + Hezbollah) is the FTO category we'd weight up given DOJ-disclosed plot disruptions and the post-Gaza retaliation cycle. The active concern is REMVE accelerationism converging on the Pride Month + summer event cycle — Patriot Front mobilization, Active Club expansion, and Atomwaffen-derivative messaging are tracking against the same June-September calendar that historically produces lone-actor attacks. The FBI's national soft-target advisory issued 3 days ago raised our internal threshold, and the AGAAVE militia / sovereign-citizen category is independently elevating around 2026 election cycle rhetoric. The convergence section below flags where these domestic threats overlap with state-aligned OT activity — a pattern single-domain feeds miss.
FTO · Foreign
4
State Dept designated
DVE · Domestic
2
REMVE + AGAAVE
HVE · Homegrown
1
Lone-actor radicalization
Active Plots
3
Disruptions trailing 30d
ISIS / ISIS-K
FTO · State Dept Designated
Active
Inspiration-driven threats continue. ISIS-K propaganda driving lone-actor radicalization indicators. Recent FBI advisory references ISIS-K material in summer event-cycle targeting. Group retains capability/intent demonstrated by Moscow Crocus attack (Mar 2024).
CONUS Target Profile
Soft targets · mass gatherings · houses of worship · LGBTQ+ venues · military/LE
FBI · NCTC · NCTC Worldwide ThreatLast advisory 3d
Al-Qaeda / AQAP
FTO · State Dept Designated
Watch
Core AQ operational capacity diminished post-decapitation. AQAP continues publishing inspiration content. Ideology persistent; capability primarily regional, with CONUS threats inspiration-based.
CONUS Target Profile
Aviation sector · military/LE · US embassies abroad · Western interests broadly
NCTC · FBIRoutine monitoring
Iran-Aligned (IRGC + Hezbollah)
FTO · IRGC 2019 · Hezbollah 1997
Elev
Post-Gaza retaliation cycle elevated. DOJ-disclosed IRGC plot disruptions against former US officials. Hezbollah financial network operations continue in CONUS per Treasury OFAC actions. Houthis affecting maritime shipping interests.
CONUS Target Profile
Former US officials · Iranian-American dissidents · Jewish / Israeli facilities
DOJ · FBI · Treasury OFAC · NCTCLast obs 8d
Hamas-Affiliated
FTO · State Dept Designated
Active
Fundraising and influence operations rather than direct attack capability in CONUS. Sympathetic charity-network infrastructure remains under continued FBI/Treasury monitoring. Demonstration-coordination overlap with state-proxy influence ops.
Recent FBI JTTF Houston arrest of domestic extremist plotting against state capitol. Sovereign citizen LE encounter trends elevated. Militia rhetoric around 2026 election cycle elevating. Anti-government messaging on federal facilities.
CONUS Target Profile
State capitols · federal buildings · courthouse infrastructure · LE personnel · election-related facilities
FBI JTTF · state fusion · ATFLast arrest 5d
HVE — Lone-Actor Radicalization
HVE · Homegrown Violent Extremist
Active
FBI national soft-target advisory active (issued 3d ago). Lone-actor radicalization via online accelerationist content + ISIS-K inspiration material. Concern pattern aligns with summer event cycles. Cross-ideological pollination observed.
CONUS Target Profile
Variable · soft targets predominantly · mass gatherings · festivals/concerts
FBI national advisory · NCTCActive · 3d ago
05 · Foreign Posture
Travel & Personnel Advisories · Global View
US State Department travel advisories with personnel-deployment relevance · Level 3 (Reconsider Travel) and Level 4 (Do Not Travel) destinations mapped globally
19 L4
25 L3
4 changed 30d
Analyst's Take
Lebanon's L4 upgrade is the headline of the week. Hezbollah-Israel cross-border tempo has crossed State Department's threshold and personnel posture for anyone with Beirut or eastern Mediterranean presence needs review in the next 72 hours — including departure-route planning given how quickly commercial aviation contracted during the 2024 escalations. The broader pattern in the Sahel — Niger and Burkina Faso both deteriorating, Mali continuing — represents an 18-month sustained regional collapse driven by JNIM and ISIS-Sahel expansion against weakened post-coup state security, and we expect at least one more L3→L4 escalation in the band before Q3. Mexico's six-state L4 designations remain the highest-volume CONUS-adjacent risk given executive travel volume and the cartel-violence overlap with corporate operations across the border. Russia's L4 stands apart: the wrongful-detention pattern is now policy, not anomaly, and any travel for any reason carries documented hostage risk against US persons. We're watching Venezuela and Colombia divergence carefully — Colombia just stepped down from L3 to L2, Venezuela is trending the other direction.
Global Advisory Map · L3 + L4 Destinations
L4 · Do Not Travel
L3 · Reconsider Travel
Recently changed
🌍
Global Advisory Map
Loading map tiles… If this persists, the Google Maps API key may be quota-exceeded, revoked, or missing this host in its referrer allowlist. Open browser DevTools → Console for the exact error. Pins show State Dept L3 and L4 destinations · click for advisory details.
Browse Destinations by Threat Level
Source · travel.state.gov
Travel Advisory Level
Destination
Level
Concerns
Updated
RussiaRU
L4
Wrongful detentionArmed conflict
5d ago
LebanonLB
L4
TerrorismArmed conflict
8d ago▲ L3→L4
Israel / GazaIL
L4 Gaza
TerrorismArmed conflict
11d ago
IranIR
L4
Wrongful detentionTerrorism
12d ago
UkraineUA
L4
Active war zone
4d ago
North KoreaKP
L4
Wrongful detention
60d ago
Mexico (6 states)MX
L4 states
Cartel violenceKidnapping
14d ago
HaitiHT
L4
Gang violenceCivil unrest
6d ago
Burkina FasoBF
L4
Terrorism (JNIM)
30d ago
NigerNE
L4
Terrorism (ISIS-Sahel)
21d ago▲ L3→L4
Global Advisory Posture
L4 · Do Not Travel
19
Countries
L3 · Reconsider
25
Countries
L2 · Caution
68
Countries
L1 · Normal
85
Countries
Recent Changes · 30d
Lebanon
▲ L3 → L4
Hezbollah-Israel tensions8d ago
Niger
▲ L3 → L4
Post-coup · ISIS-Sahel21d ago
Burkina Faso
L4 reaffirmed
JNIM activity30d ago
Colombia
▼ L3 → L2
Improved security N. depts18d ago
👔 Executive Travel Posture
If your principals or personnel are deploying to Lebanon, Mexico (Sinaloa / Tamaulipas / Colima / Michoacán / Guerrero / Zacatecas), Haiti, Israel / Gaza, or any Sahel L4 in the next 30 days, executive protection posture review is recommended. GSC can stand up tailored pre-deployment threat briefings + on-the-ground coordination for federal, corporate, and HNW principals through our CSG line.
Active and planned protests, rallies, demonstrations with potential for crowd-management or public-safety impact · 14d active + 14d forward
23 active
8 planned 72h
3 elevated risk
Analyst's Take
May Day labor mobilization and the campus encampment cycle are the two volume drivers — together pushing the demonstration count above 23 active events with eight more planned in the next 72 hours. SEIU + UAW + AFL-CIO coordination on May 1 will produce 30K-50K turnout in Chicago alone, with smaller equivalents across 14 other metros. Campus encampments are entering their highest-risk window: commencement disruption potential is elevated at Columbia, UCLA, UMich, and Brown, and four sites have confirmed counter-protest, which is the indicator that historically correlates with on-the-ground escalation. Counter-protest indicators around Pride Month are the elevation we're watching most closely — REMVE-affiliated messaging tracks consistently against the June calendar, and six cities are currently flagged for confirmed counter-protest activity. The pattern that should concern physical security teams running venue operations: Patriot Front + Active Club messaging is timing-aligned with parade routes in metros where local law enforcement coordination is variable. Anti-ICE field-office protests will continue their weekly cadence; risk is medium, not elevating.
CONUS Demonstration Map · 14d Active + Forward
Campus
Political
Labor
Social
Counter-Protest
Faith
Other
📢
CONUS Demonstration Map
Loading map tiles… If this persists, the Google Maps API key may be quota-exceeded, revoked, or missing this host in its referrer allowlist. Open browser DevTools → Console for the exact error. Pins show active and planned demonstrations · click for organizer, crowd, and risk details.
The 14-day window shows a tempo elevated by pattern-driven advisories rather than singular kinetic events. The USMS courthouse threat pattern is the operational concern: VoIP-spoofed bomb threats against western district federal buildings have now produced six incidents in trailing 30 days using consistent TTPs — this is a coordinated harassment campaign, not isolated callers, and we expect it to continue. The FBI national soft-target advisory issued three days ago is the broader threshold-setter: lone-actor accelerationist chatter is trending up against summer event cycles, with houses of worship and LGBTQ+ venues specifically flagged. Transit incidents in NYC MTA and Chicago CTA share TTP profile and are under joint investigation — this is the kind of pattern that often resolves as a single actor traveling. The Phoenix workplace shooting was non-pattern (former employee, no ideological nexus) and should not influence broader posture assessments. Pacific NW wildfire mobilization is the operational sleeper: Red Flag Warnings across CA / OR / WA combined with mass-evacuation pre-staging at three county OES centers suggests the season is opening earlier and harder than 2025 — physical-security teams with facilities in those AORs should validate continuity plans now, not after first deployment.
CONUS Incident Map · 14d Window
Shooting
Threat
Transit
Arrest
Advisory
🚨
CONUS Incident Map
Loading map tiles… If this persists, the Google Maps API key may be quota-exceeded, revoked, or missing this host in its referrer allowlist. Open browser DevTools → Console for the exact error. Pins show significant incidents in 14d window · click for incident details and status.
Incident Type
Type
Location
Summary
Status
Reported
Threat
Atlanta GA
Federal courthouse — bomb threat called in via spoofed VoIP, pattern matches USMS advisory. Building swept, cleared 14:20.
Investigation
2d ago
Advisory
Multi-state
FBI national soft-target advisory — uptick in lone-actor accelerationist chatter on summer events. House of worship + LGBTQ+ venues flagged.
Active
3d ago
Transit
NYC · MTA
Subway platform assault, 4 injuries. Suspect apprehended. Coordinated with similar pattern in Chicago CTA last week.
Investigation
4d ago
Arrest
Houston TX
FBI JTTF arrest — domestic extremist plotting against state capitol on session day. Two co-conspirators detained.
Cleared
5d ago
Shooting
Phoenix AZ
Workplace shooting at distribution warehouse, 3 fatalities. Disgruntled former employee. No nexus to larger pattern.
Investigation
6d ago
Threat
Multi-state
USMS courthouse pattern advisory — repeat callers using same TTPs targeting western district court buildings. 6 incidents in trailing 30d.
Active
7d ago
Advisory
CA · Pacific NW
Joint state fusion center wildfire mobilization — Red Flag Warnings across CA/OR/WA. Mass-evacuation pre-staging at 3 county OES.
Active
10d ago
08 · State-Aligned Cyber Activity
APTs & Criminal Operations · Active
Currently active threat actor sets with recent CONUS observations · state-aligned listed first, criminal second
4 active
14 tracked total
Analyst's Take
The PRC pair — Volt Typhoon and Salt Typhoon — are the operational dominant concern. Volt's living-off-the-land tradecraft in grid and water OT is purpose-built for dormancy through a US response cycle; we have no high-confidence kinetic timeline, which is precisely the point — pre-positioning is the operation, not a prelude to one. Salt Typhoon has now reached nine named US carriers and the lawful-intercept system access is the troubling vector: it provides counterintelligence value (who is being monitored by whom) far beyond a typical telecom compromise. MuddyWater's tempo is the Iran retaliation barometer — operations up 40% post-Gaza, and any rapid escalation in MuddyWater spear-phishing against US-Israel-aligned targets would correlate strongly with a kinetic Iran decision. Scattered Spider remains the most operationally damaging non-state actor in CONUS by dollar impact — help-desk social engineering and MFA-fatigue work because they exploit human and process gaps that no amount of EDR tuning fixes. MITRE ATT&CK technique IDs below each card are clickable in the production product; map to your detection coverage and prioritize gaps against your sector exposure.
TTP: Help-desk social engineering, MFA-fatigue, ransomware via Okta / AzureAD pivot. Insurance + finance heavy.
Targets: Finance · Retail · HospObs 8h ago
MITRET1566.004T1621T1556.006T1486
09 · CISA KEV
Active CVEs · Critical Infrastructure Exposure
Currently exploited vulnerabilities with critical-infrastructure exposure · sorted by KEV addition date desc
8 KEV
23 tracked
Analyst's Take
Eight CVEs sit on CISA's Known Exploited Vulnerabilities list with critical-infrastructure exposure in the current cycle — but the headline isn't the count, it's the vendor concentration. Cisco IOS XE, Schneider Modicon, Citrix NetScaler, Ivanti Connect Secure, and Fortinet FortiOS together account for five of the eight — all are edge-network or OT vendors with deployment density across federal, energy, water, and finance sectors. That concentration is structural, not coincidental: state-aligned actors aggressively pursue widely-deployed appliance vulnerabilities because patching cadence in these categories is poor and exposure persists for months after disclosure. CVE-2026-0817 in Schneider Modicon is the one we'd patch first — water and energy ICS exposure, CVSS 9.4, observed in active state-aligned exploitation by both Sandworm and Volt Typhoon clusters per CISA AA bulletins. The two-day gap between KEV add date and now means most organizations are still vulnerable: BOD 22-01 federal patch deadlines are 14 days for KEV criticals, but commercial cadence trails federal by 3-6 weeks on average. Schneider, Citrix, and Ivanti exposures correlate with the Volt Typhoon and MuddyWater operations called out above — patching these is convergence response, not just hygiene.
CVE
CVSS
Vendor / Product
KEV
Sectors
Added
CVE-2026-1042
9.8
Cisco IOS XE
KEV ✓
Crit Infra · Energy · Govt
2d ago
CVE-2026-0817
9.4
Schneider Modicon
KEV ✓
Crit Infra · Water · Energy
3d ago
CVE-2026-0599
8.6
Citrix NetScaler ADC
KEV ✓
Finance · Healthcare · Govt
4d ago
CVE-2026-0381
8.1
Ivanti Connect Secure
KEV ✓
Govt · Finance · Crit Infra
5d ago
CVE-2025-9876
9.1
Fortinet FortiOS
KEV ✓
All sectors
7d ago
10 · Physical + Cyber Overlap
Cross-Domain Convergence Events
Incidents where physical security and cyber operations require joint coordination · the GSC differentiator
4 active
Trending up
Analyst's Take
Convergence findings are where federal and commercial threat products almost always miss the story. Adversaries don't respect the physical/cyber boundary, but our entire intelligence apparatus is organized by it — CISA does cyber, FBI does FBI, NCTC does terrorism, fusion centers do geography. When a DVE accelerationist target set overlaps with a Volt Typhoon OT pre-positioning target set in the same utility scope, that overlap is the operative concern, and neither single-domain feed will surface it. Election infrastructure is the canonical example: polling-place physical security and voter-registration database integrity are two different vendors, two different posture reviews, and two different incident-response paths — but adversaries treat them as one attack surface. The Salt Typhoon + telecom POP convergence we flag below is the kind of finding that wouldn't exist in any single-source TI feed — it requires cyber attribution from CISA, physical-access risk modeling from carrier security teams, and an analyst willing to connect them. This is the section federal customers ask us about first. A senior CISO running pure-cyber and a senior PSD running pure-physical, even at the same organization, would each miss what this section surfaces when read alone.
⚡ Critical Infra Convergence
High
Volt Typhoon pre-positioning at water utility SCADA — physical perimeter posture review required at affected sites
OT segmentation audit · Volt Typhoon IOC sweep · SCADA + EMS credential review · vendor remote-access logs
Recommended. 14-day coordinated exercise at substations flagged in FBI advisories. Pattern of cross-domain pre-positioning is the operative concern — neither posture alone is sufficient when actors from both threat groups are in the same target set.
FBI national advisory + NERC E-ISAC + CISA · 3d agovia Marcus Reed + Darius Chen
📡 Telecom · Cyber + Physical Access
High
Salt Typhoon carrier compromise elevates physical-access posture concerns at telco POP facilities
Physical
POP perimeter + cage access review · vendor + maintenance access logs · CCTV audit at named carriers · key-management review
Recommended. Concurrent physical + cyber audit at affected carrier POPs. Many telco facilities have known under-protected physical access paths; a sophisticated cyber actor with insider physical access dramatically expands attack surface.
CISA Salt Typhoon advisory + carrier security · 12h agovia Marcus Reed + Darius Chen
Continue · Build Your Own AOR
This is the national picture. Your tailored AOR is the next step.
Federal contracting officers, critical-infrastructure CISOs, and physical security directors subscribe to receive a version of this picture scoped to their facilities, jurisdictions, vendor stack, and personnel posture — with the same agent team behind it. Existing customers include the City of Redding / Shasta County operating picture and Canyon Lake / Bexar County deployments.