REPORT   2026  2025  2024  2023  2022  2021  2020  2019  2018  2017


H  AI  ANALYSIS  APT  ATTACK  CAMPAIGN  CLOUD  CYBER  GROUP  ICS  INCIDENT  MALWARE  OPERATION  RANSOMWARE  REPORT  RISK  SECURITY  SOCIAL  VULNEREBILITY


DATE

NAME

INFO

CATEGORY

SUBCATE

4.10.26

FBI INTERNET CRIME REPORT 2025 In 2025, the FBI Internet Crime Complaint Center (IC3) celebrated its 25th anniversary as the central hub for reporting cyber-enabled crime. This milestone signifies the FBI's enduring commitment to fighting the ever-evolving cyber threat. Our success in protecting individuals and organizations is driven by public participation and robust data analysis. REPORT REPORT

25.9.26

ClickFix & Beyond Mapping the expanding family of user-assisted malware delivery techniques REPORT REPORT

16.9.26

Inside Tajin Group’s Phishing and
Money Laundering Network
Tajin Group detailed its operational challenges and announced key plans and changes, showcasing its ability to adapt and evolve to conduct payment card theft and money laundering activities. REPORT REPORT

11.9.26

Detecting and countering misuse of AI: September 2026 Over the past eight months, our Threat Intelligence team identified and disrupted operations in which threat actors tried to use Claude for malicious activity. In this report, we share case studies from those operations and describe how malicious use of Claude has evolved since our previous threat reports in March, August, and November 2025. REPORT REPORT

6.9.26

Acronis Cyberthreats Report, H2 2025 The Acronis Cyberthreats Report covers the global threat landscape as encountered by the Acronis Threat Research Unit (TRU) and Acronis sensors in the second half of 2025. General threat data (including malware, ransomware, web and email threats, vulnerabilities, etc.) presented in the report is gathered from January–December of 2025 and reflects threats targeting endpoints we observed in this time frame REPORT REPORT

31.8.26

OpenAI – Hugging Face Incident Technical Report In July 2026, during internal cybersecurity evaluations, OpenAI models in an internal evaluation environment circumvented controls intended to isolate them from the internet and performed computer network exploitation of OpenAI’s internal research infrastructure and Hugging Face systems. REPORT AI
28.8.26 BlueDelta Targets Defense and
Diplomacy with HOOKEDGE
Insikt Group identified Russian statesponsored group BlueDelta (APT28) targeting government, diplomatic, and
defense organizations in Romania, Spain, and Türkiye between September 2025 and April 2026
REPORT APT
28.8.26 CISA Vulnerability Review Fiscal Years 2024 and 2025 Cybersecurity conversations often focus on high-profile incidents involving nation-state adversaries, ransomware groups, and other sophisticated threat actors. However, most compromises have not relied on advanced techniques. They exploited simple, known software vulnerabilities that remain widespread and persistent in publicly exposed assets. Increasingly, cyber threat actors are using artificial intelligence (AI) to automate all the steps necessary to exploit these vulnerabilities. REPORT ANALYSIS
28.8.26 Threat landscape for  industrial automation  systems. Q2 2026 In this section, we examine the most significant changes to indicators over the quarter, broken down by region and industry. Further diagrams can be found in the relevant chapters of the “Statistics across all threats” section. REPORT ICS
27.8.26 China-Linked Hacking Group QTFY Targets Military and Critical Infrastructure with Malicious Distributed Systems The Federal Bureau of Investigation, National Security Agency, and Cyber National Mission Force are releasing this joint cybersecurity advisory to alert organizations concerning China-linked cyber threat actors, who use the acronyms QTFY, QT, and QTCYBER for themselves and their tools and have developed malicious distributed platforms to compromise the networks of US and foreign organizations. REPORT APT
26.8.26 A Tale of Two SOCs: Insights From Two Red Team
Assessments
The Cybersecurity and Infrastructure Security Agency’s (CISA’s) red team simulates real‑world maliciouscyber operations to assess an organization’s ability to detect, investigate, and respond to malicious cyberactivity. Emulating cyber threat actor tradecraft, the red team attempts to gain and maintain persistentaccess to an organization’s network and sensitive business systems (SBSs) while avoiding detection. REPORT SECURITY
24.8.26 Enterprise AI Usage Risk Report 2026 When the State of the Internet/Security report first analyzed the emerging artificial intelligence (AI) landscape in early 2025, enterprise adoption was largely characterized by caution and curiosity; today, it is a structural mandate. What began as sporadic experimentations with ChatGPT has evolved into a sprawling ecosystem of AI assistants, AI browsers, AI agents, AI extensions, and autonomous workflows that touch every aspect of enterprise work. REPORT AI

22.8.26

QUARTERLY THREAT LANDSCAPE REPORT The compression era: Q2 2026 has showed that traditional patch cycles are overwhelmed Q2 2026 was not just another busy quarter in cyber. It felt more like a stress test of the way we currently manage exposure. Traditional patch cycles are being overwhelmed by the sheer volume of vulnerabilities and attacker speed and precision. REPORT ANALYSIS

19.8.26

PurpleDelta's Fraudulent Employment Operations PurpleDelta operates at an industrial scale, using at least 22 personas to apply to over 1,100 companies and submitting more than 60 applications per day. REPORT OPERATION

16.8.26

The Jewelbug Dossier China-based hackers-for-hire group staging espionage attacks alongside a cryptocurrency fraud business. REPORT APT

15.8.26

Follow-Up Analysis of the 29 December 2025 Energy Sector Incident On 29 December 2025, coordinated attacks targeted the energy sector in Poland, including 30 renewable energy facilities and a large combined heat and power (CHP) plant. These attacks were described in detail in the report published on 30 January 2026*. At the same time, another incident occurred at a smaller CHP plant supplying heat to 50,000 residents. REPORT ICS

10.8.26

Pass-the-Passkey Family of Attacks Coming from the field of enterprise security, we have spent much of our careers studying privilege escalation and lateral movement through attacks against Windows Integrated Authentication. But as more companies adopt cloud services, we decided to shift our attention to passkeys, which are slowly but steadily becoming the norm. REPORT ATTACK

6.8.26

Cost of a Data Breach Report 2026
The AI tipping point
Welcome to the 21st annual Cost of a Data Breach Report. Frontier AI models have radically shifted the cybersecurity threat landscape. REPORT INCIDENT

5.8.26

Security Incident INC-2026-07-28-01 The UK AI Security Institute (AISI) exists to equip governments with a scientific understanding of the risks posed by advanced AI. To achieve that goal, AISI routinely evaluates the capabilities of frontier AI systems in domains such as cybersecurity. REPORT INCIDENT

4.8.26

Zero Day Provisioning Chaining TP-Link ZTP Vulnerabilities to Infiltrate Networks REPORT VULNEREBILITY

2.8.26

Threat H1 2026 December 2025 – May 2026 Report Welcome to the H1 2026 issue of the ESET Threat Report! REPORT ANALYSIS

25.7.26

DevMan Ransomware
Threat Actor Report
In early April 2025, an actor presenting itself as “DevMan” has claimed on X1 to gain access and perform a ransomware attack against the French transport company “doumen”. Since then, the threat actor has proved itself as being highly prolific and was named as one of the top active ransomware attackers in the following months.2 As of July 2025, DevMan has claimed at least 54 victims. REPORT RANSOMWARE

25.7.26

Cybercrime in the age of AI AI is rewiring the cybercrime ecosystem. You have six months to prepare. REPORT AI

24.7.26

Disrupting the first reported AI-orchestrated cyber espionage campaign We have developed sophisticated safety and security measures to prevent the misuse of our AI models. While these measures are generally effective, cybercriminals and other  malicious actors continually attempt to find ways around them. REPORT AI

24.7.26

ClickFix Campaigns Targeting Windows and macOS Insikt Group identified five distinct ClickFix clusters sharing the same core human-verification lure despite notable differences in themes, delivery patterns,
and infrastructure.
REPORT CAMPAIGN

24.7.26

TAG-195 Upgrades MaaS Ecosystem with Modular Tools Insikt Group identified four new TAG-195 malware families that indicate sustained  active development and a deliberate architectural transition toward modular,  operator-driven tooling. REPORT APT

24.7.26

Russian State-Supported Cyber Actors  Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025. REPORT APT

21.7.26

Anatomy of a Cyber World Effectively prioritize your investment in cybersecurity through understanding your adversaries and the attack methods targeting your industry and region REPORT CYBER

21.7.26

Considering Simultaneous Voltage-Sensitive Load Reductions Operators and planners of the Bulk Electric System (BES) should be aware of the risks and challenges associated with voltage-sensitive large loads that are rapidly being connected to the power system. REPORT ICS

20.7.26

Russian state actors are compromising IP cameras in Europe for military purposes Cybersecurity advisory Russian state actors are compromising IP cameras in Europe for military purposes REPORT APT

18.7.26

GTIG AIThreat Tracker: Advances in Threat Actor Usage of AI Tools Advances in Threat Actor Usage  of AI Tools REPORT AI

18.7.26

m-trends-2026-en m-trends-2026 REPORT ANALYSIS

18.7.26

AI Security Report 2026 AI SecurityReport 2026 Check Point AI Report • 2nd Annual EditionCheck Point Research AI Security Report 202 REPORT AI
1.7.26 Global Incident Response Report 2026 While these four trends each present a challenge, attacker success is rarely determined by a single attack vector. In more than 750 incident response (IR)  engagements, 87% of intrusions involved activity across multiple attack surfaces. This means defenders must protect endpoints, networks, cloud infrastructure, SaaS applications and identity together. REPORT INCIDENT
1.7.26 Microsoft Digital Defense Report 2025 Lighting the path to a secure future REPORT REPORT
1.6.26 ESET APT Activity Report Q4 2025–Q1 2026 CONFLICT-INFORMED ESPIONAGE: MONITORING OIL SHIPMENTS, TARGETING DRONE MAKERS REPORT APT
29.5.26 5 EUROPEAN THREAT LANDSCAPE REPORT Europe’s cyber threat actors are accelerating. eCrime adversaries, state-backed operators, and hacktivists are conducting faster intrusions, employing new social engineering tradecraft, and operating resilient criminal ecosystems. REPORT GROUP
28.5.26 State of AI in the Cloud 2026 How AI Adoption, Autonomy, and Attacker Innovation Are Reshaping Cloud Security REPORT AI
23.5.26 2026Microsoft Vulnerabilities Report13th Edition Data-packed insights and expert analysis to help you mitigate security risks in your Microsoft estate. REPORT VULNEREBILITY
14.5.26 APT ActivityApril 2025 – September 2025 Report RUSSIA-ALIGNED APTs RAMP UP ATTACKS AGAINST UKRAINE AND ITS STRATEGIC PARTNERS REPORT APT
11.5.26 ClickFix distributing Vidar Stealer via WordPress targeting Australian infrastructure The Australian Signals Directorate’s Australian Cyber Security Centre (ASD's ACSC) has observed ClickFix associated activity leveraging WordPress hosted infrastructure to distribute the Vidar Stealer malware. REPORT MALWARE
11.5.26 Acronis Cyberthreats Report, H2 2025: From exploits to malicious IA The Acronis Cyberthreats Report covers the global threat landscape as encountered by the Acronis Threat Research Unit (TRU) and Acronis sensors in the second half of 2025. REPORT REPORT
11.5.26 State of the SOFTWARE SUPPLY CHAIN 2026 The Limits of Legacy Vulnerability Management REPORT VULNEREBILITY
11.5.26 FEMITBOT Abuse of Telegram Mini Apps for Large-Scale Fraud Campaigns REPORT SOCIAL
5.5.26 Zscaler ThreatLabz 2026 VPN Risk Report For decades, VPN was the default answer to remote access security – reliable, familiar, and deeply embedded in enterprise architecture. That era is ending. AI has accelerated attack timelines from weeks to minutes, automated credential theft at industrial scale, and given adversaries a speed advantage that human-led defense cannot match. REPORT RISK
28.4.26 DSCI THREAT INTELLIGENCE AND RESEARCH INITIATIVE DSCI THREAT INTELLIGENCEAND RESEARCH INITIATIVETHREAT REPORTII FEBRUARY 2026 REPORT REPORT
26.4.26 The State of BCDR 2025: Future-Proof Your Data Protection Strategies Data is the backbone of every business, driving innovation, decision-making and customer engagement. Whether you’re an MSP protecting client environments or an internal IT professional securing your organization’s infrastructure, ensuring data availability and security is both a critical responsibility and a strategic advantage. REPORT ANALYSIS
22.4.26 Assessment | Q1 2026 Ransomware Wrap-Up
A-2026-04-17a
ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. REPORT RANSOMWARE
12.4.26 Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure REPORT APT
9.3.26 Cloud Threat Horizons Report H1 2026 The Google Cloud Threat Horizons Report provides decision-makers with strategic intelligence on threats to not just Google Cloud, but all cloud service providers. REPORT CLOUD
27.2.26 CISCO SD-WAN THREAT
HUNT GUIDE
The authors are aware that since 2023, at least one malicious cyber actor compromised Cisco SD-WANs via a previously unknown vulnerability, identified in late 2025 to be a zeroday exploit. This vulnerability is now patched in the latest updates from the vendor. REPORT ANALYSIS
20.2.26 Ninja Browser & Lumma Infostealer CTM360 has identified a large-scale malware campaign exploiting trusted Google services — including Google Groups, Google Docs, and Google Drive — to distribute Lumma Stealer and a trojanized Chromium-based “Ninja Browser.” REPORT MALWARE
10.1.26 BlueDelta’s Persistent Campaign Against UKR.NET Between June 2024 and April 2025, Recorded Future’s Insikt Group identified a sustained credential-harvesting campaign targeting users of UKR.NET, a widely used Ukrainian webmail and news service REPORT CAMPAIGN
10.1.26 GRU-Linked BlueDelta Evolves Credential Harvesting Between February and September 2025, Recorded Future’s Insikt Group identified multiple credential-harvesting campaigns conducted by BlueDelta, a Russian state-sponsored threat group associated with the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU). REPORT CAMPAIGN
3.1.26 OWASP Top 10 For Agentic Applications 2026 The information provided in this document does not, and is not intended to, constitute legal advice. REPORT AI