REPORT 2026 2025 2024 2023 2022 2021 2020 2019 2018 2017
H AI ANALYSIS APT ATTACK CAMPAIGN CLOUD CYBER GROUP ICS INCIDENT MALWARE OPERATION RANSOMWARE REPORT RISK SECURITY SOCIAL VULNEREBILITY
DATE |
NAME |
INFO |
CATEGORY |
SUBCATE |
|
4.10.26 |
FBI INTERNET CRIME REPORT 2025 | In 2025, the FBI Internet Crime Complaint Center (IC3) celebrated its 25th anniversary as the central hub for reporting cyber-enabled crime. This milestone signifies the FBI's enduring commitment to fighting the ever-evolving cyber threat. Our success in protecting individuals and organizations is driven by public participation and robust data analysis. | REPORT | REPORT |
|
25.9.26 |
ClickFix & Beyond | Mapping the expanding family of user-assisted malware delivery techniques | REPORT | REPORT |
|
16.9.26 |
Inside Tajin Group’s Phishing and Money Laundering Network |
Tajin Group detailed its operational challenges and announced key plans and changes, showcasing its ability to adapt and evolve to conduct payment card theft and money laundering activities. | REPORT | REPORT |
|
11.9.26 |
Detecting and countering misuse of AI: September 2026 | Over the past eight months, our Threat Intelligence team identified and disrupted operations in which threat actors tried to use Claude for malicious activity. In this report, we share case studies from those operations and describe how malicious use of Claude has evolved since our previous threat reports in March, August, and November 2025. | REPORT | REPORT |
|
6.9.26 |
Acronis Cyberthreats Report, H2 2025 | The Acronis Cyberthreats Report covers the global threat landscape as encountered by the Acronis Threat Research Unit (TRU) and Acronis sensors in the second half of 2025. General threat data (including malware, ransomware, web and email threats, vulnerabilities, etc.) presented in the report is gathered from January–December of 2025 and reflects threats targeting endpoints we observed in this time frame | REPORT | REPORT |
|
31.8.26 |
OpenAI – Hugging Face Incident Technical Report | In July 2026, during internal cybersecurity evaluations, OpenAI models in an internal evaluation environment circumvented controls intended to isolate them from the internet and performed computer network exploitation of OpenAI’s internal research infrastructure and Hugging Face systems. | REPORT | AI |
| 28.8.26 |
BlueDelta Targets Defense and Diplomacy with HOOKEDGE |
Insikt Group identified Russian statesponsored group
BlueDelta (APT28) targeting government, diplomatic, and defense organizations in Romania, Spain, and Türkiye between September 2025 and April 2026 |
REPORT | APT |
| 28.8.26 | CISA Vulnerability Review Fiscal Years 2024 and 2025 | Cybersecurity conversations often focus on high-profile incidents involving nation-state adversaries, ransomware groups, and other sophisticated threat actors. However, most compromises have not relied on advanced techniques. They exploited simple, known software vulnerabilities that remain widespread and persistent in publicly exposed assets. Increasingly, cyber threat actors are using artificial intelligence (AI) to automate all the steps necessary to exploit these vulnerabilities. | REPORT | ANALYSIS |
| 28.8.26 | Threat landscape for industrial automation systems. Q2 2026 | In this section, we examine the most significant changes to indicators over the quarter, broken down by region and industry. Further diagrams can be found in the relevant chapters of the “Statistics across all threats” section. | REPORT | ICS |
| 27.8.26 | China-Linked Hacking Group QTFY Targets Military and Critical Infrastructure with Malicious Distributed Systems | The Federal Bureau of Investigation, National Security Agency, and Cyber National Mission Force are releasing this joint cybersecurity advisory to alert organizations concerning China-linked cyber threat actors, who use the acronyms QTFY, QT, and QTCYBER for themselves and their tools and have developed malicious distributed platforms to compromise the networks of US and foreign organizations. | REPORT | APT |
| 26.8.26 |
A Tale of Two SOCs: Insights From Two Red Team Assessments |
The Cybersecurity and Infrastructure Security Agency’s (CISA’s) red team simulates real‑world maliciouscyber operations to assess an organization’s ability to detect, investigate, and respond to malicious cyberactivity. Emulating cyber threat actor tradecraft, the red team attempts to gain and maintain persistentaccess to an organization’s network and sensitive business systems (SBSs) while avoiding detection. | REPORT | SECURITY |
| 24.8.26 | Enterprise AI Usage Risk Report 2026 | When the State of the Internet/Security report first analyzed the emerging artificial intelligence (AI) landscape in early 2025, enterprise adoption was largely characterized by caution and curiosity; today, it is a structural mandate. What began as sporadic experimentations with ChatGPT has evolved into a sprawling ecosystem of AI assistants, AI browsers, AI agents, AI extensions, and autonomous workflows that touch every aspect of enterprise work. | REPORT | AI |
|
22.8.26 |
QUARTERLY THREAT LANDSCAPE REPORT The compression era: Q2 2026 has showed that traditional patch cycles are overwhelmed | Q2 2026 was not just another busy quarter in cyber. It felt more like a stress test of the way we currently manage exposure. Traditional patch cycles are being overwhelmed by the sheer volume of vulnerabilities and attacker speed and precision. | REPORT | ANALYSIS |
|
19.8.26 |
PurpleDelta's Fraudulent Employment Operations | PurpleDelta operates at an industrial scale, using at least 22 personas to apply to over 1,100 companies and submitting more than 60 applications per day. | REPORT | OPERATION |
|
16.8.26 |
The Jewelbug Dossier | China-based hackers-for-hire group staging espionage attacks alongside a cryptocurrency fraud business. | REPORT | APT |
|
15.8.26 |
Follow-Up Analysis of the 29 December 2025 Energy Sector Incident | On 29 December 2025, coordinated attacks targeted the energy sector in Poland, including 30 renewable energy facilities and a large combined heat and power (CHP) plant. These attacks were described in detail in the report published on 30 January 2026*. At the same time, another incident occurred at a smaller CHP plant supplying heat to 50,000 residents. | REPORT | ICS |
|
10.8.26 |
Pass-the-Passkey Family of Attacks | Coming from the field of enterprise security, we have spent much of our careers studying privilege escalation and lateral movement through attacks against Windows Integrated Authentication. But as more companies adopt cloud services, we decided to shift our attention to passkeys, which are slowly but steadily becoming the norm. | REPORT | ATTACK |
|
6.8.26 |
Cost of a Data Breach Report 2026 The AI tipping point |
Welcome to the 21st annual Cost of a Data Breach Report. Frontier AI models have radically shifted the cybersecurity threat landscape. | REPORT | INCIDENT |
|
5.8.26 |
Security Incident INC-2026-07-28-01 | The UK AI Security Institute (AISI) exists to equip governments with a scientific understanding of the risks posed by advanced AI. To achieve that goal, AISI routinely evaluates the capabilities of frontier AI systems in domains such as cybersecurity. | REPORT | INCIDENT |
|
4.8.26 |
Zero Day Provisioning | Chaining TP-Link ZTP Vulnerabilities to Infiltrate Networks | REPORT | VULNEREBILITY |
|
2.8.26 |
Threat H1 2026 December 2025 – May 2026 Report | Welcome to the H1 2026 issue of the ESET Threat Report! | REPORT | ANALYSIS |
|
25.7.26 |
DevMan Ransomware Threat Actor Report |
In early April 2025, an actor presenting itself as “DevMan” has claimed on X1 to gain access and perform a ransomware attack against the French transport company “doumen”. Since then, the threat actor has proved itself as being highly prolific and was named as one of the top active ransomware attackers in the following months.2 As of July 2025, DevMan has claimed at least 54 victims. | REPORT | RANSOMWARE |
|
25.7.26 |
Cybercrime in the age of AI | AI is rewiring the cybercrime ecosystem. You have six months to prepare. | REPORT | AI |
|
24.7.26 |
Disrupting the first reported AI-orchestrated cyber espionage campaign | We have developed sophisticated safety and security measures to prevent the misuse of our AI models. While these measures are generally effective, cybercriminals and other malicious actors continually attempt to find ways around them. | REPORT | AI |
|
24.7.26 |
ClickFix Campaigns Targeting Windows and macOS |
Insikt Group identified five distinct ClickFix clusters
sharing the same core human-verification lure despite notable differences in
themes, delivery patterns, and infrastructure. |
REPORT | CAMPAIGN |
|
24.7.26 |
TAG-195 Upgrades MaaS Ecosystem with Modular Tools | Insikt Group identified four new TAG-195 malware families that indicate sustained active development and a deliberate architectural transition toward modular, operator-driven tooling. | REPORT | APT |
|
24.7.26 |
Russian State-Supported Cyber Actors Conduct Phishing Campaign Targeting Users of Zimbra Collaboration Suite | A group of Russian state-supported cyber actors has been targeting and compromising various Western government and commercial organizations using the Zimbra Collaboration Suite (ZCS) software since at least July 2025. | REPORT | APT |
|
21.7.26 |
Anatomy of a Cyber World | Effectively prioritize your investment in cybersecurity through understanding your adversaries and the attack methods targeting your industry and region | REPORT | CYBER |
|
21.7.26 |
Considering Simultaneous Voltage-Sensitive Load Reductions | Operators and planners of the Bulk Electric System (BES) should be aware of the risks and challenges associated with voltage-sensitive large loads that are rapidly being connected to the power system. | REPORT | ICS |
|
20.7.26 |
Russian state actors are compromising IP cameras in Europe for military purposes | Cybersecurity advisory Russian state actors are compromising IP cameras in Europe for military purposes | REPORT | APT |
|
18.7.26 |
GTIG AIThreat Tracker: Advances in Threat Actor Usage of AI Tools | Advances in Threat Actor Usage of AI Tools | REPORT | AI |
|
18.7.26 |
m-trends-2026-en | m-trends-2026 | REPORT | ANALYSIS |
|
18.7.26 |
AI Security Report 2026 | AI SecurityReport 2026 Check Point AI Report • 2nd Annual EditionCheck Point Research AI Security Report 202 | REPORT | AI |
| 1.7.26 | Global Incident Response Report 2026 | While these four trends each present a challenge, attacker success is rarely determined by a single attack vector. In more than 750 incident response (IR) engagements, 87% of intrusions involved activity across multiple attack surfaces. This means defenders must protect endpoints, networks, cloud infrastructure, SaaS applications and identity together. | REPORT | INCIDENT |
| 1.7.26 | Microsoft Digital Defense Report 2025 | Lighting the path to a secure future | REPORT | REPORT |
| 1.6.26 | ESET APT Activity Report Q4 2025–Q1 2026 | CONFLICT-INFORMED ESPIONAGE: MONITORING OIL SHIPMENTS, TARGETING DRONE MAKERS | REPORT | APT |
| 29.5.26 | 5 EUROPEAN THREAT LANDSCAPE REPORT | Europe’s cyber threat actors are accelerating. eCrime adversaries, state-backed operators, and hacktivists are conducting faster intrusions, employing new social engineering tradecraft, and operating resilient criminal ecosystems. | REPORT | GROUP |
| 28.5.26 | State of AI in the Cloud 2026 | How AI Adoption, Autonomy, and Attacker Innovation Are Reshaping Cloud Security | REPORT | AI |
| 23.5.26 | 2026Microsoft Vulnerabilities Report13th Edition | Data-packed insights and expert analysis to help you mitigate security risks in your Microsoft estate. | REPORT | VULNEREBILITY |
| 14.5.26 | APT ActivityApril 2025 – September 2025 Report | RUSSIA-ALIGNED APTs RAMP UP ATTACKS AGAINST UKRAINE AND ITS STRATEGIC PARTNERS | REPORT | APT |
| 11.5.26 | ClickFix distributing Vidar Stealer via WordPress targeting Australian infrastructure | The Australian Signals Directorate’s Australian Cyber Security Centre (ASD's ACSC) has observed ClickFix associated activity leveraging WordPress hosted infrastructure to distribute the Vidar Stealer malware. | REPORT | MALWARE |
| 11.5.26 | Acronis Cyberthreats Report, H2 2025: From exploits to malicious IA | The Acronis Cyberthreats Report covers the global threat landscape as encountered by the Acronis Threat Research Unit (TRU) and Acronis sensors in the second half of 2025. | REPORT | REPORT |
| 11.5.26 | State of the SOFTWARE SUPPLY CHAIN 2026 | The Limits of Legacy Vulnerability Management | REPORT | VULNEREBILITY |
| 11.5.26 | FEMITBOT | Abuse of Telegram Mini Apps for Large-Scale Fraud Campaigns | REPORT | SOCIAL |
| 5.5.26 | Zscaler ThreatLabz 2026 VPN Risk Report | For decades, VPN was the default answer to remote access security – reliable, familiar, and deeply embedded in enterprise architecture. That era is ending. AI has accelerated attack timelines from weeks to minutes, automated credential theft at industrial scale, and given adversaries a speed advantage that human-led defense cannot match. | REPORT | RISK |
| 28.4.26 | DSCI THREAT INTELLIGENCE AND RESEARCH INITIATIVE | DSCI THREAT INTELLIGENCEAND RESEARCH INITIATIVETHREAT REPORTII FEBRUARY 2026 | REPORT | REPORT |
| 26.4.26 | The State of BCDR 2025: Future-Proof Your Data Protection Strategies | Data is the backbone of every business, driving innovation, decision-making and customer engagement. Whether you’re an MSP protecting client environments or an internal IT professional securing your organization’s infrastructure, ensuring data availability and security is both a critical responsibility and a strategic advantage. | REPORT | ANALYSIS |
| 22.4.26 |
Assessment | Q1 2026 Ransomware Wrap-Up A-2026-04-17a |
ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. | REPORT | RANSOMWARE |
| 12.4.26 | Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure | Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure | REPORT | APT |
| 9.3.26 | Cloud Threat Horizons Report H1 2026 | The Google Cloud Threat Horizons Report provides decision-makers with strategic intelligence on threats to not just Google Cloud, but all cloud service providers. | REPORT | CLOUD |
| 27.2.26 |
CISCO SD-WAN THREAT HUNT GUIDE |
The authors are aware that since 2023, at least one malicious cyber actor compromised Cisco SD-WANs via a previously unknown vulnerability, identified in late 2025 to be a zeroday exploit. This vulnerability is now patched in the latest updates from the vendor. | REPORT | ANALYSIS |
| 20.2.26 | Ninja Browser & Lumma Infostealer | CTM360 has identified a large-scale malware campaign exploiting trusted Google services — including Google Groups, Google Docs, and Google Drive — to distribute Lumma Stealer and a trojanized Chromium-based “Ninja Browser.” | REPORT | MALWARE |
| 10.1.26 | BlueDelta’s Persistent Campaign Against UKR.NET | Between June 2024 and April 2025, Recorded Future’s Insikt Group identified a sustained credential-harvesting campaign targeting users of UKR.NET, a widely used Ukrainian webmail and news service | REPORT | CAMPAIGN |
| 10.1.26 | GRU-Linked BlueDelta Evolves Credential Harvesting | Between February and September 2025, Recorded Future’s Insikt Group identified multiple credential-harvesting campaigns conducted by BlueDelta, a Russian state-sponsored threat group associated with the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU). | REPORT | CAMPAIGN |
| 3.1.26 | OWASP Top 10 For Agentic Applications 2026 | The information provided in this document does not, and is not intended to, constitute legal advice. | REPORT | AI |