Threat Landscape

Jan 04 — Mar 22 (weekly, 26-week baseline) · Last updated: 2026-03-29 07:48 UTC
512
Articles (12w)
16
Active Archetypes
8
Anomalies
Initial access brokering
⚠ SPIKE
11 this week
▶ Stable (-4.2%/w) Shift: +185.7%
Details
Mean: 2.7/w Z-score: 2.21 Recent 3w avg: 6.7/w Prior 3w avg: 2.3/w Total: 70
Espionage
⚠ SPIKE
10 this week
▲ Rising (100.0%/w) Shift: +100.0%
Details
Mean: 0.4/w Z-score: 5.0 Recent 3w avg: 3.3/w Prior 3w avg: 0.0/w Total: 10
Wiper / Sabotage
⇋ SHIFTING
1 this week
▲ Rising (28.4%/w) Shift: +75.0%
Details
Mean: 1.2/w Z-score: -0.1 Recent 3w avg: 4.7/w Prior 3w avg: 2.7/w Total: 32
BEC / Wire fraud
⇋ SHIFTING
1 this week
▼ Falling (-10.5%/w) Shift: +50.0%
Details
Mean: 1.0/w Z-score: 0.03 Recent 3w avg: 2.0/w Prior 3w avg: 1.3/w Total: 25
Cryptojacking
⇋ SHIFTING
1 this week
▶ Stable (4.0%/w) Shift: +66.7%
Details
Mean: 0.7/w Z-score: 0.28 Recent 3w avg: 1.7/w Prior 3w avg: 1.0/w Total: 18
Credential theft
● NORMAL
7 this week
▶ Stable (2.1%/w) Shift: +39.6%
Details
Mean: 8.9/w Z-score: -0.18 Recent 3w avg: 22.3/w Prior 3w avg: 16.0/w Total: 231
Ransomware
● NORMAL
3 this week
▶ Stable (-9.6%/w) Shift: -7.7%
Details
Mean: 2.5/w Z-score: 0.15 Recent 3w avg: 4.0/w Prior 3w avg: 4.3/w Total: 66
Ad fraud
● NORMAL
1 this week
▶ Stable (7.3%/w) Shift: -16.7%
Details
Mean: 0.8/w Z-score: 0.22 Recent 3w avg: 1.7/w Prior 3w avg: 2.0/w Total: 20
DDoS
● NORMAL
1 this week
▶ Stable (-7.2%/w) Shift: -20.0%
Details
Mean: 0.7/w Z-score: 0.27 Recent 3w avg: 1.3/w Prior 3w avg: 1.7/w Total: 19

Low Volume

< 1 article/week — limited statistical significance
Prepositioning
⚠ SPIKE
9 total (12w)
Defacement
⚠ SPIKE
5 total (12w)
Payment card theft
⚠ SPIKE
2 total (12w)
Crypto theft
⚠ SPIKE
1 total (12w)
Data exposure
⚠ SPIKE
1 total (12w)
Influence operations
⚠ SPIKE
1 total (12w)
Sextortion
⇋ SHIFTING
2 total (12w)

Threat Actors

Top 20 actors by article mentions (12w)
Actor Articles Associated Archetypes
TeamPCP 23 Credential theft (15) Initial access brokering (2) Wiper / Sabotage (2)
LockBit 18 Ransomware (18)
Handala 15 Wiper / Sabotage (14) DDoS (1)
Lazarus Group 12 Credential theft (6) BEC / Wire fraud (2) Ransomware (2)
MuddyWater 11 Wiper / Sabotage (7) Credential theft (2) DDoS (2)
Contagious Interview 10 Credential theft (9) Initial access brokering (1)
Qilin 10 Ransomware (9) Wiper / Sabotage (1)
DragonForce 7 Ransomware (7)
Akira 7 Ransomware (7)
APT28 6 Credential theft (4) Ransomware (1) Espionage (1)
APT33 6 Wiper / Sabotage (4) DDoS (1) Credential theft (1)
ShinyHunters 6 Credential theft (3) Ransomware (3)
RansomHub 5 Ransomware (5)
Charming Kitten 5 Wiper / Sabotage (2) DDoS (1) Credential theft (1)
BlackCat 4 Ransomware (4)
Black Basta 4 Ransomware (3) Initial access brokering (1)
APT42 4 Wiper / Sabotage (2) DDoS (1) Credential theft (1)
Forest Blizzard 4 Credential theft (3) Espionage (1)
APT34 4 Wiper / Sabotage (3) DDoS (1)
OilRig 4 DDoS (2) Wiper / Sabotage (2)

CVE Tracker

600 unique CVEs tracked
CVE-2026-3055 NEW
Citrix NetScaler ADCNetScaler ADC (Citrix ADC)NetScaler Gateway (Citrix Gateway)
2 this week 2 total 1w active
Articles Critical Out-of-Bounds Memory Read Vulnerability in Citrix NetScaler ADC and Net Critical Memory Leak Vulnerability in Citrix NetScaler ADC and NetScaler Gateway
CVE-2025-2264 NEW
DebianOpenSSHCilium
1 this week 1 total 1w active
Articles AS211590 Bucklog/FBW Networks: Anatomy of a Kubernetes-Orchestrated Scanning and
CVE-2025-48927 NEW
DebianOpenSSHCilium
1 this week 1 total 1w active
Articles AS211590 Bucklog/FBW Networks: Anatomy of a Kubernetes-Orchestrated Scanning and
CVE-2025-53109 NEW
Claude CodeGemini CLICodex CLI
1 this week 1 total 1w active
Articles Runtime Detection of AI Coding Agents: Syscall-Level Threat Modeling for Claude
CVE-2025-53110 NEW
Claude CodeGemini CLICodex CLI
1 this week 1 total 1w active
Articles Runtime Detection of AI Coding Agents: Syscall-Level Threat Modeling for Claude
CVE-2026-20929 NEW
Windows Admin CenterWindows Server 2022Windows Server 2025
1 this week 1 total 1w active
Articles CVE-2026-26119: Authentication Reflection in Windows Admin Center Enabling Domai
CVE-2026-20963 NEW
Microsoft SharePoint
1 this week 1 total 1w active
Articles Kritische Microsoft SharePoint Schwachstelle (CVE-2026-20963) wird aktiv ausgenu
CVE-2026-21385 NEW
Apple iOSiPhone
1 this week 1 total 1w active
Articles DarkSword: Zero-Click iOS Exploit Kit Leveraging Six-Vulnerability Chain in Wate
CVE-2025-55182 PERSISTENT
trivy-plugin-aquaTraceeTrivy
1 this week 16 total 8w active
Articles TeamPCP Compromises Aqua Security Internal GitHub Organization, Defacing 44 Repo RondoDox Botnet: Deep Dive into a 174-Exploit IoT Threat Campaign Quarterly Vulnerability and Exploit Landscape: Q4 2025 Threat Intelligence Repor MuddyWater Exposed: Inside an Iranian MOIS-Linked APT Operation Targeting Israel Multiple Active Campaigns: BeyondTrust CVE-2026-1731 Exploitation, AI-Generated
CVE-2026-1281 PERSISTENT
Ivanti Endpoint Manager Mobile (EPMM)NetScaler ADC (Citrix ADC)NetScaler Gateway (Citrix Gateway)
1 this week 11 total 8w active
Articles Critical Memory Leak Vulnerability in Citrix NetScaler ADC and NetScaler Gateway Active Exploitation of Ivanti EPMM RCE Vulnerabilities: The 403.jsp Webshell Cam MuddyWater Exposed: Inside an Iranian MOIS-Linked APT Operation Targeting Israel January 2026 Vulnerability Landscape: APT28 Zero-Day Exploitation and Critical A Active Exploitation of Critical Ivanti EPMM Zero-Day Vulnerabilities CVE-2026-12
CVE-2026-1340 PERSISTENT
Ivanti Endpoint Manager Mobile (EPMM)NetScaler ADC (Citrix ADC)NetScaler Gateway (Citrix Gateway)
1 this week 10 total 7w active
Articles Critical Memory Leak Vulnerability in Citrix NetScaler ADC and NetScaler Gateway Active Exploitation of Ivanti EPMM RCE Vulnerabilities: The 403.jsp Webshell Cam January 2026 Vulnerability Landscape: APT28 Zero-Day Exploitation and Critical A Active Exploitation of Critical Ivanti EPMM Zero-Day Vulnerabilities CVE-2026-12 GreyNoise Analysis Reveals 83% of Ivanti EPMM Exploitation Traced to Single Bull
CVE-2026-21509 PERSISTENT
Microsoft OfficeIvanti Endpoint Manager Mobile (EPMM)SlimAgent
0 this week 10 total 6w active
Articles Sednit APT28 Resurfaces with Modern BeardShell and Covenant Implants Rooted in 2 January 2026 Vulnerability Landscape: APT28 Zero-Day Exploitation and Critical A Turf Wars vs. Supply Chains: The Great Divergence in State Cyber Threats Technical Deep Dive: The Monero Mining Campaign The Bug Report - January 2026 Edition: Critical Vulnerabilities in Microsoft Off
CVE-2026-21858 PERSISTENT
Microsoft Officen8nDebian
1 this week 9 total 6w active
Articles AS211590 Bucklog/FBW Networks: Anatomy of a Kubernetes-Orchestrated Scanning and MuddyWater Exploits n8n Vulnerability Chain: CISA KEV Entry Understates Unauthen The Bug Report - January 2026 Edition: Critical Vulnerabilities in Microsoft Off Kubernetes-Orchestrated Webhook Scanning Campaign Targets n8n Platforms via CVE- Critical CVE-2026-21858 Ni8mare Vulnerability Enables Unauthenticated Takeover o
CVE-2025-61882 PERSISTENT
0 this week 8 total 5w active
CVE-2025-53770 PERSISTENT
0 this week 6 total 5w active
CVE-2025-68613 PERSISTENT
1 this week 6 total 6w active
CVE-2026-20127 ACTIVE
1 this week 7 total 3w active
CVE-2025-5777 ACTIVE
1 this week 3 total 3w active
CVE-2026-21962 ACTIVE
1 this week 3 total 3w active
CVE-2025-29927 ACTIVE
1 this week 2 total 2w active
CVE-2025-31277 ACTIVE
1 this week 2 total 2w active
CVE-2025-43510 ACTIVE
1 this week 2 total 2w active
Archetype Status This Week Mean Z-Score Total (12w) Trend Shift
Initial access brokering significant 11 2.7 2.21 70 -4.2%/w +185.7%
Espionage significant 10 0.4 5.0 10 +100.0%/w +100.0%
Prepositioning significant 9 0.3 5.0 9 +100.0%/w +100.0%
Defacement significant 1 0.2 2.05 5 -9.1%/w +100.0%
Payment card theft significant 2 0.1 5.0 2 +100.0%/w +100.0%
Crypto theft significant 1 0.0 5.0 1 +100.0%/w +100.0%
Data exposure significant 1 0.0 5.0 1 +100.0%/w +100.0%
Influence operations significant 1 0.0 5.0 1 +100.0%/w +100.0%
Wiper / Sabotage shifting 1 1.2 -0.1 32 +28.4%/w +75.0%
BEC / Wire fraud shifting 1 1.0 0.03 25 -10.5%/w +50.0%
Cryptojacking shifting 1 0.7 0.28 18 +4.0%/w +66.7%
Sextortion shifting 0 0.1 -0.29 2 +36.4%/w +100.0%
Credential theft normal 7 8.9 -0.18 231 +2.1%/w +39.6%
Ransomware normal 3 2.5 0.15 66 -9.6%/w -7.7%
Ad fraud normal 1 0.8 0.22 20 +7.3%/w -16.7%
DDoS normal 1 0.7 0.27 19 -7.2%/w -20.0%