Threat Landscape

Jan 04 — Mar 22 (weekly, 26-week baseline) · Last updated: 2026-03-29 07:48 UTC
512
Articles (12w)
16
Active Archetypes
8
Anomalies
20
Tracked Actors
600
CVEs
Wiper / Sabotage
⇋ SHIFTING
1 this week
▲ Rising (28.4%/w) Shift: +75.0%
Details
Mean: 1.2/w Z-score: -0.1 Recent 3w avg: 4.7/w Prior 3w avg: 2.7/w Total: 32
BEC / Wire fraud
⇋ SHIFTING
1 this week
▼ Falling (-10.5%/w) Shift: +50.0%
Details
Mean: 1.0/w Z-score: 0.03 Recent 3w avg: 2.0/w Prior 3w avg: 1.3/w Total: 25
Cryptojacking
⇋ SHIFTING
1 this week
▶ Stable (4.0%/w) Shift: +66.7%
Details
Mean: 0.7/w Z-score: 0.28 Recent 3w avg: 1.7/w Prior 3w avg: 1.0/w Total: 18
Credential theft
● NORMAL
7 this week
▶ Stable (2.1%/w) Shift: +39.6%
Details
Mean: 8.9/w Z-score: -0.18 Recent 3w avg: 22.3/w Prior 3w avg: 16.0/w Total: 231
Ransomware
● NORMAL
3 this week
▶ Stable (-9.6%/w) Shift: -7.7%
Details
Mean: 2.5/w Z-score: 0.15 Recent 3w avg: 4.0/w Prior 3w avg: 4.3/w Total: 66
Ad fraud
● NORMAL
1 this week
▶ Stable (7.3%/w) Shift: -16.7%
Details
Mean: 0.8/w Z-score: 0.22 Recent 3w avg: 1.7/w Prior 3w avg: 2.0/w Total: 20
DDoS
● NORMAL
1 this week
▶ Stable (-7.2%/w) Shift: -20.0%
Details
Mean: 0.7/w Z-score: 0.27 Recent 3w avg: 1.3/w Prior 3w avg: 1.7/w Total: 19

Low Volume

< 10 articles — limited statistical significance
Prepositioning
⚠ SPIKE
9 total (12w)
Defacement
⚠ SPIKE
5 total (12w)
Payment card theft
⚠ SPIKE
2 total (12w)
Crypto theft
⚠ SPIKE
1 total (12w)
Data exposure
⚠ SPIKE
1 total (12w)
Influence operations
⚠ SPIKE
1 total (12w)
Sextortion
⇋ SHIFTING
2 total (12w)
Archetype Status This Week Mean Z-Score Total (12w) Trend Shift
Initial access brokering significant 11 2.7 2.21 70 -4.2%/w +185.7%
Espionage significant 10 0.4 5.0 10 +100.0%/w +100.0%
Prepositioning significant 9 0.3 5.0 9 +100.0%/w +100.0%
Defacement significant 1 0.2 2.05 5 -9.1%/w +100.0%
Payment card theft significant 2 0.1 5.0 2 +100.0%/w +100.0%
Crypto theft significant 1 0.0 5.0 1 +100.0%/w +100.0%
Data exposure significant 1 0.0 5.0 1 +100.0%/w +100.0%
Influence operations significant 1 0.0 5.0 1 +100.0%/w +100.0%
Wiper / Sabotage shifting 1 1.2 -0.1 32 +28.4%/w +75.0%
BEC / Wire fraud shifting 1 1.0 0.03 25 -10.5%/w +50.0%
Cryptojacking shifting 1 0.7 0.28 18 +4.0%/w +66.7%
Sextortion shifting 0 0.1 -0.29 2 +36.4%/w +100.0%
Credential theft normal 7 8.9 -0.18 231 +2.1%/w +39.6%
Ransomware normal 3 2.5 0.15 66 -9.6%/w -7.7%
Ad fraud normal 1 0.8 0.22 20 +7.3%/w -16.7%
DDoS normal 1 0.7 0.27 19 -7.2%/w -20.0%
Actor Articles Associated Archetypes
TeamPCP 23 Credential theft (15) Initial access brokering (2) Wiper / Sabotage (2)
LockBit 18 Ransomware (18)
Handala 15 Wiper / Sabotage (14) DDoS (1)
Lazarus Group 12 Credential theft (6) BEC / Wire fraud (2) Ransomware (2)
MuddyWater 11 Wiper / Sabotage (7) Credential theft (2) DDoS (2)
Contagious Interview 10 Credential theft (9) Initial access brokering (1)
Qilin 10 Ransomware (9) Wiper / Sabotage (1)
DragonForce 7 Ransomware (7)
Akira 7 Ransomware (7)
APT28 6 Credential theft (4) Ransomware (1) Espionage (1)
APT33 6 Wiper / Sabotage (4) DDoS (1) Credential theft (1)
ShinyHunters 6 Credential theft (3) Ransomware (3)
RansomHub 5 Ransomware (5)
Charming Kitten 5 Wiper / Sabotage (2) DDoS (1) Credential theft (1)
BlackCat 4 Ransomware (4)
Black Basta 4 Ransomware (3) Initial access brokering (1)
APT42 4 Wiper / Sabotage (2) DDoS (1) Credential theft (1)
Forest Blizzard 4 Credential theft (3) Espionage (1)
APT34 4 Wiper / Sabotage (3) DDoS (1)
OilRig 4 DDoS (2) Wiper / Sabotage (2)
Citrix NetScaler ADCNetScaler ADC (Citrix ADC)NetScaler Gateway (Citrix Gateway)
2 this week 2 total 1w active
Articles Critical Out-of-Bounds Memory Read Vulnerability in Citrix NetScaler ADC and Net Critical Memory Leak Vulnerability in Citrix NetScaler ADC and NetScaler Gateway
DebianOpenSSHCilium
1 this week 1 total 1w active
Articles AS211590 Bucklog/FBW Networks: Anatomy of a Kubernetes-Orchestrated Scanning and
DebianOpenSSHCilium
1 this week 1 total 1w active
Articles AS211590 Bucklog/FBW Networks: Anatomy of a Kubernetes-Orchestrated Scanning and
Claude CodeGemini CLICodex CLI
1 this week 1 total 1w active
Articles Runtime Detection of AI Coding Agents: Syscall-Level Threat Modeling for Claude
Claude CodeGemini CLICodex CLI
1 this week 1 total 1w active
Articles Runtime Detection of AI Coding Agents: Syscall-Level Threat Modeling for Claude
Windows Admin CenterWindows Server 2022Windows Server 2025
1 this week 1 total 1w active
Articles CVE-2026-26119: Authentication Reflection in Windows Admin Center Enabling Domai
Microsoft SharePoint
1 this week 1 total 1w active
Articles Kritische Microsoft SharePoint Schwachstelle (CVE-2026-20963) wird aktiv ausgenu
CVE-2025-61882
PERSISTENT
0 this week 8 total 5w active
CVE-2025-53770
PERSISTENT
0 this week 6 total 5w active
CVE-2025-68613
PERSISTENT
1 this week 6 total 6w active
1 this week 7 total 3w active
CVE-2025-5777
ACTIVE
1 this week 3 total 3w active
1 this week 3 total 3w active
1 this week 2 total 2w active
1 this week 2 total 2w active
1 this week 2 total 2w active