Cyber Threat Report: March 2026
2094
Threat Clusters
19115
Articles Analyzed
51.8
Avg Threat Score
134
Rising Entities
Top threats
APT28 Exploits MSHTML Zero-Day Vulnerability in Windows
94.3
AzCopy Utility Exploited in Ransomware Data Exfiltration Campaigns
89.3
Massive Ransomware Attack Targets Critical Infrastructure in the U.S.
81.6
Massive Ransomware Attack Targets Critical Infrastructure in March 2026
81.0
APT28 Exploits Zimbra Vulnerability in Ongoing Attacks Against Ukraine
80.8
Massive Ransomware Attack Targets Critical Infrastructure in March 2026
79.7
Critical Vulnerabilities in Firefox and Thunderbird Require Immediate Patching
79.5
Massive Ransomware Attack Targets Critical Infrastructure in March 2026
79.5
Massive Ransomware Attack Targets Global Financial Institutions
79.0
CISA Urges Endpoint Security Enhancements After Stryker Cyberattack
78.5
Critical Exploitation of Quest KACE SMA Vulnerability Underway
78.2
TeamPCP's CanisterWorm Targets Iranian Systems with Destructive Kubernetes Wiper
78.0
Ransomware leak sites this month
876 victim listings across 48 groups, from ThreatCluster's own collection of ransomware leak sites. Listings are claims by the groups, not confirmed breaches. Most-listed sectors: Not Found (336), Manufacturing (101), Technology (94), Healthcare (52), Financial Services (43).
| Group | Listings |
|---|---|
| qilin | 146 |
| akira | 80 |
| nightspire | 71 |
| dragonforce | 64 |
| incransom | 57 |
| lockbit5 | 50 |
| thegentlemen | 50 |
| play | 46 |
| handala | 39 |
| coinbasecartel | 34 |
Ransomware tracker · Dark web API
Rising entities
Apt Group
- Volt Typhoon+100%
- Silver Fox+300%
- TeamPCP+500%
- Konni+150%
- MuddyWater+150%
Attack Type
- Supply Chain Attack+11%
- Privilege Escalation+70%
- Botnet+15%
- Prompt Injection+133%
- Server-Side Request Forgery+100%
Campaign
Country
- Iran+730%
- Israel+463%
- Russia+153%
- Ukraine+290%
- United States+129%
Cve
- CVE-2025-52881+300%
- CVE-2025-40257+300%
- CVE-2025-40254+300%
- CVE-2025-40261+300%
- CVE-2025-40259+300%
Industry
- Energy+47%
- Healthcare+15%
- Financial+8%
- Technology+18%
- Agriculture+700%
Malware
- Glassworm+175%
- Kimwolf+29%
- Brickstorm+57%
- Vidar+200%
- Mirai+200%
Mitre Attack
Platform
- GitHub+110%
- Microsoft Intune+2700%
- IOS+33%
- Safari+1000%
- Steam+950%
Ransomware Group
- Interlock+467%
- WannaCry+400%
- TheGentlemen+200%
- Clop+33%
- Nova+50%
Tool
- Microsoft Teams+175%
- Npm+68%
- GitHub Actions+550%
- Python+56%
- Gmail+41%
Vulnerability
- Log4j+200%
- IngressNightmare+100%
- AirSnitch+100%
- Cache Poisoning+100%
- EternalBlueNEW
Entity type distribution
| Entity type | Count |
|---|---|
| Cve | 1529 |
| Platform | 946 |
| Company | 820 |
| Tool | 373 |
| Malware | 284 |
| Country | 192 |
| Campaign | 189 |
| Apt Group | 155 |
| Mitre Attack | 103 |
| Vulnerability | 98 |
| Industry | 62 |
| Ransomware Group | 50 |
| Attack Type | 49 |
| Eth | 2 |
| Btc | 1 |
| Xmr | 1 |