Cyber Threat Report: May 2026
2365
Threat Clusters
14751
Articles Analyzed
50.5
Avg Threat Score
153
Rising Entities
Top threats
Critical Zero-Day Vulnerability CVE-2026-20182 Exploited in Cisco SD-WAN Systems
87.2
Critical Zero-Day Vulnerability in LiteSpeed cPanel Plugin Actively Exploited
86.0
GRU Compromises Home Routers in 23 States to Steal Outlook Credentials
80.8
SHADOW-EARTH-053 Exploits Microsoft Exchange Vulnerabilities in Asia
80.7
Critical SQL Injection Vulnerability in Drupal Core Actively Exploited
80.2
Russian SVR Exploits SolarWinds and Other Vulnerabilities Against U.S. Networks
80.0
Russia Launches Nuclear-Capable Missile Strike on Ukraine's Capital
79.2
Critical NGINX Vulnerability CVE-2026-42945 Exposes Millions to RCE and DoS Attacks
78.8
Critical Samba Vulnerability Allows Remote Code Execution
78.0
Critical Memory Overread Vulnerability in Citrix NetScaler Exploited
78.0
GCHQ Warns of Escalating Russian Cyber Threats to UK Infrastructure
78.0
Ghost CMS SQL Injection Exploits 700+ Sites in Ongoing ClickFix Campaign
78.0
Ransomware leak sites this month
467 victim listings across 47 groups, from ThreatCluster's own collection of ransomware leak sites. Listings are claims by the groups, not confirmed breaches. Most-listed sectors: Business Services (90), Not Found (74), Manufacturing (61), Technology (39), Healthcare (37).
| Group | Listings |
|---|---|
| qilin | 76 |
| dragonforce | 55 |
| thegentlemen | 40 |
| akira | 25 |
| nova | 24 |
| incransom | 20 |
| safepay | 18 |
| play | 16 |
| nightspire | 15 |
| cmdorganization | 13 |
Ransomware tracker · Dark web API
Rising entities
Apt Group
- Lazarus Group+76%
- Sandworm+300%
- TeamPCP+100%
- MuddyWater+120%
- Earth Estries+500%
Attack Type
- Supply Chain Attack+37%
- Data Breach+8%
- Zero-day Exploit+22%
- Phishing+8%
- Malware+5%
Btc
Campaign
- Operation Sindoor+275%
- Operation Epic Fury+9%
- Resilient Trident+200%
- Operation Endgame+50%
- The Last Ones+100%
Company
- Ubuntu+38%
- Azure+71%
- X+62%
- Arbitrum+250%
- Manage My Health+1600%
Cve
- CVE-2026-31431+20%
- CVE-2026-20127+125%
- CVE-2026-41940+200%
- CVE-2018-0802+300%
- CVE-2026-1281+33%
Cwe
Eth
Industry
- Financial+40%
- Government+21%
- Transportation+47%
- Retail+40%
- Manufacturing+15%
Malware
- Mini Shai-Hulud+800%
- Shai-hulud+380%
- Cobalt Strike+100%
- ClickFix+150%
- Glassworm+100%
Mitre Attack
Ransomware Group
- Nitrogen+2200%
- WannaCry+300%
- Cl0p+450%
- Conti+140%
- The Gentlemen+200%
Vulnerability
- Copy Fail+104%
- XSS+61%
- RedSun+217%
- UnDefend+275%
- Dirty Pipe+550%
Entity type distribution
| Entity type | Count |
|---|---|
| Platform | 1438 |
| Company | 1259 |
| Cve | 941 |
| Tool | 635 |
| Malware | 379 |
| Campaign | 312 |
| Country | 243 |
| Apt Group | 229 |
| Mitre Attack | 142 |
| Vulnerability | 123 |
| Industry | 94 |
| Ransomware Group | 79 |
| Attack Type | 56 |
| Cwe | 42 |
| Eth | 16 |
| Btc | 3 |