Cyber Threat Report: June 2026
2373
Threat Clusters
12904
Articles Analyzed
51.0
Avg Threat Score
148
Rising Entities
Top threats
Critical Joomla JCE Vulnerability Under Active Exploitation
87.2
Critical Exploitation of Cisco CM and Samsung KNOX Vulnerabilities
86.0
Critical Unauthenticated RCE Vulnerability in LiteLLM Exploited in the Wild
86.0
CVE-2026-47668: Unauthenticated RCE Vulnerability in DbGate
86.0
Critical Remote Code Execution Vulnerability Exploited by China-Nexus Actor
80.7
Operation Highland: Velvet Ant's Decade-Long Espionage Campaign
80.7
Israel Urges Strengthened Cybersecurity for Remote Access Amid Rising Threats
80.2
F5 Issues Critical Patches for NGINX Vulnerabilities Allowing Remote Code Execution
80.0
Critical SQL Injection Vulnerability in GPTranslate Plugin (CVE-2026-49776)
79.5
Gamaredon Exploits WinRAR Vulnerability in Ongoing Ukraine Campaign
79.5
GhostShell Malware Targets Ukraine's UAV and Defense Supply Chain
79.3
Critical CVE-2026-48768 Vulnerability in TypeBot Exposes Users to File Upload Attacks
78.8
Ransomware leak sites this month
807 victim listings across 66 groups, from ThreatCluster's own collection of ransomware leak sites. Listings are claims by the groups, not confirmed breaches. Most-listed sectors: Not Found (157), Business Services (140), Manufacturing (91), Technology (66), Consumer Services (66).
| Group | Listings |
|---|---|
| thegentlemen | 117 |
| qilin | 85 |
| lockbit5 | 59 |
| akira | 33 |
| incransom | 33 |
| krybit | 29 |
| nova | 29 |
| dragonforce | 28 |
| safepay | 24 |
| shinyhunters | 24 |
Ransomware tracker · Dark web API
Rising entities
Apt Group
- Gamaredon+900%
- Apt32+900%
- ShinyHunters+53%
- Scattered Spider+200%
- OceanLotus+400%
Attack Type
- Data Breach+18%
- Ransomware+17%
- DDoS+32%
- Denial of Service+130%
- Phishing+5%
Campaign
- Operation Endgame+833%
- FileFix+100%
- FortiBleedNEW
- HadesNEW
- Boss ScamNEW
Company
- Fedora+131%
- Ubuntu+48%
- Jaguar Land Rover+180%
- Anthropic+100%
- Meta+189%
Country
- France+37%
- Lebanon+79%
- Switzerland+148%
- Canada+16%
- Bulgaria+183%
Cve
- CVE-2025-54518+550%
- CVE-2026-33814+1050%
- CVE-2026-46300+136%
- CVE-2026-23274+900%
- CVE-2026-46333+88%
Cwe
Eth
Industry
- Government+18%
- Healthcare+27%
- Technology+48%
- Manufacturing+20%
- Hospitality+600%
Mitre Attack
Ransomware Group
- Qilin+300%
- Black Basta+450%
- Akira+89%
- Rhysida+140%
- DragonForce+233%
Tool
- Nginx+126%
- Microsoft Teams+88%
- Curl+87%
- Gmail+108%
- Openssl+1300%
Vulnerability
- Path Traversal+800%
- XSS+19%
- EchoLeak+400%
- Moveit+200%
- EternalBlue+33%
Entity type distribution
| Entity type | Count |
|---|---|
| Cve | 2091 |
| Platform | 1612 |
| Company | 1276 |
| Tool | 709 |
| Malware | 373 |
| Campaign | 282 |
| Country | 245 |
| Apt Group | 202 |
| Vulnerability | 178 |
| Mitre Attack | 152 |
| Industry | 94 |
| Ransomware Group | 78 |
| Attack Type | 57 |
| Cwe | 46 |
| Eth | 8 |