Cyber Threat Report: July 2026
1908
Threat Clusters
11329
Articles Analyzed
49.8
Avg Threat Score
151
Rising Entities
Top threats
Cluster c188592f
92.9
Critical SonicWall SMA1000 Vulnerabilities Under Active Exploitation
87.2
Critical Command Injection Vulnerability in Arista VeloCloud Orchestrator Under Active Exploitation
84.3
Critical SQL Injection Vulnerability in NocoBase (CVE-2026-52887)
84.3
Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign
80.8
Cisco IOS Vulnerability CVE-2008-4128 Under Active Exploitation
80.0
Critical RCE Vulnerability in Rails Active Storage Disclosed
79.5
Critical Vulnerabilities in SonicWall and Fortinet Devices Exploited in the Wild
79.0
Critical Vulnerability CVE-2026-4767 in TR7 Cyber Defense WAF-ASP
78.9
Widespread DNS Poisoning Campaign Targets Hotel Wi-Fi to Steal Credentials
78.5
DarkSword iOS Exploit Chain Targets Mobile Devices Globally
78.5
Malware Spread via Fake Polymarket Trading Bot Targets DeFi Developers
78.5
Ransomware leak sites this month
998 victim listings across 64 groups, from ThreatCluster's own collection of ransomware leak sites. Listings are claims by the groups, not confirmed breaches. Most-listed sectors: Manufacturing (136), Not Found (116), Technology (115), Business Services (104), Healthcare (85).
| Group | Listings |
|---|---|
| thegentlemen | 179 |
| qilin | 133 |
| deadlock | 85 |
| dragonforce | 42 |
| incransom | 40 |
| crpxo | 36 |
| safepay | 33 |
| global secret group | 32 |
| krybit | 25 |
| akira | 23 |
Ransomware tracker · Dark web API
Rising entities
Apt Group
- Laundry Bear+2600%
- Apt28+243%
- Turla+160%
- Dragonfly+700%
- Fancy Bear+1400%
Attack Type
- Sql Injection+105%
- Brute Force+112%
- Botnet+69%
- Trojan+62%
- Credential Stuffing+21%
Campaign
- Operation Riptide+225%
- Contagious Interview+100%
- SolarWinds Compromise+300%
- Boss Scam+33%
- Operation Atlantic+200%
Company
- OpenAI+217%
- Reliance Group+2600%
- Drift Protocol+400%
- Medtronic+1200%
- Langflow+250%
Cve
- CVE-2025-55182+900%
- CVE-2025-3248+900%
- CVE-2026-8451+600%
- CVE-2026-46331+250%
- CVE-2026-43499+250%
Cwe
Eth
Malware
- Pegasus+89%
- Lumma Stealer+533%
- Mirai+800%
- AsyncRAT+367%
- React2Shell+900%
Mitre Attack
Tool
- Hugging Face+1862%
- Dropbox+144%
- GitHub Copilot+1300%
- AnyDesk+171%
- Tornado Cash+125%
Vulnerability
- Spring4Shell+300%
- Path Traversal+22%
- CitrixBleed+200%
- Wp2shellNEW
- JanuscapeNEW
Entity type distribution
| Entity type | Count |
|---|---|
| Cve | 2917 |
| Platform | 1424 |
| Company | 1102 |
| Tool | 724 |
| Malware | 573 |
| Apt Group | 300 |
| Campaign | 255 |
| Country | 233 |
| Vulnerability | 184 |
| Mitre Attack | 179 |
| Ransomware Group | 100 |
| Industry | 88 |
| Cwe | 53 |
| Attack Type | 53 |
| Eth | 14 |
| Btc | 1 |