Cyber Threat Report: August 2026
1353
Threat Clusters
7834
Articles Analyzed
55.2
Avg Threat Score
152
Rising Entities
Top threats
Critical RCE Vulnerabilities in Joomla Extensions CVE-2026-48907 & CVE-2026-48908
89.0
Critical RCE Vulnerability in Prompty (CVE-2026-73299) Requires Immediate Action
84.3
Active Exploitation of GitLab CVE-2026-19478 and Microsoft Entra ID Flaw
84.0
Lazarus Group Exploits Windows Zero-Day to Target Defense Sector
81.0
Critical RCE Vulnerability in Windows IKE Actively Exploited
80.9
Microsoft SharePoint Attacks: Over 400 Victims Including US Agencies
80.8
Chinese Operator Breaches Philippine Nuclear and Naval Entities
80.7
Critical RCE Vulnerability in IBM Langflow Under Active Exploitation
80.2
Critical RCE Vulnerability in Zimbra Exploited by Attackers
79.0
CISA Warns of Critical Exploits in Langflow, Tomcat, and N-central Flaws
79.0
Storm-1175 Deploys New StormEncryptor Ransomware Targeting N-central Systems
78.8
Critical Oracle WebLogic Flaw Under Active Exploitation
78.8
Ransomware leak sites this month
1,252 victim listings across 86 groups, from ThreatCluster's own collection of ransomware leak sites. Listings are claims by the groups, not confirmed breaches. Most-listed sectors: Manufacturing (191), Technology (167), Not Found (151), Professional Services (142), Other (123).
| Group | Listings |
|---|---|
| qilin | 166 |
| thegentlemen | 116 |
| clop | 88 |
| krybit | 50 |
| direwolf | 46 |
| orova | 45 |
| incransom | 44 |
| storm | 41 |
| akira | 34 |
| lockbit5 | 31 |
Ransomware tracker · Dark web API
Rising entities
Apt Group
- Kimsuky+338%
- Mustang Panda+500%
- Salt Typhoon+83%
- Lazarus+400%
- TeamPCP+75%
Attack Type
- Malware+4%
- Phishing+2%
- Man-in-the-Middle+44%
- Command Injection+67%
- Worm+29%
Campaign
- Helix+400%
- Storm-1516+400%
- Operation Epic Fury+75%
- Redact+300%
- Operation Sindoor+20%
Company
- Anthropic+261%
- NASA+1400%
- Department of Justice+2600%
- Cursor+100%
- Snowflake+500%
Country
- China+32%
- Iran+36%
- Switzerland+180%
- Taiwan+106%
- North Korea+20%
Cve
- CVE-2026-53587+600%
- CVE-2026-53584+600%
- CVE-2026-53585+600%
- CVE-2026-53586+600%
- CVE-2026-46113+1200%
Cwe
Eth
Industry
- Financial+7%
- Utilities+367%
- Retail+24%
- Manufacturing+10%
- Hospitality+78%
Malware
- StealC+2900%
- Vidar+500%
- LummaC2+283%
- Atomic Stealer+650%
- Lumma+1100%
Mitre Attack
Tool
- Claude Code+55%
- Curl+71%
- Python+36%
- DeepSeek+133%
- VMware+100%
Vulnerability
- OS Command Injection+350%
- Citrix NetScaler+600%
- RoguePlanet+44%
- Log4Shell+67%
- KindaRails2Shell+200%
Entity type distribution
| Entity type | Count |
|---|---|
| Cve | 3057 |
| Platform | 1476 |
| Company | 1076 |
| Tool | 670 |
| Malware | 436 |
| Campaign | 228 |
| Apt Group | 205 |
| Vulnerability | 188 |
| Country | 187 |
| Mitre Attack | 158 |
| Industry | 84 |
| Ransomware Group | 77 |
| Attack Type | 63 |
| Cwe | 59 |
| Eth | 54 |
| Btc | 1 |
| Xmr | 1 |