Skip to content

Q3 2026 threat intelligence report

Ransomware named more organisations than in any other quarter this year. The ways in were edge appliances and ClickFix.

Published October 2026. TLP:CLEAR. Covers 1 July to 30 September 2026, with Q2 2026 (1 April to 30 June) as the comparison quarter.

Read the report
3,072
leak-site listings
+75%
110
groups posting
+39%
67
zero-day clusters
from 34
64
CVEs added to KEV
+36%
42
ClickFix clusters
+163%
74,026
articles processed
-12%

Executive summary

Ransomware groups named more organisations on their leak sites in Q3 2026 than in any other quarter this year. Our collection logged 3,072 listings, up 75% on Q2's 1,758, posted by 110 groups (79 in Q2) and naming organisations in 126 countries. August was the peak, with 1,214 listings, the busiest month of 2026.

The groups doing the posting changed over the quarter. The Gentlemen overtook Qilin as the most prolific brand, 396 listings to 366. Brands posting for the first time arrived at volume, led by Storm (78) and Global Secret Group (48). Manufacturing was the most-listed sector (465), ahead of technology (371), professional services (291) and healthcare (284). Organisations in the United States made up 33% of all listings.

Leak sites show who the groups claim to have breached. The highest-scoring reporting of the quarter described the ways in. Exploitation of network edge and security appliances accounted for 7 of the 10 highest-scoring clusters, led by the Cisco ISE zero-day at 89, the top score of the quarter. The other 6 concerned Cisco Secure Firewall Management Center, SonicWall SMA1000, Arista VeloCloud Orchestrator, Citrix NetScaler, Cisco Secure Email Gateway and F5 BIG-IP APM. Clusters with "zero-day" in the title rose from 34 to 67. CISA added 64 CVEs to its Known Exploited Vulnerabilities (KEV) catalogue, against 47 in Q2, and 7 of the 10 CVEs named in the most clusters were in KEV by the end of September.

The other route that grew was ClickFix, where a fake web page talks the user into pasting and running a command. Clusters describing ClickFix and its variants (FileFix, fake CAPTCHA pages) rose from 16 to 42. Their average threat score of 67 was the highest of any theme we track. Infostealers, the usual payload, held level at 74 clusters against 70, although StealC drew 22 of its 34 mentions in September.

AI coverage grew 6% to 1,527 clusters at an average score of 47, because most of it is product and policy news. The part of it turning into security reporting, on AI agents and MCP, grew faster: up 43% to 299 clusters.

Healthcare featured in both sources of data. Its leak-site listings doubled to 284 and press coverage of the sector rose 35% to 620 tagged articles. Government coverage rose 31% to 1,242, education 19% to 276 and retail 59% to 178. Coverage of most countries fell, most sharply Iran (down 62%) and Israel (down 63%), while Australia (up 25%) and Poland (up 14%) rose. Supply-chain coverage fell 35% from a Q2 total that included the Shai-Hulud npm reporting.

All of this comes from a quarter in which we collected less. ThreatCluster processed 74,026 articles from 11,144 sources and grouped them into 6,166 clusters. Ingestion fell 12% on Q2 while the source base grew 4%, and clusters fell 8%, leaving 12.0 articles per cluster against 12.6. Collection was also uneven, with August held down by a fault in our fetcher (see the collection notes). The rise in zero-day and edge-device clusters came despite that drop.

The quarter in numbers

Q3 2026Q2 2026Change
Articles processed74,02684,398-12%
Clusters6,1666,676-8%
Unique sources11,14410,672+4%
Articles per day813938-13%
Articles per cluster12.012.6
Clusters scoring 80+3718+106%
Clusters scoring 65+1,8772,099-11%
Leak-site victim listings3,0721,758+75%
Groups posting11079+39%
Countries named in listings126100+26%
CVEs added to CISA KEV6447+36%
Validated indicators extracted2,6811,109+142%

Monthly volume

July
24,170
August
17,707
September
32,149

July had 24,170 articles in 1,911 clusters at an average score of 51.5. August had 17,707 articles in 1,335 clusters at 55.3, so fewer clusters at a higher average. September had 32,149 articles in 2,730 clusters at 50.1, and produced 23 of the quarter's 37 clusters scoring 80 or above.

Severity

Clusters scoring 80 or above more than doubled, from 18 to 37, while those scoring 65 or above fell 11% to 1,877. The quarter's highest score was 89, for the Cisco ISE zero-day on 16 September.

Sources

Linuxsecurity contributed the most articles (4,571), followed by Sploitus (2,796), cve.org (1,764), Microsoft MSRC (1,324), Redpacketsecurity (993), GBHackers (903), Cybersecuritynews (895), 4sysops (642), The Hacker News (606) and BleepingComputer (599). Advisory and exploit feeds hold the top 4 places, which raises the share of vulnerability material in every count below.

The quarter's stories

Microsoft's Patch Tuesday release of 8 September gathered 927 articles into one cluster, the largest of the quarter. Next came the coordinated attack on Minnesota water utilities (198 articles, score 77), the Microsoft Edge vulnerability bulletin (190), EU and UK sanctions on Russian cyber networks (125, score 78) and the SonicWall SMA1000 zero-day (123, score 81).

Ransomware and the leak sites

Figures in this section come from our own collection of listings on ransomware groups' leak sites, which covers 239 groups. Press coverage of ransomware follows at the end of the section.

Volume

2,257
Q1 2026
1,758
Q2 2026
3,072
Q3 2026
980
July
1,214
August
878
September

Listings ran at 980 in July, 1,214 in August and 878 in September. The quarter's 3,072 compares with 1,758 in Q2 and 2,257 in Q1.

New groups

The largest groups posting for the first time were Storm (78), Global Secret Group (48), Orova (47), Crpxo (37), Panzer (35), Emperador (34), Dark Project (30), L Group (28), Zawoo (25), Booba Project (24), Majinahanashi (22) and Section9 (20). These 12 account for 428 listings, 14% of the quarter.

Storm 78Global Secret Group 48Orova 47Crpxo 37Panzer 35Emperador 34Dark Project 30L Group 28Zawoo 25Booba Project 24Majinahanashi 22Section9 20
GroupQ3Q2
The Gentlemen396193
Qilin366213
Cl0p11427 or fewer
INC Ransom11273
Krybit9550
DeadLock9127 or fewer
Akira90102
Storm78new
SafePay7743
DragonForce69132
Direwolf6027 or fewer
LockBit 5.05987
Settra5627 or fewer
Play5034
Global Secret Group48new

"27 or fewer" marks groups outside the Q2 top 15, whose lowest entry had 27 listings.

The Gentlemen doubled its listings and took first place from Qilin. DragonForce fell 48% and LockBit 5.0 fell 32%. Cl0p moved from outside the Q2 top 15 to third.

Vulnerabilities and zero-days

Clusters with "zero-day" in the title rose from 34 in Q2 to 67. Network edge or security appliances account for 7 of the 9 highest-scoring exploitation clusters, and in September alone we clustered in-the-wild exploitation of five of them. Clusters on edge devices and VPNs rose 34% over the quarter, from 124 to 166.

  1. 2 SepSonicWall SMA1000
  2. 14 SepCisco Secure Email Gateway
  3. 16 SepCisco ISE
  4. 22 SepF5 BIG-IP APM
  5. 26 to 28 SepCitrix NetScaler

The quarter's exploitation clusters by score, whether or not the title uses the term "zero-day".

ClusterDateScoreArticlesEdge
Cisco ISE zero-day under active exploitation16 Sep8959yes
Cisco FMC authentication bypass exploitedSep8869yes
SonicWall SMA1000 vulnerabilities exploitedSep8742yes
Arista VeloCloud Orchestrator command injection exploitedSep8412yes
Citrix NetScaler zero-days exploited28 Sep8267yes
Cisco Secure Email Gateway zero-day exploited14 Sep8237yes
F5 BIG-IP APM zero-day, remote code execution22 Sep8225yes
Lazarus exploits Windows zero-day against the defence sector12 Aug8121
GitLab vulnerabilities exploited within hours of disclosureSep8167

KEV and CVE volume

64 vs 47

CVEs added to the CISA KEV catalogue in Q3 against Q2.

37,712

CVEs published by the CVE programme in the quarter, against 20,871 in Q2, a rise of 81% that is independent of our collection.

7 of 10

Most-covered CVEs that were in KEV by the end of September.

Actors, malware and techniques

Lazarus Group
100
APT28
72
Kimsuky
62
APT29
50
ShinyHunters
41
Sandworm
34
Turla
30
Scattered Spider
26
Mustang Panda
24
Volt Typhoon
23

Articles in which the group was tagged.

Groups

Lazarus Group led with 100 articles. Its August campaign against the defence sector, using a Windows zero-day, scored 81. APT28 followed with 72, then Kimsuky 62, APT29 50, ShinyHunters 41, Sandworm 34, Turla 30, Scattered Spider 26, Mustang Panda 24 and Volt Typhoon 23.

Malware

Pegasus led with 108 mentions, ahead of Mirai (42), Vidar (40), StealC (34), Lumma under two tags (LummaC2 and Lumma Stealer, 32 each), RedLine (28) and Cobalt Strike (28). StealC rose in September, which accounted for 22 of its 34 mentions.

Of the families first seen this quarter, those with sustained reporting were WeWorm (15 articles), NoviSpy (13), SparroWocky (12), RatHat (12), NeedyMantis (10) and RevStealer (10).

WeWorm 15NoviSpy 13SparroWocky 12RatHat 12NeedyMantis 10RevStealer 10

Themes and emerging technology

Clusters whose title or summary carries the theme, Q3 against Q2, with the average threat score of the Q3 clusters.

ThemeQ3Q2ChangeAvg score
AI and LLMs (all)1,5271,443+6%
47
AI agents and MCP299209+43%
48
Deepfakes198182+9%
51
ClickFix, FileFix, fake CAPTCHA4216+163%
67
Zero-days12888+45%
65
Edge devices and VPNs166124+34%
59
Infostealers7470+6%
65
Cloud, identity and SaaS229293-22%
51
Supply chain (incl. npm, PyPI)210322-35%
54
Quantum115152-24%
28

The zero-day row counts title or summary matches, so it is broader than the title-only count of 67 used above.

AI is the largest theme by volume and among the lowest-scoring, because most of it is product and policy news. Within it, the agent and MCP subset carries the security reporting: vulnerabilities in MCP servers, agent hijacking, prompt injection through tool results, and organisations deploying agents without governance in place. Quantum coverage is almost entirely policy and vendor announcements, with an average score of 28. ClickFix is small and growing fast, and has the highest average score in the table.

Carried into Q4

  • Agentic tooling as an attack surface, with CVEs in MCP and agent frameworks and clusters describing malware aimed at AI coding assistants.
  • Deepfake-enabled fraud in executive impersonation and recruitment scams.
  • Edge-device exploitation, with appliances from SonicWall, Cisco, Arista, F5 and Citrix all exploited in the wild during September.
  • Attacks on water and other municipal utilities. The Minnesota cluster was the second most-covered of the quarter.

The platform in Q3

+58%
registered users
September the biggest sign-up month
13x
API keys in issue
over the quarter
26x
weekly API requests
week of 31 Aug to week of 21 Sep
+142%
validated indicators
2,681 in Q3
+143%
IOC feed pulls
July to September
+72%
MCP tool calls
July to September
SHA-256
946
Domains
797
MD5
653
IPv4
198
SHA-1
87

Validated indicators extracted from Q3 reporting, 2,681 in all. The false-positive gate rejected a further 12,249 candidates.

Corpus

500 of our 504 configured feeds were active at quarter end. Of the 6,166 clusters built, 87 (1.4%) were later marked out of scope by the new scope gate.

Users and API

Registered users grew 58% over the quarter, with September the biggest sign-up month to date, and the number of API keys in issue rose thirteen-fold. External weekly request volume grew 26 times between the week of 31 August and the week of 21 September. MCP tool calls rose 72% from July to September.

Distribution

threatcluster-mcp had 505 npm downloads in the quarter. On PyPI, where it appeared on 28 September, it had about 1,000 downloads in its first 3 days. Our 3 Hugging Face datasets (incident clusters, leak-site victims, CVE exploitation signals) have 221 downloads to date. The LLM recency benchmark published on 16 September found 8 models scored 0 of 150 on summer ransomware questions unaided and 158 of 158 with ThreatCluster records.

About this report

ThreatCluster collects security reporting from open sources and groups it into clusters using density-based semantic clustering. We then tag and count the entities in each cluster. "Mentions" is the number of distinct articles in which an entity was tagged, which measures attention in open reporting. Leak-site figures count listings on the groups' own sites. A listing is the group's claim, and some are false or recycled.

Collection notes

Ingestion fell 12% in Q3 after rising 55% in Q2. A memory fault in our fetcher depressed August's collection. In September, a source-retirement rule removed 121 feeds on the 11th until they were restored, and the summarisation service lapsed on the 26th. Every source was re-enabled on the 27th.

The source mix has moved towards advisory and exploit feeds, which lifts vulnerability counts relative to news.

On 1 October we introduced a relevance filter that removes entities tagged from sidebars, cited pages and roundups. The Q3 figures were computed after applying it to the whole corpus. The Q2 report's figures predate it, so the two quarters' entity counts are not strictly comparable.

League tables merge known aliases to canonical names. First-seen tallies do not merge aliases, and we have not used them for headline findings.

"Unique sources" counts every distinct publishing domain that appeared in the quarter; "configured feeds" counts the feeds we poll. One feed can surface many domains.

[email protected]
© 2026 ThreatCluster Ltd (17124226). All rights reserved. 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ