Cyber Threat Report: W/C June 29, 2026
383
Threat Clusters
2557
Articles Analyzed
54.8
Avg Threat Score
142
Rising Entities
Top threats
Critical Vulnerability CVE-2026-4767 in TR7 Cyber Defense WAF-ASP
78.9
Malware Spread via Fake Polymarket Trading Bot Targets DeFi Developers
78.5
Armored Likho APT Targets Power Grids with BusySnake Stealer Malware
78.0
Critical RCE Vulnerability in Divi Form Builder Plugin for WordPress
78.0
Critical Privilege Escalation Vulnerability in ProfileGrid Plugin for WordPress
78.0
Critical Authentication Bypass Vulnerability in Gorse Exposed
78.0
Critical RCE Vulnerability in PTC Windchill and FlexPLM Under Active Exploitation
78.0
US Offers $10M Reward for Information on Russian Hackers Targeting Messaging Apps
77.0
Google and FBI Disrupt NetNut Proxy Network Linked to 2 Million Devices
76.5
Major Cyber Breach: Russian Hackers Compromise UK Government Logins
75.9
Critical Bad Epoll Vulnerability Grants Root Access to Unprivileged Users
75.0
Russia's Shadow Fleet Conducts Drone Surveillance on European Nuclear Sites
74.9
Ransomware leak sites this week
224 victim listings across 38 groups, from ThreatCluster's own collection of ransomware leak sites. Listings are claims by the groups, not confirmed breaches. Most-listed sectors: Business Services (46), Not Found (32), Manufacturing (22), Technology (21), Healthcare (21).
| Group | Listings |
|---|---|
| thegentlemen | 41 |
| qilin | 30 |
| incransom | 12 |
| safepay | 12 |
| krybit | 11 |
| settra | 11 |
| genesis | 10 |
| medusalocker | 10 |
| apt73 | 8 |
| anubis | 5 |
Ransomware tracker · Dark web API
Rising entities
Apt Group
- ShinyHunters+133%
- Lazarus Group+30%
- Scattered Spider+50%
- Mustang PandaNEW
- Unc3944NEW
Attack Type
- Malware+29%
- Phishing+20%
- Zero-day Exploit+47%
- Brute Force+243%
- Botnet+280%
Campaign
- Operation Riptide+800%
- FortiBleed+33%
- Boss Scam+33%
- StegoAdNEW
- PolinRiderNEW
Company
- Azure+100%
- Langflow+700%
- Drift Protocol+600%
- Google+167%
- Booking.com+500%
Country
- Russia+35%
- Belgium+260%
- Poland+133%
- United States+19%
- Spain+91%
Cve
- CVE-2025-55182+700%
- CVE-2026-39830+100%
- CVE-2026-33017+200%
- CVE-2026-50548NEW
- CVE-2026-50549NEW
Cwe
Industry
- Finance+400%
- Retail+100%
- Logistics+100%
- Food And AgricultureNEW
- MediaNEW
Malware
- Pegasus+3200%
- AsyncRAT+350%
- React2Shell+500%
- ClickFix+50%
- Lumma Stealer+200%
Mitre Attack
Ransomware Group
- Conti+400%
- Ransomhub+200%
- CipherForce+100%
- Silent Ransom Group+100%
- VectNEW
Tool
- Tornado Cash+800%
- ScreenConnect+600%
- Chrome+125%
- Google Chrome+100%
- Dropbox+150%
Vulnerability
- Path Traversal+400%
- Use-After-Free+100%
- DuneSlideNEW
- Bad EpollNEW
- Log4ShellNEW
Entity type distribution
| Entity type | Count |
|---|---|
| Platform | 434 |
| Company | 354 |
| Cve | 282 |
| Tool | 246 |
| Malware | 149 |
| Country | 98 |
| Mitre Attack | 92 |
| Campaign | 64 |
| Apt Group | 52 |
| Vulnerability | 43 |
| Cwe | 39 |
| Ransomware Group | 32 |
| Industry | 28 |
| Attack Type | 27 |
| Eth | 1 |
| Btc | 1 |