Cyber Threat Report: W/C July 20, 2026
341
Threat Clusters
2004
Articles Analyzed
56.3
Avg Threat Score
143
Rising Entities
Top threats
Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign
80.8
Critical Vulnerabilities in SonicWall and Fortinet Devices Exploited in the Wild
79.0
Widespread DNS Poisoning Campaign Targets Hotel Wi-Fi to Steal Credentials
78.5
Critical Authorization Vulnerability in SiYuan (CVE-2026-66012)
78.0
MuddyWater Targets U.S. Entities Amid Geopolitical Tensions
77.9
Drift Protocol Hack: $285M Stolen Funds Transferred After Months of Dormancy
77.0
Kimsuky Exploits South Korean Groupware Vendors with New Gomir Variants
77.0
Russian Hackers Target US Nuclear Scientists and Defense Contractors
77.0
UAC-0099 Exploits Notepad++ to Distribute Malware in Ukraine
77.0
State-Sponsored Actors Target Network Edge Devices Amid Rising Exploits
77.0
Russian GRU Hackers Use Fake CAPTCHAs to Compromise Ukrainian Users
77.0
Fake Bahrain Civil Defense App Distributes Advanced Surveillance Malware
76.0
Ransomware leak sites this week
306 victim listings across 46 groups, from ThreatCluster's own collection of ransomware leak sites. Listings are claims by the groups, not confirmed breaches. Most-listed sectors: Manufacturing (46), Technology (46), Professional Services (42), Healthcare (29), Retail & E-Commerce (24).
| Group | Listings |
|---|---|
| qilin | 36 |
| thegentlemen | 32 |
| global secret group | 31 |
| crpxo | 20 |
| safepay | 20 |
| section9 | 18 |
| deadlock | 15 |
| exfilsquad | 15 |
| nightspire | 13 |
| nova | 13 |
Ransomware tracker · Dark web API
Rising entities
Apt Group
- Apt28+220%
- Apt29+700%
- Fancy Bear+200%
- Forest Blizzard+200%
- MuddyWater+300%
Attack Type
- Zero-day Exploit+88%
- Phishing+30%
- Denial of Service+107%
- Sql Injection+30%
- Credential Stuffing+60%
Campaign
- Contagious Interview+200%
- Operation Endgame+100%
- SolarWinds CompromiseNEW
- FakeAgentNEW
- HadesNEW
Country
- Saudi Arabia+1300%
- Indonesia+300%
- Kazakhstan+600%
- Thailand+44%
- Brazil+80%
Cve
- CVE-2026-63030+400%
- CVE-2026-60137+250%
- CVE-2026-56434+500%
- CVE-2026-60005+500%
- CVE-2026-42533+100%
Cwe
Eth
Industry
- Technology+188%
- Retail+100%
- Hospitality+500%
- Finance+300%
- Telecommunications+7%
Malware
- Agent Tesla+250%
- ClickFix+200%
- Kimwolf+200%
- AsyncRAT+300%
- Aisuru+25%
Mitre Attack
Ransomware Group
- Asahi+50%
- Cl0p+100%
- QilinNEW
- RansomHouseNEW
- ChaosNEW
Tool
- Hugging Face+2267%
- Nginx+71%
- Chrome+80%
- Docker+133%
- Google Cloud+150%
Vulnerability
- Wp2shell+112%
- XSS+114%
- Path Traversal+200%
- RefluXFSNEW
- HermeticReaderNEW
Entity type distribution
| Entity type | Count |
|---|---|
| Cve | 1636 |
| Platform | 442 |
| Malware | 278 |
| Company | 278 |
| Tool | 231 |
| Apt Group | 186 |
| Country | 129 |
| Mitre Attack | 116 |
| Campaign | 77 |
| Industry | 50 |
| Vulnerability | 47 |
| Cwe | 31 |
| Ransomware Group | 27 |
| Attack Type | 24 |
| Eth | 3 |