REPORT   2026  2025  2024  2023  2022  2020  2019  2018  2017

DATE

NAME

INFO

CATEGORY

SUBCATE

1.6.26 ESET APT Activity Report Q4 2025–Q1 2026 CONFLICT-INFORMED ESPIONAGE: MONITORING OIL SHIPMENTS, TARGETING DRONE MAKERS REPORT REPORT
29.5.26 5 EUROPEAN THREAT LANDSCAPE REPORT Europe’s cyber threat actors are accelerating. eCrime adversaries, state-backed operators, and hacktivists are conducting faster intrusions, employing new social engineering tradecraft, and operating resilient criminal ecosystems. REPORT REPORT
28.5.26 State of AI in the Cloud 2026 How AI Adoption, Autonomy, and Attacker Innovation Are Reshaping Cloud Security REPORT REPORT
23.5.26 2026Microsoft Vulnerabilities Report13th Edition Data-packed insights and expert analysis to help you mitigate security risks in your Microsoft estate. REPORT REPORT
14.5.26 APT ActivityApril 2025 – September 2025
Report
RUSSIA-ALIGNED APTs RAMP UP ATTACKS AGAINST UKRAINE AND ITS STRATEGIC PARTNERS REPORT REPORT
11.5.26 ClickFix distributing Vidar Stealer via WordPress targeting Australian infrastructure The Australian Signals Directorate’s Australian Cyber Security Centre (ASD's ACSC) has observed ClickFix associated activity leveraging WordPress hosted infrastructure to distribute the Vidar Stealer malware. REPORT REPORT
11.5.26 Acronis Cyberthreats Report, H2 2025: From exploits to malicious IA The Acronis Cyberthreats Report covers the global threat landscape as encountered by the Acronis Threat Research Unit (TRU) and Acronis sensors in the second half of 2025. General threat data (including malware, ransomware, web and email threats, vulnerabilities, etc.) presented in the report is gathered from January–December of 2025 and reflects threats targeting endpoints we observed in this time frame. REPORT REPORT
11.5.26 State of the SOFTWARE SUPPLY CHAIN 2026 The Limits of Legacy Vulnerability Management REPORT REPORT
11.5.26 FEMITBOT Abuse of Telegram Mini Apps for Large-Scale Fraud Campaigns REPORT REPORT
5.5.26 Zscaler ThreatLabz 2026 VPN Risk Report For decades, VPN was the default answer to remote access security – reliable, familiar, and deeply embedded in enterprise architecture. That era is ending. AI has accelerated attack timelines from weeks to minutes, automated credential theft at industrial scale, and given adversaries a speed advantage that human-led defense cannot match. REPORT REPORT
28.4.26 DSCI THREAT INTELLIGENCE AND RESEARCH INITIATIVE DSCI THREAT INTELLIGENCEAND RESEARCH INITIATIVETHREAT REPORTII FEBRUARY 2026 REPORT REPORT
26.4.26 The State of BCDR 2025: Future-Proof Your Data Protection Strategies Data is the backbone of every business, driving innovation, decision-making and customer engagement. Whether you’re an MSP protecting client environments or an internal IT professional securing your organization’s infrastructure, ensuring data availability and security is both a critical responsibility and a strategic advantage. REPORT REPORT
22.4.26 Assessment | Q1 2026 Ransomware Wrap-Up
A-2026-04-17a
ZeroFox Intelligence is derived from a variety of sources, including—but not limited to—curated open-source accesses, vetted social media, proprietary data sources, and direct access to threat actors and groups through covert communication channels. REPORT REPORT
12.4.26 Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US
Critical Infrastructure
REPORT REPORT
9.3.26 Cloud Threat Horizons Report H1 2026 The Google Cloud Threat Horizons Report provides decision-makers with strategic intelligence on threats to not just Google Cloud, but all cloud service providers. REPORT REPORT
27.2.26 CISCO SD-WAN THREAT
HUNT GUIDE
The authors are aware that since 2023, at least one malicious cyber actor compromised Cisco SD-WANs via a previously unknown vulnerability, identified in late 2025 to be a zeroday exploit. This vulnerability is now patched in the latest updates from the vendor. REPORT REPORT
20.2.26 Ninja Browser & Lumma Infostealer CTM360 has identified a large-scale malware campaign exploiting trusted Google services — including Google Groups, Google Docs, and Google Drive — to distribute Lumma Stealer and a trojanized Chromium-based “Ninja Browser.” REPORT REPORT
10.1.26 BlueDelta’s Persistent
Campaign Against UKR.NET
Between June 2024 and April 2025, Recorded Future’s Insikt Group identified a sustained
credential-harvesting campaign targeting users of UKR.NET, a widely used Ukrainian webmail and news
service
REPORT REPORT
10.1.26 GRU-Linked BlueDelta Evolves
Credential Harvesting
Between February and September 2025, Recorded Future’s Insikt Group identified multiple credential-harvesting campaigns conducted by BlueDelta, a Russian state-sponsored threat group associated with the Main Directorate of the General Staff of the Armed Forces of the Russian Federation (GRU). REPORT REPORT
3.1.26 OWASP Top 10 For Agentic Applications 2026 The information provided in this document does not, and is not intended to, constitute legal advice. REPORT REPORT