Comparitech counted 2,627 ransomware attacks claimed in Q3 2026, a quarterly record up 27% on Q2 and 61% on a year earlier. Victims have confirmed 247 of those claims, so the record is mostly a count of what the gangs themselves assert.
Reality
- Evidence42
- Adoption
- Insufficient
- Hype gap+30
- Incentives
- Insufficient
- Confidence40
A single actor used a free Chinese pentest agent and four commercial AI models to breach South Korean financial firms in about two weeks. The free, resold toolkit let one person breach several firms at once, and researchers expect adversaries to keep using it to lift their tempo.
Reality
- Evidence45
- Adoption15
- Hype gap+15
- Incentives
- Insufficient
- Confidence40
A public proof-of-concept for CVE-2026-88771 pushed a stealthy NetScaler zero-day into mass exploitation, with fewer than 10% of exposed hosts patched. Citrix admits its detection script may miss intrusions, so exposed appliances should be treated as breached.
Reality
- Evidence60
- Adoption70
- Hype gap+8
- Incentives35
- Confidence62
Microsoft's 2026 Digital Defense Report says intrusions spanning identity, cloud and supply chains become clearer when defenders join separate signals. Its attacker findings are incremental, with AI so far confined to parts of familiar attack workflows.
Perspective Coverage
7 publishers
- Builder
- Builder 30%
- Operator
- Operator 56%
- Investor
- Investor 14%
Reality
- Evidence70
- Adoption58
- Hype gap+12
- Incentives72
- Confidence70
Huntress found legitimate remote management software abused in 45% of the endpoint incidents it logged in the first quarter of 2026. A rogue copy can behave like IT's approved one, so defenders have to know which tools are sanctioned and how each install arrived.
Reality
- Evidence45
- Adoption55
- Hype gap+5
- Incentives
- Insufficient
- Confidence55
Attacker server logs show the Coruna iOS WebKit kit compromising a live iPhone's browser in six seconds, two months after Google published its teardown. It fired with no tap from the user, on a phone still running iOS 15.8.3.
Publishers:c2huntersresearch.com
Reality
- Evidence62
- Adoption12
- Hype gap+15
- Incentives
- Insufficient
- Confidence58
NCC Group counted 1,073 ransomware attacks in August, a second straight 2026 high and 12% above July. Industrial companies took 31% of them, up from 28% in July, so the hardest-hit sector drew a larger slice of a larger total.
Publishers:infosecurity-magazine.com · nccgroup.com Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+25
- Incentives60
- Confidence55
Disclosures doubled year over year while actually-exploited vulnerabilities rose 8%. The arithmetic retires patch-everything SLAs and leaves exploitability triage as the defensible option.
Perspective Coverage
3 publishers
- Builder
- Builder 12%
- Operator
- Operator 76%
- Investor
- Investor 12%
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+30
- Incentives70
- Confidence60
Researcher Dancho Danchev matched 205 handles from a 2005-2008 Exploit.in dump to private messages on five later forums, 26 of them from active early members. A matching handle does not prove a matching person, so 205 is a ceiling, but the forum's core was only about 90 accounts, few enough to follow from board to board.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence40
Palo Alto's threat unit says about 97% of AI-linked malware never leaves sandboxes and VirusTotal, and that what does arrive is caught by detection layers customers already run.
Reality
- Evidence55
- Adoption15
- Hype gap+20
- Incentives75
- Confidence55
Hunt.io only found the intrusion because the operator left his staging directory browsable on port 8000 in Amsterdam. The scripts inside needed no passwords, just valid usernames and an ownCloud install nobody had updated.
Perspective Coverage
3 publishers
- Builder
- Builder 33%
- Operator
- Operator 57%
- Investor
- Investor 10%
Reality
- Evidence64
- Adoption
- Insufficient
- Hype gap+8
- Incentives38
- Confidence60
Anthropic's threat intelligence team published case counts for biological misuse and state-linked surveillance of Claude, and did not say how long most of the logged activity ran before the company found it.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+20
- Incentives55
- Confidence60
buildOne report1 publisher Kiteworks has told customers to shut down servers over a possible attack, and Heise reports a six-hour worldwide window starting Saturday. Its 9.5.1 update fixes only known flaws, so self-hosted operators are weighing downtime against a threat the company has not described.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+10
- Incentives55
- Confidence55
Conifers assessed 14,652 customer detections and found 47% at the average organization need attention while still showing as deployed. Against the ATT&CK techniques relevant to each customer, average protection stood at 64%, leaving one in three without a reliable detection.
Reality
- Evidence38
- Adoption
- Insufficient
- Hype gap+30
- Incentives68
- Confidence40
Austin Larsen of Google's threat intelligence group says a Mandiant persona sat in TeamPCP's inner circle from almost the start of the campaign. For the companies the group breached, that infiltration was the warning system.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+20
- Incentives60
- Confidence55
Microsoft says affiliate Storm-2570 has run the same remote access and exfiltration tools whether it deploys Qilin, DragonForce, Anubis or BERT ransomware. Detections built on those tools can catch the operator before any payload runs.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap+10
- Incentives30
- Confidence55
Cisco Talos has published CLOSEDQUORUM, a Windows credential stealer with no command-and-control server. It hands the state of the infected host to Gemini, DeepSeek, Qwen and Mistral, then acts on the majority verdict.
Reality
- Evidence52
- Adoption15
- Hype gap+18
- Incentives68
- Confidence55
buildOne report1 publisher The company says the architecture around a bug matters more than how fast the patch ships, and it is making that case on a stack built from its own products after watching an AI assistant fix bugs and break their dependencies.
Reality
- Evidence34
- Adoption25
- Hype gap+18
- Incentives82
- Confidence55
Cisco Talos has open-sourced CAIRN, a framework that tags malware by the traces its AI calls leave in metadata. The first sample it surfaced polls DeepSeek, Qwen, Mistral and Gemini for orders and decides for itself.
Reality
- Evidence55
- Adoption18
- Hype gap+26
- Incentives62
- Confidence58
TeamPCP hijacked developer accounts, poisoned hundreds of programs and released a worm to automate the spread. Google says the inside access let it warn victims, revoke stolen credentials and help patch an AI-developed zero-day.
Reality
- Evidence32
- Adoption38
- Hype gap+22
- Incentives68
- Confidence30
Earlier coverage
- Talos puts 78% of Japan's ransomware victims under JPY 1 billion in capital
Security · September 17, 2026 · One report1 publisher
- N0va captures refresh tokens from sign-ins the identity provider itself approved
Security · September 16, 2026 · One report1 publisher
- Dataminr's detection feed now maps alerts to each Horizon client's offices and travelers
Product · September 14, 2026 · One report1 publisher
- An eval agent cheated its way from a locked test sandbox to Hugging Face cluster admin
Security · September 11, 2026 · One report1 publisher
- Takedowns pushed fraud buyers into smaller specialised shops, Rapid7 says
Security · September 11, 2026 · One report1 publisher
- Rubrik wires ReversingLabs' ransomware feed into the scans that pick a clean recovery point
Security · September 10, 2026 · One report1 publisher
- Anthropic refers suspects to police before a crime, according to the American Prospect
Security · September 10, 2026 · One report1 publisher
- Talos splits security burnout into four injuries with four different fixes
Security · September 10, 2026 · One report1 publisher
- A six-hour agent run harvested credentials from behind the victim's own cloud IPs
Build · September 10, 2026 · One report1 publisher
- Google clocks TeamPCP standing up a mass credential-harvesting campaign in under six hours
Security · September 9, 2026 · One report1 publisher
- Google traces a six-hour credential harvest to a coding chatbot running markdown playbooks
Product · September 8, 2026 · One report1 publisher