Monthly report · August 2026
Cyber threat situation
What the 18-month archive shows across 10,818 curated items: which attacks recur, who is most active, and what to fix first.
- ransomware
- 1,053
- data breach
- 671
- RCE
- 510
- SQL injection
- 292
The trend
18 moBy category
- ransomware875
- other686
- research368
- vuln252
- policy242
- breach230
- malware188
- exploit164
The number of security incidents initially decreased, but started to rise rapidly from 2025-09 onwards, reaching record levels (3839 and 6639) in 2026-07 and 2026-08. The most common attack types were ransomware, data breach, and RCE. 'thegentlemen' and 'qilin' were the most active threat actors. The most exploited CVEs were vulnerabilities discovered in 2026.
The landscape
80 KEVThe threat landscape includes 10818 items. The most active crime actors are 'thegentlemen' (313 victims) and 'qilin' (294 victims) ransomware groups. The most prevalent attack types were ransomware (1053), data breach (671), and RCE (510). The most targeted sectors were government (58), healthcare (46), and cybersecurity (44). The KEV catalog contains 80 CVEs.
Most active actors — by observed victims
- 313vic
- 294vic
- 93vic
- 90vic
- 76vic
- 62vic
- 62vic
- 62vic
- 49vic
- 46vic
- 40vic
- 38vic
Most-targeted sectors
- government58
- healthcare46
- cybersecurity44
- critical infrastructure21
- water21
- energy19
- cryptocurrency17
- defense17
- banking16
- education15
Recurring CVEs
- CVE-2026-33017KEV×4
- CVE-2026-50522KEVCWE-502×3
- CVE-2026-58644KEVCWE-502×3
- CVE-2026-56164KEVCWE-306×3
- CVE-2026-55040KEVCWE-287×3
- CVE-2026-56155KEVCWE-269×3
- CVE-2026-34486KEV×3
- CVE-2026-10520KEVCWE-78×2
Defender priorities
8The most-seen attack types in the archive, ranked, each with concrete steps drawn only from canonical mitigation records — nothing invented.
- 01
RCE
510 incidents- Upgrade Gitea to version 1.27.1 or later
- Upgrade OpenWrt to version 24.10.8
- Update vBulletin to the latest version
- Apply security updates for Adobe Campaign Classic
- Apply the security update provided by JetBrains
- Upgrade Ruby on Rails Active Storage to versions 7.2.3.2, 8.0.5.1, or 8.1.3.1
- Apply security updates released by Broadcom for VMware vCenter, ESX, Workstation, and Fusion
- Update Zoom now
- Update WordPress to a patched version
- Patch Langflow immediately
- Update Elementor Pro plugin to the latest version
- 02
SQL injection
292 incidents- Upgrade the Project Management, Bug and Issue Tracking Plugin to version 5.1.0 or later
- 03
supply-chain
113 incidents- Enable mandatory two-factor authentication for critical projects on PyPI
- Enable Dependabot updates
- Apply a 30-day quarantine period for new packages
- Apply a 48-hour waiting period before adding new maintainers
- Apply a 24-hour waiting period for API key creation
- 04
remote code execution
108 incidents- Apply Microsoft's August Patch Tuesday updates immediately.
- Upgrade OpenWrt to version 24.10.8
- 05
authentication bypass
98 incidents- Update NetScaler ADC and NetScaler Gateway to the latest version provided by Citrix
- 06
XSS
95 incidents- Update WordPress to a patched version
- 07
zero-day
87 incidents- Apply the security updates released by Microsoft
- Apply the patch for the exploited Windows zero-day vulnerability
- 08
DDoS
73 incidents- Plan migration by January 1, 2027, after adding the Anti-DDoS managed rule group in Count mode to eligible web ACLs before AWS Shield Advanced L7 automatic mitigation retires
Every figure is drawn straight from the skopnix archive — 10,818 curated items over 18 months. Defensive steps are selected from 35 canonical mitigation records; nothing is invented. Updated 23 Aug 2026. Part of skopnix — global cyber-threat intelligence.