Trends
Momentum analysis over 944 operational entries. Deltas compare the latest complete ISO week against the week before it (2026-W27 → 2026-W38); the running week 2026-W39 is shown separately and never compared; a half-finished week is not a decline.
Ransomware items / week
1
▼ -50% vs prior complete week · 3 so far this week
54 over 12 complete wk
view items →Actively-exploited vulnerabilities / week
4
▼ -56% vs prior complete week · 5 so far this week
84 over 12 complete wk
view items →Public-sector items / week
19
▼ -5% vs prior complete week · 17 so far this week
366 over 12 complete wk
Supply-chain items / week
6
▲ +200% vs prior complete week · 3 so far this week
85 over 12 complete wk
view items →AI-abuse items / week
4
▲ +100% vs prior complete week · 4 so far this week
74 over 12 complete wk
view items →Switzerland + Europe items / week
8
▲ +14% vs prior complete week · 4 so far this week
224 over 12 complete wk
view items →Nation-state items / week
5
▲ +25% vs prior complete week · 2 so far this week
73 over 12 complete wk
view items →Cohort × week detail
| Cohort | W31 | W32 | W33 | W34 | W35 | W36 | W37 | W38 | W39* |
|---|---|---|---|---|---|---|---|---|---|
| Ransomware | 6 | 5 | 5 | 7 | 5 | 1 | 2 | 1 | 3 |
| Actively-exploited vulnerabilities | 10 | 9 | 5 | 7 | 9 | 8 | 9 | 4 | 5 |
| Public-sector | 34 | 44 | 29 | 34 | 44 | 27 | 20 | 19 | 17 |
| Supply-chain | 9 | 14 | 7 | 5 | 8 | 4 | 2 | 6 | 3 |
| AI-abuse | 7 | 14 | 2 | 4 | 8 | 7 | 2 | 4 | 4 |
| Switzerland + Europe | 17 | 24 | 32 | 32 | 28 | 9 | 7 | 8 | 4 |
| Nation-state | 5 | 4 | 3 | 7 | 12 | 5 | 4 | 5 | 2 |
* 2026-W39 is the running week: incomplete by definition, never compared against complete weeks.
Entity momentum
Most active entities · last 30 days
Actors, malware, campaigns and tools by entry count, vs the 30 days before. Click through for the full dossier, timeline and TTP profile.
| Entity | Type | 30d | Prior 30d | Δ | Last seen |
|---|---|---|---|---|---|
| Microsoft Windows | product | 11 | 11 | → 0 | 2026-09-24 |
| Google Chrome | product | 5 | 3 | ▲ +2 | 2026-09-24 |
| Microsoft Edge | product | 4 | 1 | ▲ +3 | 2026-09-24 |
| PurpleDelta | actor | 4 | 1 | ▲ +3 | 2026-09-19 |
| JFrog Artifactory | product | 3 | 0 | new | 2026-09-12 |
| Kimsuky | actor | 3 | 0 | new | 2026-09-08 |
| Microsoft Exchange Server | product | 3 | 0 | new | 2026-09-21 |
| Check Point Security Management Server | product | 3 | 1 | ▲ +2 | 2026-09-23 |
| Hermes AI agent | tool | 3 | 1 | ▲ +2 | 2026-09-23 |
| Joomla extension file-upload RCE wave | trend | 3 | 3 | → 0 | 2026-08-28 |
| BerriAI LiteLLM | product | 2 | 0 | new | 2026-09-03 |
| Canton Bern Gesetz über Informations- und Cybersicherheit (ICSG) and IDSV ordinance | policy | 2 | 0 | new | 2026-09-23 |
New entities · first tracked in the last 30 days
Names that entered the knowledge base recently: the threats a reader (human or agent) is least likely to know yet.
| Entity | Type | First covered | Entries |
|---|---|---|---|
| SolarWinds Observability Self-Hosted | product | 2026-09-24 | 1 |
| ShinyHunters claimed breach of the FBI via an Oracle PeopleSoft zero-day | incident | 2026-09-24 | 1 |
| ResetSpy | tool | 2026-09-24 | 1 |
| Oracle PeopleSoft | product | 2026-09-24 | 1 |
| OpenAI agent unauthorized access to Australian government Medicare statistics portal | incident | 2026-09-24 | 1 |
| CLOSEDQUORUM | malware | 2026-09-24 | 1 |
| CAIRN (Cisco Talos) | tool | 2026-09-24 | 1 |
| Strix | tool | 2026-09-23 | 1 |
| Softaculous Virtualizor | product | 2026-09-23 | 1 |
| Magento | product | 2026-09-23 | 1 |
| Google Account | product | 2026-09-23 | 1 |
| F5 BIG-IP Access Policy Manager (APM) | product | 2026-09-23 | 1 |
ATT&CK technique momentum · last 28 days
Techniques by count of entries mapping them (techniques[] frontmatter, pinned ATT&CK v19.2), vs the 28 days before. Click a technique id for its evidence in the coverage matrix.
| Technique | Name | 28d | Prior 28d | Δ |
|---|---|---|---|---|
| T1190 | Exploit Public-Facing Application | 71 | 72 | ▼ -1 |
| T1068 | Exploitation for Privilege Escalation | 15 | 13 | ▲ +2 |
| T1071.001 | Application Layer Protocol: Web Protocols | 14 | 9 | ▲ +5 |
| T1027 | Obfuscated Files or Information | 13 | 16 | ▼ -3 |
| T1105 | Ingress Tool Transfer | 12 | 12 | → 0 |
| T1552.001 | Unsecured Credentials: Credentials In Files | 12 | 12 | → 0 |
| T1082 | System Information Discovery | 11 | 8 | ▲ +3 |
| T1213 | Data from Information Repositories | 11 | 9 | ▲ +2 |
| T1574.001 | Hijack Execution Flow: DLL | 10 | 5 | ▲ +5 |
| T1059 | Command and Scripting Interpreter | 10 | 6 | ▲ +4 |
| T1204.002 | User Execution: Malicious File | 10 | 10 | → 0 |
| T1572 | Protocol Tunneling | 10 | 10 | → 0 |
How to read this
Cohort tiles count entries whose frontmatter carries the relevant taxonomy values, bucketed by the ISO week of discovered_at. Entity momentum counts entries linked to each registry entity; technique momentum counts entries mapping each ATT&CK id. Everything is post-hoc analytics over published entries; no separate data source.
The cohorts are coarse on purpose · they mirror the deployment's trend cohorts in config/branding.yaml. For finer slicing, use the per-tag list pages under /tags/.