CTIPilot

Trends

Momentum analysis over 944 operational entries. Deltas compare the latest complete ISO week against the week before it (2026-W27 → 2026-W38); the running week 2026-W39 is shown separately and never compared; a half-finished week is not a decline.

Cohort × week detail

CohortW31W32W33W34W35W36W37W38W39*
Ransomware655751213
Actively-exploited vulnerabilities1095798945
Public-sector344429344427201917
Supply-chain9147584263
AI-abuse7142487244
Switzerland + Europe17243232289784
Nation-state5437125452

* 2026-W39 is the running week: incomplete by definition, never compared against complete weeks.

Entity momentum

Most active entities · last 30 days

Actors, malware, campaigns and tools by entry count, vs the 30 days before. Click through for the full dossier, timeline and TTP profile.

EntityType30dPrior 30dΔLast seen
Microsoft Windowsproduct1111→ 02026-09-24
Google Chromeproduct53▲ +22026-09-24
Microsoft Edgeproduct41▲ +32026-09-24
PurpleDeltaactor41▲ +32026-09-19
JFrog Artifactoryproduct30new2026-09-12
Kimsukyactor30new2026-09-08
Microsoft Exchange Serverproduct30new2026-09-21
Check Point Security Management Serverproduct31▲ +22026-09-23
Hermes AI agenttool31▲ +22026-09-23
Joomla extension file-upload RCE wavetrend33→ 02026-08-28
BerriAI LiteLLMproduct20new2026-09-03
Canton Bern Gesetz über Informations- und Cybersicherheit (ICSG) and IDSV ordinancepolicy20new2026-09-23

New entities · first tracked in the last 30 days

Names that entered the knowledge base recently: the threats a reader (human or agent) is least likely to know yet.

EntityTypeFirst coveredEntries
SolarWinds Observability Self-Hostedproduct2026-09-241
ShinyHunters claimed breach of the FBI via an Oracle PeopleSoft zero-dayincident2026-09-241
ResetSpytool2026-09-241
Oracle PeopleSoftproduct2026-09-241
OpenAI agent unauthorized access to Australian government Medicare statistics portalincident2026-09-241
CLOSEDQUORUMmalware2026-09-241
CAIRN (Cisco Talos)tool2026-09-241
Strixtool2026-09-231
Softaculous Virtualizorproduct2026-09-231
Magentoproduct2026-09-231
Google Accountproduct2026-09-231
F5 BIG-IP Access Policy Manager (APM)product2026-09-231

ATT&CK technique momentum · last 28 days

Techniques by count of entries mapping them (techniques[] frontmatter, pinned ATT&CK v19.2), vs the 28 days before. Click a technique id for its evidence in the coverage matrix.

TechniqueName28dPrior 28dΔ
T1190Exploit Public-Facing Application7172▼ -1
T1068Exploitation for Privilege Escalation1513▲ +2
T1071.001Application Layer Protocol: Web Protocols149▲ +5
T1027Obfuscated Files or Information1316▼ -3
T1105Ingress Tool Transfer1212→ 0
T1552.001Unsecured Credentials: Credentials In Files1212→ 0
T1082System Information Discovery118▲ +3
T1213Data from Information Repositories119▲ +2
T1574.001Hijack Execution Flow: DLL105▲ +5
T1059Command and Scripting Interpreter106▲ +4
T1204.002User Execution: Malicious File1010→ 0
T1572Protocol Tunneling1010→ 0

How to read this

Cohort tiles count entries whose frontmatter carries the relevant taxonomy values, bucketed by the ISO week of discovered_at. Entity momentum counts entries linked to each registry entity; technique momentum counts entries mapping each ATT&CK id. Everything is post-hoc analytics over published entries; no separate data source.

The cohorts are coarse on purpose · they mirror the deployment's trend cohorts in config/branding.yaml. For finer slicing, use the per-tag list pages under /tags/.