ctipilot.ch

Trends

Momentum analysis over 652 operational entries. Deltas compare the latest complete ISO week against the week before it (2026-W19 → 2026-W28); the running week 2026-W29 is shown separately and never compared — a half-finished week is not a decline.

Cohort × week detail

CohortW21W22W23W24W25W26W27W28W29*
Ransomware1134756673
Actively-exploited vulnerabilities109101297877
Public-sector463541463835224532
OT / ICS310477951518
Supply-chain178101110131188
AI-abuse611511765103
Switzerland + Europe344125323338102321
Nation-state12131312912696

* 2026-W29 is the running week — incomplete by definition, never compared against complete weeks.

Entity momentum

Most active entities · last 30 days

Actors, malware, campaigns and tools by entry count, vs the 30 days before. Click through for the full dossier, timeline and TTP profile.

EntityType30dPrior 30dΔLast seen
ShinyHuntersactor2919▲ +102026-07-18
FortiBleedincident120new2026-07-12
The Gentlemenactor115▲ +62026-07-18
DragonForceactor71▲ +62026-07-14
Operation Endgame — Amadey/StealC takedowncampaign60new2026-06-29
Secret Blizzardactor60new2026-07-13
Scattered Spideractor61▲ +52026-07-17
Akiraactor67▼ -12026-07-12
EU Cyber Resilience Actpolicy67▼ -12026-07-12
Miasmacampaign68▼ -22026-07-16
Qilinactor58▼ -32026-07-12
Joomla extension file-upload RCE wavetrend40new2026-07-12

New entities · first tracked in the last 30 days

Names that entered the knowledge base recently — the threats a reader (human or agent) is least likely to know yet.

EntityTypeFirst coveredEntries
UTA0533actor2026-07-181
TetrisPhantomactor2026-07-181
OTTERCOOKIEtool2026-07-181
KNUCKLEBALL / ORANGETAIL SonicWall SMA toolsettool2026-07-181
GoSerpentmalware2026-07-181
WLDRtool2026-07-171
Wind Tre vishing + API-enumeration breach (2025)incident2026-07-171
UAT-11795actor2026-07-171
Starland RATtool2026-07-171
HelloNet toolkittool2026-07-171
HelloNetcampaign2026-07-171
CastleStealertool2026-07-171

ATT&CK technique momentum · last 28 days

Techniques by count of entries mapping them (techniques[] frontmatter, pinned ATT&CK v19.1), vs the 28 days before. Click a technique id for its evidence in the coverage matrix.

TechniqueName28dPrior 28dΔ
T1190Exploit Public-Facing Application6032▲ +28
T1078Valid Accounts1818→ 0
T1505.003Server Software Component: Web Shell156▲ +9
T1068Exploitation for Privilege Escalation147▲ +7
T1027Obfuscated Files or Information112▲ +9
T1078.004Valid Accounts: Cloud Accounts1110▲ +1
T1059Command and Scripting Interpreter1117▼ -6
T1486Data Encrypted for Impact103▲ +7
T1105Ingress Tool Transfer91▲ +8
T1059.006Command and Scripting Interpreter: Python92▲ +7
T1552.001Unsecured Credentials: Credentials In Files95▲ +4
T1528Steal Application Access Token83▲ +5

How to read this

Cohort tiles count entries whose frontmatter carries the relevant taxonomy values, bucketed by the ISO week of discovered_at. Entity momentum counts entries linked to each registry entity; technique momentum counts entries mapping each ATT&CK id. Everything is post-hoc analytics over published entries — no separate data source.

The cohorts are coarse on purpose: they're the questions a Swiss / EU public-sector SOC manager would ask scanning the site monthly ("are we seeing more ransomware?", "is OT/ICS escalating?", "did public-sector targeting move?"). For finer slicing, use the per-tag list pages under /tags/.