Trends
Momentum analysis over 652 operational entries. Deltas compare the latest complete ISO week against the week before it (2026-W19 → 2026-W28); the running week 2026-W29 is shown separately and never compared — a half-finished week is not a decline.
Ransomware items / week
7
▲ +17% vs prior complete week · 3 so far this week
63 over 10 complete wk
view items →Actively-exploited vulnerabilities / week
7
▼ -12% vs prior complete week · 7 so far this week
92 over 10 complete wk
view items →Public-sector items / week
45
▲ +105% vs prior complete week · 32 so far this week
346 over 10 complete wk
OT / ICS items / week
15
▲ +200% vs prior complete week · 18 so far this week
71 over 10 complete wk
view items →Supply-chain items / week
8
▼ -27% vs prior complete week · 8 so far this week
107 over 10 complete wk
view items →AI-abuse items / week
10
▲ +100% vs prior complete week · 3 so far this week
74 over 10 complete wk
view items →Switzerland + Europe items / week
23
▲ +130% vs prior complete week · 21 so far this week
287 over 10 complete wk
view items →Nation-state items / week
9
▲ +50% vs prior complete week · 6 so far this week
101 over 10 complete wk
view items →Cohort × week detail
| Cohort | W21 | W22 | W23 | W24 | W25 | W26 | W27 | W28 | W29* |
|---|---|---|---|---|---|---|---|---|---|
| Ransomware | 11 | 3 | 4 | 7 | 5 | 6 | 6 | 7 | 3 |
| Actively-exploited vulnerabilities | 10 | 9 | 10 | 12 | 9 | 7 | 8 | 7 | 7 |
| Public-sector | 46 | 35 | 41 | 46 | 38 | 35 | 22 | 45 | 32 |
| OT / ICS | 3 | 10 | 4 | 7 | 7 | 9 | 5 | 15 | 18 |
| Supply-chain | 17 | 8 | 10 | 11 | 10 | 13 | 11 | 8 | 8 |
| AI-abuse | 6 | 11 | 5 | 11 | 7 | 6 | 5 | 10 | 3 |
| Switzerland + Europe | 34 | 41 | 25 | 32 | 33 | 38 | 10 | 23 | 21 |
| Nation-state | 12 | 13 | 13 | 12 | 9 | 12 | 6 | 9 | 6 |
* 2026-W29 is the running week — incomplete by definition, never compared against complete weeks.
Entity momentum
Most active entities · last 30 days
Actors, malware, campaigns and tools by entry count, vs the 30 days before. Click through for the full dossier, timeline and TTP profile.
| Entity | Type | 30d | Prior 30d | Δ | Last seen |
|---|---|---|---|---|---|
| ShinyHunters | actor | 29 | 19 | ▲ +10 | 2026-07-18 |
| FortiBleed | incident | 12 | 0 | new | 2026-07-12 |
| The Gentlemen | actor | 11 | 5 | ▲ +6 | 2026-07-18 |
| DragonForce | actor | 7 | 1 | ▲ +6 | 2026-07-14 |
| Operation Endgame — Amadey/StealC takedown | campaign | 6 | 0 | new | 2026-06-29 |
| Secret Blizzard | actor | 6 | 0 | new | 2026-07-13 |
| Scattered Spider | actor | 6 | 1 | ▲ +5 | 2026-07-17 |
| Akira | actor | 6 | 7 | ▼ -1 | 2026-07-12 |
| EU Cyber Resilience Act | policy | 6 | 7 | ▼ -1 | 2026-07-12 |
| Miasma | campaign | 6 | 8 | ▼ -2 | 2026-07-16 |
| Qilin | actor | 5 | 8 | ▼ -3 | 2026-07-12 |
| Joomla extension file-upload RCE wave | trend | 4 | 0 | new | 2026-07-12 |
New entities · first tracked in the last 30 days
Names that entered the knowledge base recently — the threats a reader (human or agent) is least likely to know yet.
| Entity | Type | First covered | Entries |
|---|---|---|---|
| UTA0533 | actor | 2026-07-18 | 1 |
| TetrisPhantom | actor | 2026-07-18 | 1 |
| OTTERCOOKIE | tool | 2026-07-18 | 1 |
| KNUCKLEBALL / ORANGETAIL SonicWall SMA toolset | tool | 2026-07-18 | 1 |
| GoSerpent | malware | 2026-07-18 | 1 |
| WLDR | tool | 2026-07-17 | 1 |
| Wind Tre vishing + API-enumeration breach (2025) | incident | 2026-07-17 | 1 |
| UAT-11795 | actor | 2026-07-17 | 1 |
| Starland RAT | tool | 2026-07-17 | 1 |
| HelloNet toolkit | tool | 2026-07-17 | 1 |
| HelloNet | campaign | 2026-07-17 | 1 |
| CastleStealer | tool | 2026-07-17 | 1 |
ATT&CK technique momentum · last 28 days
Techniques by count of entries mapping them (techniques[] frontmatter, pinned ATT&CK v19.1), vs the 28 days before. Click a technique id for its evidence in the coverage matrix.
| Technique | Name | 28d | Prior 28d | Δ |
|---|---|---|---|---|
| T1190 | Exploit Public-Facing Application | 60 | 32 | ▲ +28 |
| T1078 | Valid Accounts | 18 | 18 | → 0 |
| T1505.003 | Server Software Component: Web Shell | 15 | 6 | ▲ +9 |
| T1068 | Exploitation for Privilege Escalation | 14 | 7 | ▲ +7 |
| T1027 | Obfuscated Files or Information | 11 | 2 | ▲ +9 |
| T1078.004 | Valid Accounts: Cloud Accounts | 11 | 10 | ▲ +1 |
| T1059 | Command and Scripting Interpreter | 11 | 17 | ▼ -6 |
| T1486 | Data Encrypted for Impact | 10 | 3 | ▲ +7 |
| T1105 | Ingress Tool Transfer | 9 | 1 | ▲ +8 |
| T1059.006 | Command and Scripting Interpreter: Python | 9 | 2 | ▲ +7 |
| T1552.001 | Unsecured Credentials: Credentials In Files | 9 | 5 | ▲ +4 |
| T1528 | Steal Application Access Token | 8 | 3 | ▲ +5 |
How to read this
Cohort tiles count entries whose frontmatter carries the relevant taxonomy values, bucketed by the ISO week of discovered_at. Entity momentum counts entries linked to each registry entity; technique momentum counts entries mapping each ATT&CK id. Everything is post-hoc analytics over published entries — no separate data source.
The cohorts are coarse on purpose: they're the questions a Swiss / EU public-sector SOC manager would ask scanning the site monthly ("are we seeing more ransomware?", "is OT/ICS escalating?", "did public-sector targeting move?"). For finer slicing, use the per-tag list pages under /tags/.