Trends
Momentum analysis over 821 operational entries. Deltas compare the latest complete ISO week against the week before it (2026-W21 → 2026-W32); the running week 2026-W33 is shown separately and never compared — a half-finished week is not a decline.
Ransomware items / week
4
▼ -43% vs prior complete week · 0 so far this week
73 over 12 complete wk
view items →Actively-exploited vulnerabilities / week
15
▲ +15% vs prior complete week · 0 so far this week
113 over 12 complete wk
view items →Public-sector items / week
56
▲ +24% vs prior complete week · 0 so far this week
481 over 12 complete wk
OT / ICS items / week
12
▼ -29% vs prior complete week · 0 so far this week
118 over 12 complete wk
view items →Supply-chain items / week
16
▲ +14% vs prior complete week · 0 so far this week
131 over 12 complete wk
view items →AI-abuse items / week
15
▲ +36% vs prior complete week · 0 so far this week
99 over 12 complete wk
view items →Switzerland + Europe items / week
32
▲ +45% vs prior complete week · 0 so far this week
331 over 12 complete wk
view items →Nation-state items / week
3
▼ -50% vs prior complete week · 0 so far this week
113 over 12 complete wk
view items →Cohort × week detail
| Cohort | W25 | W26 | W27 | W28 | W29 | W30 | W31 | W32 | W33* |
|---|---|---|---|---|---|---|---|---|---|
| Ransomware | 5 | 6 | 6 | 7 | 4 | 9 | 7 | 4 | 0 |
| Actively-exploited vulnerabilities | 9 | 7 | 8 | 7 | 7 | 6 | 13 | 15 | 0 |
| Public-sector | 38 | 35 | 22 | 45 | 34 | 38 | 45 | 56 | 0 |
| OT / ICS | 7 | 9 | 5 | 15 | 18 | 11 | 17 | 12 | 0 |
| Supply-chain | 10 | 13 | 11 | 8 | 9 | 4 | 14 | 16 | 0 |
| AI-abuse | 7 | 6 | 5 | 10 | 3 | 9 | 11 | 15 | 0 |
| Switzerland + Europe | 33 | 38 | 10 | 23 | 23 | 18 | 22 | 32 | 0 |
| Nation-state | 9 | 12 | 6 | 9 | 6 | 12 | 6 | 3 | 0 |
* 2026-W33 is the running week — incomplete by definition, never compared against complete weeks.
Entity momentum
Most active entities · last 30 days
Actors, malware, campaigns and tools by entry count, vs the 30 days before. Click through for the full dossier, timeline and TTP profile.
| Entity | Type | 30d | Prior 30d | Δ | Last seen |
|---|---|---|---|---|---|
| ShinyHunters | actor | 10 | 33 | ▼ -23 | 2026-08-02 |
| Hugging Face autonomous AI agent breach | incident | 9 | 0 | new | 2026-08-09 |
| Joomla extension file-upload RCE wave | trend | 9 | 2 | ▲ +7 | 2026-08-02 |
| DragonForce | actor | 9 | 3 | ▲ +6 | 2026-07-26 |
| EU Cyber Resilience Act | policy | 8 | 8 | → 0 | 2026-08-09 |
| ByteToBreach | actor | 7 | 0 | new | 2026-08-09 |
| Cl0p | actor | 7 | 0 | new | 2026-08-09 |
| ANCPI Romania cadastre cyberattack | incident | 6 | 0 | new | 2026-08-05 |
| Ernst & Young third-party ITSM breach | incident | 6 | 0 | new | 2026-08-02 |
| LAUNDRY BEAR | actor | 6 | 0 | new | 2026-08-02 |
| Contagious Interview | campaign | 6 | 1 | ▲ +5 | 2026-08-08 |
| Everest | actor | 5 | 0 | new | 2026-08-02 |
New entities · first tracked in the last 30 days
Names that entered the knowledge base recently — the threats a reader (human or agent) is least likely to know yet.
| Entity | Type | First covered | Entries |
|---|---|---|---|
| Swiss ISV Article 51 federal-administration ISMS transition deadline | policy | 2026-08-09 | 1 |
| NCSC UK forensic observability for network devices | policy | 2026-08-09 | 1 |
| Metabase unauthenticated SQL-injection zero-day exploitation (August 2026) | incident | 2026-08-09 | 2 |
| Germany NIS2 registration deadline and enforcement gap | policy | 2026-08-09 | 1 |
| EU AI Act Digital Omnibus (Regulation (EU) 2026/1744) | policy | 2026-08-09 | 2 |
| CI Fortify — Advice for isolating vital systems | policy | 2026-08-09 | 1 |
| 2026 Minimum Elements for a Software Bill of Materials | policy | 2026-08-09 | 1 |
| ScreenConnect app-store-themed fake-update distribution campaign | campaign | 2026-08-08 | 1 |
| JINX-0163 | actor | 2026-08-08 | 1 |
| Digitaal Vlaanderen compromise disclosed in the Stykas North Korea victim-set research | incident | 2026-08-08 | 2 |
| Beacon CRM access-key breach affecting around 1,500 UK charities | incident | 2026-08-08 | 1 |
| Meta AI cybersecurity-evaluation containment breach (August 2026) | incident | 2026-08-07 | 2 |
ATT&CK technique momentum · last 28 days
Techniques by count of entries mapping them (techniques[] frontmatter, pinned ATT&CK v19.2), vs the 28 days before. Click a technique id for its evidence in the coverage matrix.
| Technique | Name | 28d | Prior 28d | Δ |
|---|---|---|---|---|
| T1190 | Exploit Public-Facing Application | 106 | 45 | ▲ +61 |
| T1078 | Valid Accounts | 22 | 21 | ▲ +1 |
| T1027 | Obfuscated Files or Information | 20 | 5 | ▲ +15 |
| T1068 | Exploitation for Privilege Escalation | 18 | 10 | ▲ +8 |
| T1059 | Command and Scripting Interpreter | 16 | 10 | ▲ +6 |
| T1105 | Ingress Tool Transfer | 14 | 4 | ▲ +10 |
| T1486 | Data Encrypted for Impact | 13 | 9 | ▲ +4 |
| T1552.001 | Unsecured Credentials: Credentials In Files | 12 | 8 | ▲ +4 |
| T1078.004 | Valid Accounts: Cloud Accounts | 12 | 10 | ▲ +2 |
| T1199 | Trusted Relationship | 11 | 1 | ▲ +10 |
| T1213 | Data from Information Repositories | 11 | 1 | ▲ +10 |
| T1572 | Protocol Tunneling | 11 | 2 | ▲ +9 |
How to read this
Cohort tiles count entries whose frontmatter carries the relevant taxonomy values, bucketed by the ISO week of discovered_at. Entity momentum counts entries linked to each registry entity; technique momentum counts entries mapping each ATT&CK id. Everything is post-hoc analytics over published entries — no separate data source.
The cohorts are coarse on purpose: they're the questions a Swiss / EU public-sector SOC manager would ask scanning the site monthly ("are we seeing more ransomware?", "is OT/ICS escalating?", "did public-sector targeting move?"). For finer slicing, use the per-tag list pages under /tags/.