ctipilot.ch

Trends

Momentum analysis over 821 operational entries. Deltas compare the latest complete ISO week against the week before it (2026-W21 → 2026-W32); the running week 2026-W33 is shown separately and never compared — a half-finished week is not a decline.

Cohort × week detail

CohortW25W26W27W28W29W30W31W32W33*
Ransomware566749740
Actively-exploited vulnerabilities97877613150
Public-sector38352245343845560
OT / ICS79515181117120
Supply-chain10131189414160
AI-abuse765103911150
Switzerland + Europe33381023231822320
Nation-state91269612630

* 2026-W33 is the running week — incomplete by definition, never compared against complete weeks.

Entity momentum

Most active entities · last 30 days

Actors, malware, campaigns and tools by entry count, vs the 30 days before. Click through for the full dossier, timeline and TTP profile.

EntityType30dPrior 30dΔLast seen
ShinyHuntersactor1033▼ -232026-08-02
Hugging Face autonomous AI agent breachincident90new2026-08-09
Joomla extension file-upload RCE wavetrend92▲ +72026-08-02
DragonForceactor93▲ +62026-07-26
EU Cyber Resilience Actpolicy88→ 02026-08-09
ByteToBreachactor70new2026-08-09
Cl0pactor70new2026-08-09
ANCPI Romania cadastre cyberattackincident60new2026-08-05
Ernst & Young third-party ITSM breachincident60new2026-08-02
LAUNDRY BEARactor60new2026-08-02
Contagious Interviewcampaign61▲ +52026-08-08
Everestactor50new2026-08-02

ATT&CK technique momentum · last 28 days

Techniques by count of entries mapping them (techniques[] frontmatter, pinned ATT&CK v19.2), vs the 28 days before. Click a technique id for its evidence in the coverage matrix.

TechniqueName28dPrior 28dΔ
T1190Exploit Public-Facing Application10645▲ +61
T1078Valid Accounts2221▲ +1
T1027Obfuscated Files or Information205▲ +15
T1068Exploitation for Privilege Escalation1810▲ +8
T1059Command and Scripting Interpreter1610▲ +6
T1105Ingress Tool Transfer144▲ +10
T1486Data Encrypted for Impact139▲ +4
T1552.001Unsecured Credentials: Credentials In Files128▲ +4
T1078.004Valid Accounts: Cloud Accounts1210▲ +2
T1199Trusted Relationship111▲ +10
T1213Data from Information Repositories111▲ +10
T1572Protocol Tunneling112▲ +9

How to read this

Cohort tiles count entries whose frontmatter carries the relevant taxonomy values, bucketed by the ISO week of discovered_at. Entity momentum counts entries linked to each registry entity; technique momentum counts entries mapping each ATT&CK id. Everything is post-hoc analytics over published entries — no separate data source.

The cohorts are coarse on purpose: they're the questions a Swiss / EU public-sector SOC manager would ask scanning the site monthly ("are we seeing more ransomware?", "is OT/ICS escalating?", "did public-sector targeting move?"). For finer slicing, use the per-tag list pages under /tags/.