 | Threat landscape for industrial automation systems. Q2 2026 | 2026-08-27 | True | Kaspersky ICS CERT | True | | |
 | Exploits and vulnerabilities in Q2 2026 | 2026-08-26 | True | Alexander Kolesnikov | True | | |
 | The invisible passenger in your car | 2026-08-21 | True | Dmitry Kalinin | True | | |
 | APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit | 2026-08-14 | True | Fareed Radzi | True | | |
 | Armored Likho expands its cyber-espionage toolkit | 2026-08-13 | True | Konstantin Isakov | True | | |
 | Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants | 2026-08-11 | True | Kaspersky | True | | |
 | Project CAV3RN continues: Google Apps Script as C2 relay and DNS-based C2 channel selection | 2026-08-11 | True | GReAT | True | | |
 | IT threat evolution in Q2 2026. Non-mobile statistics | 2026-08-10 | True | AMR | True | | |
 | IT threat evolution in Q2 2026. Mobile statistics | 2026-08-10 | True | Anton Kivva | True | | |
 | How legitimate cloud platforms enable phishers to bypass MFA | 2026-08-04 | True | Olga Altukhova | True | | |
 | An analysis of incidents at Brazilian educational institutions | 2026-08-03 | True | Cristian Souza | True | | |
 | Network Anomaly Detection in KATA | 2026-07-31 | True | Arseny Vesnovsky, Valery Akulenko, Dmitry Sabadash | True | | |
 | OctLurk and SilkLurk: newly identified tailored backdoors in cyber-espionage campaign in Central Asia | 2026-07-30 | True | Saurabh Sharma, Yaroslav Kikel | True | | |
 | Toy Ghouls’ new toy: the GenieLocker ransomware | 2026-07-30 | True | Fedor Sinitsyn, Yanis Zinchenko | True | | |
 | Mirage Kitten targets Middle East and Africa region with new malware | 2026-07-28 | True | Omar Amin, Vasily Berdnikov | True | | |
 | A new extortion cocktail: office printers, small ransoms, and BitLocker | 2026-07-21 | True | Eduardo Ovalle | True | | |
 | New Project CAV3RN module abuses Outlook calendar events for C2 and DNS AAAA records for configuration recovery | 2026-07-21 | True | GReAT | True | | |
 | HelloNet campaign — new malicious modules launched through the ViPNet update system | 2026-07-16 | True | Konstantin Isakov, Georgy Kucherin, Anton Kargin | True | | |
 | GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration | 2026-07-16 | True | Noushin Shabab | True | | |
 | OkoBot: new sophisticated malware framework targets cryptocurrency users | 2026-07-15 | True | Yaroslav Kikel | True | | |
 | Threat landscape for industrial automation systems. Q1 2026 | 2026-07-07 | True | Kaspersky ICS CERT | True | | |
 | When checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft website | 2026-07-06 | True | Roman Dedenok | True | | |
 | Armored Likho digging a snake pit: inside the covert BusySnake Stealer campaign | 2026-07-03 | True | Kaspersky | True | | |
 | Missed incidents, persistent threats, and response gaps: Insights from compromise assessment projects | 2026-07-02 | True | Victor Sergeev, Amged Wageh | True | | |
 | The SOC Files: ScreenConnect masked as freeware. An inside look at a large-scale campaign | 2026-07-01 | True | Denis Kulik | True | | |
 | OpenClaw: risks for the users and how to mitigate them | 2026-07-01 | True | Kaspersky | True | | |
 | ToddyCat: your hidden email assistant. Part 2 | 2026-06-30 | True | Andrey Gunkin | True | | |
 | The Gentlemen are knocking: сustom backdoors and evolving tactics | 2026-06-29 | True | Fatih Şensoy, Maher Yamout | True | | |
 | Beware of the license manager: how a Schneider Electric software vulnerability puts industrial facilities at risk | 2026-06-26 | True | Valery Akulenko | True | | |
 | Inside the 2026 SMB threat landscape: From phishing and scams to fake AI tools | 2026-06-25 | True | Vasily Kolesnikov, Olga Altukhova, Anna Lazaricheva, Ekaterina Beloborodova | True | | |
 | StrikeShark: investigating a new campaign delivering Cobalt Strike through SharkLoader | 2026-06-24 | True | Fareed Radzi | True | | |
 | A VBScript campaign distributed through WhatsApp deploying RMM software | 2026-06-22 | True | Fareed Radzi | True | | |
 | Dozens of malicious wallpapers found on Steam Workshop: gamers’ accounts at risk | 2026-06-16 | True | Maxim Starodubov, Denis Brylev | True | | |
 | From cause to cash: a cross-border look at hacktivist activity | 2026-06-08 | True | Kaspersky | True | | |
 | Argamal: Malware hidden in hentai games | 2026-06-03 | True | Mikhail Reznichenko | True | | |
 | Containers on fire: from container escapes to supply chain attacks | 2026-06-01 | True | Alexander Chudnov | True | | |
 | What’s in the container? Analyzing vulnerabilities, risks and protection with Kaspersky Container Security and the KIRA AI assistant | 2026-05-29 | True | Yaroslav Shmelev, Anton Kivva, Denis Parinov, Vladimir Kuskov, Yanina Balandyuk-Opalinskaya | True | | |
 | Pirates in the crosshairs: how one cybercrime gang has been infecting book, movie, and TV show fans for years | 2026-05-28 | True | Konstantin Krasilnikov, Valery Akulenko, Artem Snegirev | True | | |
 | Cloud Atlas activity in the second half of 2025 and early 2026: new tools and a new payload | 2026-05-22 | True | Kaspersky | True | | |
 | How an image could compromise your Mac: understanding an ExifTool vulnerability (CVE-2026-3102) | 2026-05-20 | True | Lucas Tay | True | | |
 | IT threat evolution in Q1 2026. Mobile statistics | 2026-05-18 | True | Anton Kivva | True | | |
 | IT threat evolution in Q1 2026. Non-mobile statistics | 2026-05-18 | True | AMR | True | | |
 | Kimsuky targets organizations with PebbleDash-based tools | 2026-05-14 | True | Sojun Ryu | True | | |
 | State of ransomware in 2026 | 2026-05-12 | True | Fabio Assolini, Marc Rivero, Maher Yamout, Darya Gorodilova | True | | |
 | CVE-2025-68670: discovering an RCE vulnerability in xrdp | 2026-05-08 | True | Denis Skvortsov, Dmitry Shmoylov | True | | |
 | Exploits and vulnerabilities in Q1 2026 | 2026-05-07 | True | Alexander Kolesnikov | True | | |
 | OceanLotus suspected of using PyPI to deliver ZiChatBot malware | 2026-05-06 | True | GReAT | True | | |
 | Websites with an undefined trust level: avoiding the trap | 2026-05-06 | True | Lama Saqqour, Anna Larkina | True | | |
 | “Legitimate” phishing: how attackers weaponize Amazon SES to bypass email security | 2026-05-04 | True | Roman Dedenok | True | | |
 | Silver Fox uses the new ABCDoor backdoor to target organizations in Russia and India | 2026-04-30 | True | Anton Kargin, Vladimir Gursky, Victoria Vlasova, Anna Lazaricheva | True | | |