logo

Anatomy of a Cyber World Global Report 2026

ID: cdc4c2ed-d6e5-5ff7-bd65-7e61be8d51e0

STIX ID: report--cdc4c2ed-d6e5-5ff7-bd65-7e61be8d51e0

Feed Name: Securelist by Kaspersky

Threat Score
65/100

Date Published: 2026-03-25

Date Updated: 2026-04-29

Author: Kaspersky Security Services

...
...

Kaspersky’s 2025 MDR/IR/Compromise Assessment summary aggregates global telemetry and incident response data: the MDR processed ~15,000 telemetry events per host/day, generating ~400,000 alerts (39,000 investigated); most customers were in the CIS, Middle East, and Europe, with government and industrial sectors most targeted and IT rising to third. Key trends include a decline in high-severity incidents (many tied to APTs and red-team activity), widespread exploitation of Microsoft RCE CVEs (including unauthenticated cases), over 80% of attacks initiating via public-facing apps, valid accounts or trusted relationships, and frequent use of living-off-the-land binaries (powershell.exe, rundll32.exe, mshta.exe) and tools such as Mimikatz, PsExec, PowerShell, and AnyDesk; the full report maps initial vectors to MITRE ATT&CK and lists CVEs discovered during IR engagements.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.