news.mlab.sh
Back to the feed
threat-intel

IT threat evolution in Q2 2026. Non-mobile statistics

High
Image: Securelist
Summary

In Q2 2026, Kaspersky products blocked a massive 399.3 million attacks originating from online resources, highlighting a continued surge in ransomware activity and botnet attacks. The Qilin ransomware group dominated, accounting for 14.57% of all ransomware victims on data leak sites, alongside Akira and DragonForce. Microsoft successfully dismantled a malware-signing-as-a-service (MSaaS) operation run by Fox Tempest, while Check Point faced zero-day exploitation of CVE-2026-50751 by Qilin and CVE-2026-50752. Significant trends included a rise in miner variants (almost doubling compared to last quarter), increased attacks targeting macOS via vulnerabilities like FlutterShell and Coruna exploit kit, and a continued dominance of Mirai and Prometei botnets in IoT attacks. The Netherlands, Germany, and the United States led in SSH-based attacks, while Pakistan saw a notable increase in Telnet-based attacks.

Read the full article at Securelist

Summary written automatically in our own words from the original article, which belongs to its publisher and remains the reference. It may contain errors. Sources & data

Report an error
Confirmed errors are fixed and listed on /corrections.