Generated 2026-09-19 23:18 UTC from live context. Charts are counts for this brief’s window, not model output.
CTI Daily Brief — 2026-09-19 16:16 UTC
Snapshot
In the last 24 hours, 13 victims were reported, with a total of 26 active groups and 374 groups in total. The hottest group is play, with 3 victims in the last 24 hours. In the last 7 days, 199 victims were reported, with a total of 44 groups and 967 groups in total. The ransomware KEV/CVE count is 326, with 46 critical CVEs in the last 24 hours and 406 in the last 7 days.
Trends
_Jev 6-month trend snapshot · 2026-09-19 22:10 UTC_
- Regime (6mo): volatile
- Wave type (30d): duopoly
- Daily vs trend: quieter than trend
- Leader stability (6mo): short term challenger
- Trend severity (6mo): 1.9
- Escalation needed: elevated (0.79)
- Geo US-heavy: elevated (0.90)
- KEV pressure today: moderate (0.63)
- Victims: 24h 8 · 7d 202 · 30d 939 · 180d 6,047
- MoM change: -57.5%
- Hottest: 7d `thegentlemen` · 30d `qilin` · 180d `qilin`
Hottest groups
The hottest group in the last 24 hours is play, with 3 victims. The top groups in the last 24 hours are:
- play: 3 victims
- lockbit5: 2 victims
- AuditTeam: 1 victim
- N0n: 1 victim
- Panzer: 1 victim
- emperador: 1 victim
- Vexy Ransomware: 1 victim
- anubis: 1 victim
- Spirals: 1 victim
- Gammax: 1 victim
ATT&CK notes
The following attack groups were identified in the last 7 days:
- qilin: 29 victims, techniques T1027.013, T1082, T1134, T1480.002, T1547.004, T1529, T1071.002, T1087.001, T1489, T1566.002, T1047, T1106
- akira: 10 victims, techniques T1083, T1082, T1059.001, T1047, T1059.003, T1135, T1106, T1490, T1057, T1486, T1567.002, T1213.002
- lockbit5: 5 victims, techniques T1140, T1573.001, T1548.002, T1484.001, T1059.001, T1112, T1480.002, T1027.013, T1027.002, T1680, T1543.003, T1569.002
- incransom: 5 victims, techniques T1120, T1570, T1566, T1106, T1652, T1490, T1047, T1680, T1135, T1486, T1140, T1083
- play: 3 victims, techniques T1486, T1490, T1083, T1030, T1016, T1048, T1070.004, T1059.003, T1059.001, T1560.001, T1018, T1057
KEV/CVE
The following KEV/CVEs were identified in the last 24 hours:
- CVE-2026-50751: Check Point Security Gateway Improper Authentication Vulnerability
- CVE-2026-48027: Nx Console Embedded Malicious Code Vulnerability
- CVE-2026-45321: TanStack Unspecified Vulnerability
- CVE-2026-41940: WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability
- CVE-2024-1708: ConnectWise ScreenConnect Path Traversal Vulnerability
- CVE-2024-57728: SimpleHelp Path Traversal Vulnerability
- CVE-2024-57726: SimpleHelp Missing Authorization Vulnerability
- CVE-2023-27351: PaperCut NG/MF Improper Authentication Vulnerability