Generated 2026-09-19 23:18 UTC from live context. Charts are counts for this brief’s window, not model output.
CTI Monthly Brief — 2026-09-19 17:17 UTC
Snapshot
The last 30 days have seen a significant increase in activity from various threat groups, with qilin being the hottest group. This group has been responsible for 29 victims in the last 7 days and 110 victims in the last 30 days. The sectors most affected by qilin are Other, Manufacturing, Technology, Agriculture and Food Production, and Not Found. The countries most affected are the US, AR, ES, AU, and FR.
Trends
_Jev 6-month trend snapshot · 2026-09-19 22:10 UTC_
- Regime (6mo): volatile
- Wave type (30d): duopoly
- Daily vs trend: quieter than trend
- Leader stability (6mo): short term challenger
- Trend severity (6mo): 1.9
- Escalation needed: elevated (0.79)
- Geo US-heavy: elevated (0.90)
- KEV pressure today: moderate (0.63)
- Victims: 24h 8 · 7d 202 · 30d 939 · 180d 6,047
- MoM change: -57.5%
- Hottest: 7d `thegentlemen` · 30d `qilin` · 180d `qilin`
Hottest groups
The hottest group over the last 30 days is qilin, with 29 victims in the last 7 days and 110 victims in the last 30 days. The top 5 hottest groups are:
- qilin: 29 victims in the last 7 days, 110 victims in the last 30 days
- thegentlemen: 30 victims in the last 7 days, 105 victims in the last 30 days
- krybit: 3 victims in the last 7 days, 43 victims in the last 30 days
- akira: 10 victims in the last 7 days, 41 victims in the last 30 days
- Storm: 8 victims in the last 7 days, 35 victims in the last 30 days
ATT&CK notes
The following groups have been identified as using various ATT&CK techniques:
- qilin: T1027.013, T1082, T1134, T1480.002, T1547.004, T1529, T1071.002, T1087.001, T1489, T1566.002, T1047, T1106
- akira: T1083, T1082, T1059.001, T1047, T1059.003, T1135, T1106, T1490, T1057, T1486, T1567.002, T1213.002
- lockbit5: T1140, T1573.001, T1548.002, T1484.001, T1059.001, T1112, T1480.002, T1027.013, T1027.002, T1680, T1543.003, T1569.002
- incransom: T1120, T1570, T1566, T1106, T1652, T1490, T1047, T1680, T1135, T1486, T1140, T1083
- play: T1486, T1490, T1083, T1030, T1016, T1048, T1070.004, T1059.003, T1059.001, T1560.001, T1018, T1057
- chaos: T1573.001, T1059.004, T1110, T1205, T1104
KEV/CVE
The following KEV/CVE entries have been identified:
- CVE-2026-50751: Check Point Security Gateway Improper Authentication Vulnerability
- CVE-2026-48027: Nx Console Embedded Malicious Code Vulnerability
- CVE-2026-45321: TanStack Unspecified Vulnerability
- CVE-2026-41940: WebPros cPanel & WHM and WP2 (WordPress Squared) Missing Authentication for Critical Function Vulnerability
- CVE-2024-1708: ConnectWise ScreenConnect Path Traversal Vulnerability
- CVE-2024-57728: SimpleHelp Path Traversal Vulnerability
- CVE-2024-57726: SimpleHelp Missing Authorization Vulnerability
- CVE-2023-27351: PaperCut NG/MF Improper Authentication Vulnerability