Skip to navigation Skip to main content Skip to footer

Cyber Threat
Intelligence Reports

Exclusive insights into the latest Threat Intelligence. Keeping constant watch over the cyber and geopolitical landscapes so you don’t have to.

 

Monthly Threat Intelligence Report

Ransomware activity reached a year-to-date high in July 2026, while advances in AI-enabled attack capabilities, evolving cyber espionage infrastructure, and geopolitical developments continued to shape the threat landscape.

July 2026 key insights:

  • 894 ransomware attacks were recorded globally in July, representing a 22% increase compared to June and the highest monthly total recorded in 2026 to date.
  • Industrials remained the most targeted sector, accounting for 250 attacks (28%), followed by Consumer Discretionary with 165 (18%) and Information Technology with 103 (12%) attacks.
  • North America remained the most targeted region, accounting for 365 attacks (41%), followed by Europe with 263 attacks (29%).
  • The Gentlemen was the most active ransomware group in July, responsible for 138 attacks (15%), closely followed by Qilin with 127 attacks (14%).
  • Security researchers documented JADEPUFFER, an autonomous AI-driven ransomware operator capable of independently progressing through multiple stages of the attack lifecycle with minimal human intervention.

Ransomware activity surged in July, while wider developments across the cyber threat landscape provided further insight into the evolving nature of cyber risk. The emergence of increasingly autonomous AI-enabled attacks and the growing use of shared relay infrastructure by state-aligned actors reflected a broader shift towards more scalable, resilient, and difficult-to-attribute activity. Together, these trends demonstrate how cyber operations are becoming more efficient, adaptive, and harder to detect, reinforcing the importance of proactive security strategies and resilient defences.

Mini Shai-Hulud and Open-Source Supply Chain Attacks

NCC Group is monitoring the ongoing and rapidly evolving wave of Shai-Hulud supply chain attacks.

This report covers the most recent wave of Shai-Hulud activity (Mini Shai-Hulud, Miasma and Hades), observed throughout May and early June 2026. As well as supporting triage of active infections, it provides guidance for defenders building security postures that address the structural risks of open-source package reliance, rather than simply ingesting wave-specific IOCs in response to each new campaign.


Download the full report

Monthly webinar

Our team of Threat Intel experts keep a constant watch over the cyber and geopolitical landscape, so you don’t have to.

Introducing our monthly highlights webinar, giving you further insight and exclusive access to what's going on now. Join our Global Head of Threat Intelligence, Matt Hull, each month for:

  • A deeper understanding of the latest report findings
  • A look at emerging trends by region and sector
  • Insight into new threat actors
  • Spotlight on the most impactful active cyber threats

Our next webinar will take place on October 20th 2026, 4pm BST.

Matt Hull

Matt Hull

VP, Cyber Intelligence and Response

Subscribe to our monthly reports and webinars for the latest on recent and emerging advances in the threat landscape and a deep understanding of the latest Tactics, Techniques and Procedures (TTPs) of threat actors.

Cyber Threat Intelligence report archive

On demand videos

Missed a webinar? Find every past recording in our showcase:

View now

Never miss any intelligence.

Hit the button below to get our monthly reports and highlight webinars straight to your inbox.