Agregátor RSS

Za tragický pád letadla ATR v Brazílii mohla námraza i posádka. Závěrečná zpráva odhalila šlendrián aerolinek

Živě.cz - 10 Srpen, 2026 - 15:45
Letadlo se zřítilo kvůli nefunkčnímu systému proti námraze a chybám posádky • Odmrazovací systém nefungoval a piloti ignorovali hlášení o poklesu rychlosti • Aerolinky dlouhodobě zanedbávaly údržbu a poruchy se nezapisovaly do deníku
Kategorie: IT News

Attackers pick Levi's pockets in social engineering attack

The Register - Anti-Virus - 10 Srpen, 2026 - 15:36
Levi Strauss is investigating a data breach after attackers used social engineering to access three employees' work computers. In a regulatory filing, the jeans maker said the intruders accessed and exfiltrated what it described only as "certain corporate information." Levi's said it spotted the intrusion, kicked off its incident response procedures, brought in outside cybersecurity experts, and managed to cut off the unauthorized access. Its investigation remains ongoing. There is some good news for anyone worried that their trouser-buying habits might now be circulating on the dark web: Levi's said its preliminary investigation indicates that no consumer data was affected. The company also said the attack caused no disruption to its operations and, based on what it knows so far, isn't expected to have a material impact on its business. Affected parties and regulators will be notified where required. While Levi's isn't sharing much else about the incident, Reuters reports that the company was also among more than 200 targeted over the past five weeks by ransom-seeking hackers using decidedly old-school social engineering techniques. Google researchers have been tracking several crews involved in the wider campaign, which it believes may sit under an umbrella group dubbed UNC6671. The attackers have been phoning employees on their personal mobiles while posing as colleagues or IT support staff, then directing them to spoofed login pages designed to harvest credentials and multi-factor authentication codes. Their targets have included financial and legal firms handling the sort of information that can make for particularly effective extortion fodder, although Google says the attackers have previously gone after organizations across manufacturing, healthcare, insurance, technology, and hospitality too. There's no confirmation that UNC6671 was behind the successful Levi's intrusion, nor has the denim dealer said exactly what was stolen or whether anyone tried to extort it. For now, Levi's appears to have contained the breach before its attackers could get any deeper into its pockets. ®
Kategorie: Viry a Červi

Wetherspoons bars smart glasses from filming customers

The Register - Anti-Virus - 10 Srpen, 2026 - 15:20
Wetherspoons has stopped short of banning Meta-style smart glasses from its pubs, but told The Register that customers should switch off their cameras and refrain from filming. "Like many hospitality companies, Wetherspoon has CCTV cameras for security reasons, but their use is strictly controlled by data legislation," a spokesperson said. "Apart from that, the general code that applies in our pubs, and most pubs, is that you can't film customers or employees without their permission. "Meta glasses seem to breach this code, and common sense, by enabling surreptitious surveillance, so our instinct is to say turn off the cameras. This is akin to our efforts to stop audible playing of videos in our pubs, which also invades people's space." The Register asked whether customers who refused to stop recording would be ejected, but Wetherspoons declined to elaborate. Wetherspoons' statement suggests that recording, rather than merely wearing the glasses during a wallet-friendly session, would attract the attention of security staff. The policy is therefore less strict than those adopted by venues and events that have banned recording glasses outright over privacy concerns. DEF CON, which concluded last week, was the latest in a series of organizations to issue outright bans on Meta-style recording glasses, even for those who use them with prescription lenses. Conference organizers told delegates to pack "non-violating eyewear" if they needed them. Monopoly Events, which runs UK Comic Cons among other events, recently imposed a ban after talent agencies and guests raised concerns about privacy and the effect of covert recording on personal interactions. Scottish ferry operator CalMac also temporarily suspended unplanned visits to ships' bridges after a passenger made crew members feel uncomfortable during a crossing in June. Restaurateur Jeremy King, who owns London's Arlington, The Park, and Simpson's in the Strand, has said the glasses should not be worn in his establishments. Similarly, private members' club Soho House does not allow recording inside its venues, a policy that extends to Meta-style glasses. Brighton's Yellow Book Bar called the glasses "creepy and intrusive" when announcing its ban, and theatre companies ATG Entertainment and Trafalgar Entertainment do not permit them either. Meta's smart glasses have become shorthand for the wider category of camera-equipped eyewear. Google unveiled Glass in 2012 but failed to turn it into a mainstream consumer product. Meta and EssilorLuxottica launched their first Ray-Ban Stories glasses in 2021, followed by the second-generation Ray-Ban Meta range in 2023 and an expansion into Oakley-branded models. Meta's glasses have become the most prominent products in the category, prompting other tech companies to work on rivals. The next-gen eyewear has proven especially popular among social media users, allowing them to record high-res, hands-free, and first-person footage with ease. Unlike Google Glass, however, the wearables are largely indistinguishable from their analog counterparts, which makes their recording capabilities all the more problematic. The camera in Meta's specs is small and embedded neatly inside the glasses' frame. The company routinely highlights that each pair is fitted with a recording light, which activates when the user begins shooting video, and that if this light is covered up, then recording immediately stops. The feature has done little to appease those who feel the cameras are an invasion of privacy. UK law does not generally prevent individuals from filming in public, although pubs are private premises and may set their own rules. Smart glasses make those rules harder to enforce because recording is far less conspicuous than when someone points a smartphone at the scene. Researchers have shown that Meta's glasses can be paired with apps that can dox passersby in seconds. Others have worked up projects that inform Android users of nearby glasses-wearers using Bluetooth signals. Meta faces a UK data protection probe concerning the cross-border data flows of its glasses' footage after Kenyan reviewer teams reported seeing footage from wearers' more intimate moments. ®
Kategorie: Viry a Červi

Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development

The Hacker News - 10 Srpen, 2026 - 15:19
North Korea's state hackers are no longer content to type prompts into public chatbots. One of the country's main espionage groups has begun running artificial intelligence (AI) offline on its own servers, connecting document-search tools to files in its possession, and collecting the software parts needed to build AI into its malware. South Korean security firm Genians says it uncovered the Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Member of The Com sent to prison for blackmail, sextortion

Bleeping Computer - 10 Srpen, 2026 - 14:56
A member of "The Com," a loose-knit online cybercrime collective that targets children and teenagers, has been sentenced to two years in prison for blackmail and sextortion offenses against nearly 120 victims worldwide. [...]
Kategorie: Hacking & Security

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

The Hacker News - 10 Srpen, 2026 - 14:25
Three separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on. Passkeys are designed to replace reusable passwords and resist phishing. The attacks instead reused signed authentication material that Windows had exposed, abused a cloud-synced passkey system from malware already on the victim's machine, and used a Swati Khandelwalhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Cyber vulnerability sweep picks up Royal Navy drones sending data to China

The Register - Anti-Virus - 10 Srpen, 2026 - 14:25
Cameras aboard Royal Navy drone boats were found phoning home to an IP address in China during a routine cyber vulnerability assessment. The UK Ministry of Defence confirmed the discovery, describing it as "an issue affecting a Kraken Unmanned Surface Vessel sub-system used by the Royal Navy." The Register understands that the data consisted of a "heartbeat" signalling that the camera was online and functioning normally. Even so, an unexpected transmission from military equipment to an IP address in China will rattle nerves. We contacted unmanned surface vessel supplier Kraken for more information, but have yet to receive a reply. An MoD spokesperson told The Reg: "A thorough investigation found no evidence of MoD data or systems being accessed, compromised or transmitted externally." "Our assurance and testing processes are designed to identify and address potential vulnerabilities early, and we continue to undertake routine security activity across our systems and equipment." According to reports, the talkative components were cameras sourced by Kraken from a third-party supplier. The incident raises questions about supply chains, audits, and cybersecurity in the British armed forces. The spokesperson said: "The first duty of government is national security, and we take the security of our equipment, networks, and data extremely seriously." Concerns about China-linked cyber activity have risen sharply in recent years. In April, the National Cyber Security Centre issued a security advisory regarding covert networks, built from compromised routers and other edge devices. Beijing is also rarely far from the headlines when spying and covert operations are involved. In January, a China-linked group was accused of spying on the phones of aides to UK prime ministers. An unexpected connection from military hardware to China is therefore concerning, even if it carried little more than an "I'm alive!" heartbeat. The incident also demonstrates why every component in a defense supply chain needs testing rather than relying on a supplier's assurances. ®
Kategorie: Viry a Červi

Linux Vulnerability Prioritization with Threat Intelligence Insight

LinuxSecurity.com - 10 Srpen, 2026 - 14:13
A Linux vulnerability scan can create almost as many questions as it answers. The scan may identify dozens of affected packages, several CVEs marked High or Critical, and a mix of fixes that are available now or still working through a distribution's update process.
Kategorie: Hacking & Security

LexisNexis shuts down services after suspicious activity on servers

Bleeping Computer - 10 Srpen, 2026 - 14:11
LexisNexis took its Diligence, Metabase API, and Newsdesk services offline as part of its response to unusual activity on servers hosted and managed by an unnamed third-party vendor. [...]
Kategorie: Hacking & Security

Valve notifies Steam hardware customers of a data breach

Bleeping Computer - 10 Srpen, 2026 - 13:47
Video game publisher and digital distribution giant Valve is notifying Steam hardware customers in Europe that hackers stole their data after hacking its shipping partner, CEVA Logistics. [...]
Kategorie: Hacking & Security

Tech sector adds jobs, defies overall US job market decline

Computerworld.com [Hacking News] - 10 Srpen, 2026 - 13:36

While the number of US jobs declined by 23,000 in July, employment in the tech sector rebounded as the AI revolution continues to gain steam.

The national unemployment numbers were reported Friday by the US Bureau of Labor Statistics. At the same time, research firms said July was a good month for IT hiring compared to June.

According to CompTIA, which analyzed the BLS data, tech sector jobs rose in July by 3,700. In June, the IT sector had lost 900 jobs.

Companies last month hired in the cloud, hosting, information processing, data, and semiconductor manufacturing sectors, CompTIA said in a statement. 

“We’re entering a labor market where opportunity is increasingly concentrated around specific skills, industries, and investments,” said Ger Doyle, regional president of North America at ManpowerGroup, a labor consulting firm.

For example, data center hiring was up 39% in July compared to the same period last year, Doyle said. Not surprisingly, the data-center growth has been fueled by AI infrastructure needs and demand for hardware. That has helped increase the number of jobs in ancillary sectors such as transportation.

July hiring data showed heavy truck driver demand, which surged by 181% from June, Doyle said.

According to the BLS data, employment went up by 2.4% in the “computing infrastructure providers, data processing, web hosting, and related services” sectors, which is listed under the information sector.

Jobs in the “computer and electronic product manufacturing” sector — which is bunched under manufacturing — rose by 2.9% from June to July.

But bad news continued for the telecommunications sector, where the number of jobs declined by 1.5% from June to July. That continued a downward slide in recent years.

Overall job layoffs slowed in July, with 33,429 cuts announced; that’s down from 45,849 cuts announced in June, and the lowest since July 2024, according to data from Challenger, Gray and Christmas.

“Hiring has also increased over last year by 25%, so while AI is shifting the labor market, it is not dismantling it,” said Andy Challenger, chief revenue officer for Challenger, Gray & Christmas.

The tech sector announced 9,867 cuts in July, bringing the year-to-date total to 149,023 so far in 2026, according to Challenger figures.

Tech sector hiring and job losses vary as organizations use different measurement techniques to gauge the overall hiring environment. 

The top-line US unemployment rate declined to 4.1% from 4.2%, in part because of  workers leaving the workforce or not looking for jobs, indicating a slow labor market.

Still, hiring demand exists across the US, despite declining labor force participation and longer job searches, Doyle said.

Because technology underpins many of the changes occurring across sectors such as healthcare and services, employers are rethinking hiring.  “That’s why the labor market many workers are experiencing doesn’t always match the one described by the headline numbers,” Doyle said.

ADP’s National Employment report said only 44,000 jobs were added to private payrolls in July, with choppiness across sectors.

But demand for AI skills continues to rise, according to research firms that track growth by analyzing job listings. CompTIA noted that about 14,000 new job listings in July sought AI and machine learning skills.

It’s not clear how the ongoing AI boom may be hurting or helping human jobs. Many recent job cuts have been attributed to AI, though some companies have been accused of using the technology as a rationale for cuts they made for other reasons.

A recent OECD report said that even manual jobs once thought immune to AI are at risk of being taken over by robots. The OECD report said creative jobs — typically management, arts, and social work — will be least threatened by AI.

There are also increasing indications that successful AI deployments will require humans in the loop. For example, more consulting firms are using forward-deployed engineers (FDEs) to implement agentic AI. And smaller consultancy firms are finding more productivity by automating mundane work with AI and spending more time meeting client requirements.

Kategorie: Hacking & Security

TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore

The Hacker News - 10 Srpen, 2026 - 13:33
The threat actor known as Head Mare has been observed weaponizing security flaws in unpatched TrueConf servers once again in attacks targeting Russian companies spanning instrumentation, electronics, transport, energy, IT, and software development sectors. Russian cybersecurity vendor Kaspersky said it detected the attacks in July 2026. The activity involves exploiting a vulnerability chain Ravie Lakshmananhttp://www.blogger.com/profile/[email protected]
Kategorie: Hacking & Security

Framework loses customer data in Metabase zero-day attack

The Register - Anti-Virus - 10 Srpen, 2026 - 13:21
Modular laptop maker Framework has warned customers that an attacker exploited a zero-day at analytics provider Metabase to access names, email addresses, phone numbers, physical addresses, and login IP addresses, according to an email shared on Reddit. For business customers, the exposed information may also include company names, phone numbers, VAT or Employer Identification Numbers (EINs), and billing email addresses. Framework said order and payment details were not affected. "We are deeply sorry for this breach of information, and are reviewing and improving our methodology for data storage in external database vendors," Framework said, adding that it's notifying regulators where required, though it noted that names, email addresses, phone numbers, and physical addresses don't cross the mandatory reporting threshold in many regions. Customers are getting the heads-up regardless. Framework didn't immediately reply to The Register's questions, but told TechCrunch that the breach had affected "all customers." The intrusion began with a zero-day vulnerability in Metabase, the business intelligence platform Framework uses to analyze its data. In its own blog post, Metabase said an attacker targeted its cloud service using a previously unknown vulnerability affecting versions 1.58 and later. The company blocked the endpoints used in the attack, patched the bug, and deployed the fix across its cloud service. Framework's account provides a timeline for the break-in. Metabase discovered the attack on August 3 and notified Framework at 9am Pacific Time on August 6, telling the laptop maker that its instance had been vulnerable and that the attacker had successfully gained access to it. Framework said it then rotated credentials for every database connected to its Metabase instance and found no changes to admin access or evidence that systems outside Metabase had been accessed. The company has also brought in a third-party forensics firm to investigate, and cautioned that its findings so far are preliminary. According to Metabase, exploitation can allow an attacker to inject arbitrary SQL against the application's database and potentially gain administrator access. From there, they could alter configuration settings, steal credentials for databases connected to Metabase, query data those connections can access, and export the results. Metabase told anyone running their own instance to patch immediately. If the vulnerable password-reset endpoint was exposed to the internet, admins have more work ahead of them: killing active sessions, checking for rogue API keys or admin accounts, rotating database credentials, and digging through logs for anything suspicious. Framework is reviewing how customer information is made available through external analytics services, but hasn't yet said what changes that review might produce. The breach lands during an already bumpy spell for Framework and its customers. In July, the repairable PC maker warned that the price it was being charged for LPCAMM2 memory used in its Laptop 13 Pro had more than doubled, forcing it to raise memory prices rather than swallow the increase. It also warned that CPU prices were heading upward and could push overall system prices higher in the coming weeks. Being able to replace almost every part of your laptop is handy. Finding your home address exposed through an analytics service is rather less so. ®
Kategorie: Viry a Červi

Zatmění Slunce 2026. Česko čeká působivé divadlo, Španělsko úplná tma

Živě.cz - 10 Srpen, 2026 - 13:20
Ve středu 12. srpna 2026 čeká Evropu jedno z nejzajímavějších zatmění Slunce posledních let. V Česku nebude úplné, ale i tak výrazné: Měsíc zakryje přes 80 % slunečního kotouče, na západě republiky téměř 87 %. Kdo chce zažít úplnou fázi, musí vyrazit do pásu totality. Nejpraktičtější evropskou ...
Kategorie: IT News

Onsemi, Meopta i Advacam. Do českých čipů míří velké peníze, patenty mají hned sloužit byznysu

Živě.cz - 10 Srpen, 2026 - 12:45
Do českého výzkumu čipů zamíří půl miliardy korun, cílem je z objevů konečně udělat byznys • . • Plzeňští vědci ukázali, že se polovodič dá pouhým světlem proměnit v kov. • Na projektu se sešly univerzity s předními výrobci jako je Onsemi, Meopta i dodavatel Nvidie.
Kategorie: IT News

Claude Code puts auto mode in the driver's seat

The Register - Anti-Virus - 10 Srpen, 2026 - 12:38
Anthropic is making auto mode the default in Claude Code from August 14, claiming its classifier is "as safe or safer than an average user clicking through prompts." Users with a different default already set might receive a one-time prompt asking whether they want to switch. It applies to new sessions on Pro, Max, and Team plans. It will remain opt-in for now on Claude Enterprise, the Claude API, Claude Platform on AWS, Amazon Bedrock, Google Cloud's Agent Platform, and Microsoft Foundry. Anthropic plans to make it the default across those services within the coming month. Anthropic has also stopped charging Pro, Max, and Team users for the extra tokens consumed by the classifier, and plans to do the same on the other platforms. Auto mode was launched in March as a research preview and became generally available on July 10. It was an alternative to Claude Code's default permissions, in which every file write and bash command required manual approval. This conservative approach meant running a large task and walking away wasn't possible. The alternative was the --dangerously-skip-permissions flag, which, as the name suggests, lets Claude act without those checks and can lead to risky or destructive results. Auto mode sends each tool call through a classifier designed to block actions that are "irreversible, destructive, or aimed outside your environment." When the classifier blocks something, Claude will try to find a safer way to proceed. If there are three blocks in a row or 20 across a session, Claude Code falls back to manual approvals. "We spent the last several months testing whether auto mode is as safe or safer than an average user clicking through prompts," Anthropic said. "We ran internal red-teaming, third-party red-teaming and prompt-injection evaluations, a controlled study with 1,053 paid testers, and analysis of real production sessions. On every measure we tested, auto mode matched or outperformed manual review." In the controlled study, testers caught a deliberately inserted dangerous command just 13.6 percent of the time. Auto mode blocked 89 percent of the same commands. Anthropic also found that Claude Code users approve 97 percent of permission prompts, suggesting the human checkpoint often amounts to little more than muscle memory. Anthropic produced the usual set of charts showing how wonderful its new feature is compared to the competition, with its auto mode stopping all 720 attack attempts tested, compared to GPT-5.6 Sol running Codex's Auto-review mode, which let 5.83 percent of attacks through. The company also described three potentially damaging actions that auto mode blocked inside Anthropic. These were an off-network data leak, a destructive mass operation, and a privilege escalation. Anthropic stated: "In each case, Claude either found a safer path on its own or checked in with the user before proceeding." ®
Kategorie: Viry a Červi

Mobilní Hackday #8 proběhne 28. srpna v Praze

AbcLinuxu [zprávičky] - 10 Srpen, 2026 - 12:12
V pátek 28. srpna 2026 se v pražském Karlíně uskuteční již osmý Mobilní Hackday. Akce začne v 10:00 a potrvá až do večera. Setkání proběhne v prostorách SUSE Linux, s.r.o. na adrese Křižíkova 148/34, Praha 8 – Karlín. Nejbližší zastávkou je Křižíkova, kam se lze dostat tramvají i metrem. Na programu budou například novinky z posledních měsíců, možnosti, jak si zjednodušit práci s LLM/AI, a také nová linuxová distribuce BengalOS, včetně ukázky, jak ji vyzkoušet a sestavit. Prostor dostane také vývoj linuxového jádra a práce na telefonech s platformou Qualcomm Snapdragon 845 (sdm845). Řeč bude například o zařízeních OnePlus 6/6T, Xiaomi Poco F1 nebo Shift 6MQ. Akce je určena zájemcům o Linux na mobilních zařízeních, vývoj a komunitní hackování. Zájemci o účast by měli svou účast předem potvrdit. Kdy: pátek 28. 8. 2026 od 10:00 do večera Kde: SUSE Linux, s.r.o., Křižíkova 148/34, Praha 8 – Karlín Doprava: metro/tramvaj Křižíkova Mastodon | Matrix
Kategorie: GNU/Linux & BSD

IT threat evolution in Q2 2026. Non-mobile statistics

Kaspersky Securelist - 10 Srpen, 2026 - 12:00

IT threat evolution in Q2 2026. Non-mobile statistics
IT threat evolution in Q2 2026. Mobile statistics

The statistics in this report are based on detection verdicts returned by Kaspersky products unless otherwise stated. The information was provided by Kaspersky users who consented to sharing statistical data.

Quarterly figures

In Q2 2026:

  • Kaspersky products blocked nearly 400 million attacks that originated with various online resources.
  • Web Anti-Virus responded to 52 million unique links.
  • File Anti-Virus blocked more than 16 million malicious and potentially unwanted objects.
  • There were 2538 new ransomware variants discovered.
  • More than 71,000 users experienced ransomware attacks.
  • 15% of all ransomware victims whose data was published on threat actors’ data leak sites (DLS) were attacked by Qilin.
  • More than 213,000 users were targeted by miners.
Ransomware Quarterly trends and highlights Threat actor disruption

Microsoft has dismantled an illicit malware-signing service used by ransomware operators. Microsoft’s Digital Crimes Unit has shut down a malware-signing-as-a-service (MSaaS) operation run by the threat group Fox Tempest. The illicit service abused the Microsoft Artifact Signing platform to generate digital signature certificates for malicious software. Malware signed by these certificates was observed in campaigns conducted by such ransomware groups as Rhysida, Akira, INC, Qilin, and BlackByte. The service was also leveraged by operators of the Oyster loader as well as the Lumma and Vidar infostealers. To disrupt the operation, Microsoft seized the domain used by the MSaaS platform, revoked all associated certificates, and disabled the related accounts. Additionally, the company filed a lawsuit against Fox Tempest.

Vulnerabilities and attacks

CISA has confirmed that a Windows vulnerability known as BlueHammer is actively being exploited in ransomware attacks. On April 22, the agency updated its Known Exploited Vulnerabilities (KEV) catalog to note the ongoing ransomware exploitation of CVE-2026-33825. The local privilege escalation flaw in Microsoft Defender was originally disclosed earlier in April. Although Microsoft released a fix on April 14, unpatched systems remain vulnerable. CISA did not disclose further details or attribute the attacks to specific threat groups.

Check Point has linked zero-day exploitation of CVE-2026-50751 to the Qilin ransomware group. The critical vulnerability affects Check Point Remote Access VPN and Mobile Access. Attackers began exploiting the flaw as a zero-day on May 7, with activity spiking sharply in early June. While several dozen organizations have been targeted, at least one incident has been definitively tied to Qilin. Check Point also disclosed a related certificate validation flaw (CVE-2026-50752) that affects site-to-site VPN connections relying on the legacy IKEv1 key exchange protocol.

Researchers assess with high confidence that the PayoutsKing group is leveraging the legitimate QEMU emulator to deploy hidden, Alpine Linux-based virtual machines on compromised hosts. Because security solutions often lack visibility inside virtualized environments, the threat actors use this technique to evade detection. Inside the VM image, the operators deploy various tools — such as credential theft software — and configure the virtual machine as a backdoor managed via a reverse SSH tunnel to their command-and-control infrastructure. While the technique is not new, and we’ve detailed it before, it remains relatively rare in ransomware attacks.

The most prolific groups

This section highlights the most prolific ransomware gangs by number of victims added to each group’s DLS. Qilin reclaimed the top spot (accounting for 14.57% of total listings) after placing second last quarter. It is followed by the Akira ransomware (7.80%) and the DragonForce RaaS group (6.88%).

Number of each group’s victims according to its DLS as a percentage of all groups’ victims published on all the DLSs under review during the reporting period (download)

Number of new ransomware variants

In Q2, Kaspersky solutions detected four new ransomware families and 2538 new modifications. This signals a continued stabilization following spikes seen in Q1 and Q4 of last year.

Number of new ransomware modifications, Q2 2025 — Q2 2026 (download)

Number of users attacked by ransomware Trojans

Our solutions protected a total of 71,860 unique users from ransomware during Q2. Ransomware activity peaked in April, with 31,206 targeted users recorded during that month.

Number of unique users attacked by ransomware Trojans, Q2 2026 (download)

TOP 10 countries and territories attacked by ransomware Trojans Country/territory* %** 1 South Korea 0.87 2 Pakistan 0.76 3 China 0.71 4 Libya 0.49 5 Tajikistan 0.46 6 Turkmenistan 0.38 7 Cameroon 0.38 8 Indonesia 0.36 9 Bangladesh 0.36 10 Mozambique 0.34

* Excluded are countries and territories with relatively few (under 50,000) Kaspersky users.
** Unique users whose computers were attacked by ransomware Trojans as a percentage of all unique users of Kaspersky products in the country/territory.

TOP 10 most common families of ransomware Trojans Name Verdict %* 1 (generic verdict) Trojan-Ransom.Win32.Gen 28.02 2 WannaCry Trojan-Ransom.Win32.Wanna 7.14 3 (generic verdict) Trojan-Ransom.Win32.Crypren 6.27 4 (generic verdict) Trojan-Ransom.Win32.Agent 4.89 5 (generic verdict) Trojan-Ransom.Win32.Encoder 4.65 6 (generic verdict) Trojan-Ransom.Python.Agent 3.07 7 (generic verdict) Trojan-Ransom.Win32.Crypmod 2.70 8 (generic verdict) Trojan-Ransom.MSIL.Agent 2.45 9 PolyRansom/VirLock Virus.Win32.PolyRansom / Trojan-Ransom.Win32.PolyRansom 2.31 10 (generic verdict) Trojan-Ransom.Win32.Phny 2.12

* Unique Kaspersky users attacked by the specific ransomware Trojan family as a percentage of all unique users attacked by this type of threat.

Miners Number of new miner variants

In Q2 2026, Kaspersky solutions detected 6067 new miner variants, almost twice the number for the previous reporting period.

Number of new miner modifications, Q2 2026 (download)

Number of users attacked by miners

In Q2, we detected attacks using miner programs on the computers of 213,003 unique Kaspersky users worldwide.

Number of unique users attacked by miners, Q2 2026 (download)

TOP 10 countries and territories attacked by miners Country/territory* %** 1 Mali 1.56 2 Senegal 1.54 3 Tanzania 1.32 4 Panama 1.04 5 Bangladesh 1.03 6 Ethiopia 0.87 7 Costa Rica 0.67 8 Bolivia 0.67 9 Côte d’Ivoire 0.65 10 Kazakhstan 0.62

* Excluded are countries and territories with relatively few (under 50,000) Kaspersky users.
** Unique users whose computers were attacked by miners as a percentage of all unique users of Kaspersky products in the country/territory.

Attacks on macOS Quarterly highlights

In April, Aikido researchers reported a new attack by the GlassWorm stealer, which was distributed via malicious IDE extensions on the Open VSX Registry. The payload operated by installing a secondary malicious extension across all installed IDE environments on the host machine. Ultimately, this second-stage implant exfiltrated crypto wallet data, environment variables, and other secrets. It also installed a RAT on the infected device.

In May, Socket researchers uncovered a supply chain compromise involving the popular npm package art-template. As a result of the breach, the weaponized package injected the Coruna exploit kit into web applications it was used to build. Coruna targets iOS devices.

In June, Palo Alto Networks’ Unit 42 discovered FlutterShell, a new backdoor family that targets macOS devices. Developed with the Flutter framework, the malware leverages the WebView engine to load web pages that contain malicious JavaScript. On the client side, the backdoor registers bridge functions invoked by the loaded JavaScript that allow threat actors to execute arbitrary payloads on the victim’s device. Notably, the malicious applications successfully passed Apple notarization. Although the specific samples analyzed functioned primarily as adware, the underlying architecture permits the delivery of far more sophisticated malicious payloads.

TOP 20 threats to macOS

* Unique users who encountered this malware as a percentage of all attacked users of Kaspersky security solutions for macOS (download)

* Data for the previous quarter may differ slightly from previously published data due to some verdicts being retrospectively revised.

Detections of PasivRobber spyware continued their downward trend. Meanwhile, adware and traffic-routing utilities (categorized as NetTool) rose to the top of the rankings. Additionally, Q2 saw a noticeable spike in detections for the DirtyCow exploit frequently leveraged for iPhone jailbreaking.

TOP 10 countries and territories by share of attacked users Country/territory %* Q1 2026 %* Q2 2026 Brazil 1.13 1.13 China 1.04 1.28 Hong Kong 0.92 0.49 Singapore 0.85 0.19 France 0.62 1.18 Mexico 0.43 0.72 India 0.41 0.42 Thailand 0.40 0.24 Germany 0.33 0.71 The Netherlands 0.31 0.62

* Unique users who encountered threats to macOS as a percentage of all unique Kaspersky users in the country/territory.

IoT threat statistics

This section presents statistics on attacks targeting Kaspersky IoT honeypots. The geographic data on attack sources is based on the IP addresses of attacking devices.

In Q2 2026, the breakdown of attacking devices and sessions that targeted Kaspersky honeypots by protocol was as follows:

Distribution of attacked services by number of unique IP addresses of attacking devices (download)

The share of SSH attacks saw a slight uptick compared to the previous quarter.

Distribution of cybercriminal sessions in Kaspersky honeypots (download)

TOP 10 threats delivered to IoT devices

Share of each threat delivered to an infected device as a result of a successful attack, out of the total number of threats delivered (download)

As is typically the case, Mirai botnet variants continue to dominate the IoT threat landscape. Activity of another prominent botnet, Prometei, also saw an increase.

Attacks on IoT honeypots

the Netherlands, Germany, and The United States accounted for the highest proportions of SSH-based attacks during this period. While the top three countries remained the same as last quarter, their relative rankings shifted.

Country/territory Q1 2026 Q2 2026 The Netherlands 17.57% 21.18% Germany 10.34% 16.73% United States 23.74% 6.76% Bulgaria 1.10% 5.50% Sweden 2.09% 4.93% Panama 6.34% 4.67% Luxembourg 0.16% 4.62% Romania 5.82% 4.06% Vietnam 3.50% 3.91% India 6.05% 2.78%

The percentage of Telnet-based attacks originating from Pakistan continued to climb, knocking China down to second place.

Country/territory Q1 2026 Q2 2026 Pakistan 27.31% 36.60% China 39.54% 35.62% Russian Federation 8.25% 8.75% India 4.66% 4.19% Brazil 3.30% 3.34% United States 0.45% 3.03% Indonesia 6.71% 1.52% Philippines 0.36% 0.95% France 0.17% 0.84% Thailand 0.55% 0.66% Attacks via web resources

The statistics in this section are based on detection verdicts by Web Anti-Virus, which protects users when suspicious objects are downloaded from malicious or infected web pages. These malicious pages are purposefully created by cybercriminals. Websites that host user-generated content, such as message boards, as well as compromised legitimate sites, can become infected.

TOP 10 countries and territories that served as sources of web-based attacks

The following statistics show the distribution by country/territory of the sources of internet attacks blocked by Kaspersky products on user computers (web pages redirecting to exploits, sites containing exploits and other malware, botnet C&C centers, and so on). One or more web-based attacks could originate from each unique host.

To determine the geographic source of web attacks, we matched the domain name with the real IP address where the domain is hosted, then identified the geographic location of that IP address (GeoIP).

In Q2 2026, Kaspersky solutions blocked 399,312,961 attacks launched from internet resources worldwide. Web Anti-Virus was triggered by 52,850,592 unique URLs.

Web-based attacks by country/territory, Q1 2026 (download)

Countries and territories where users faced the greatest risk of online infection

To assess the risk of malware infection via the internet for users’ computers in different countries and territories, we calculated the share of Kaspersky users in each location on whose computers Web Anti-Virus was triggered during the reporting period. The resulting data provides an indication of the aggressiveness of the environment in which computers operate in different countries and territories.

This ranked list includes only attacks by malicious objects classified as Malware. Our calculations leave out Web Anti-Virus detections of potentially dangerous or unwanted programs, such as RiskTool or adware.

Country/territory* %** 1 Bangladesh 11.71 2 India 7.40 3 Tajikistan 7.13 4 Venezuela 7.05 5 New Zealand 6.58 6 Vietnam 6.34 7 Taiwan 6.28 8 Belgium 6.24 9 France 5.97 10 Hungary 5.92 11 Nepal 5.91 12 Portugal 5.86 13 Italy 5.77 14 Costa Rica 5.72 15 Canada 5.65 16 Qatar 5.61 17 Dominican Republic 5.52 18 Palestine 5.48 19 Greece 5.47 20 UAE 5.43

* Excluded are countries and territories with relatively few (under 10,000) Kaspersky product users.
** Unique users targeted by web-based Malware attacks as a percentage of all unique users of Kaspersky products in the country/territory.

On average during the quarter, 4.54% of users’ computers worldwide were subjected to at least one Malware web attack.

Local threats

Statistics on local infections of user computers are an important indicator. They include objects that penetrated the target computer by infecting files or removable media, or initially made their way onto the computer in non-open form. Examples of the latter are programs in complex installers and encrypted files.

Data in this section is based on analyzing statistics produced by anti-virus scans of files on the hard drive at the moment they were created or accessed, and the results of scanning removable storage media. The statistics are based on detection verdicts from the On-Access Scan (OAS) and On-Demand Scan (ODS) modules of File Anti-Virus and include detections of malicious programs located on user computers or removable media connected to the computers, such as flash drives, camera memory cards, phones, or external hard drives.

In Q2 2026, our File Anti-Virus detected 16,986,351 malicious and potentially unwanted objects.

Countries and territories where users faced the highest risk of local infection

For each country and territory, we calculated the percentage of Kaspersky users whose computers had the File Anti-Virus triggered at least once during the reporting period. These statistics reflect the level of personal computer infection in different countries.

Note that this ranked list includes only attacks by malicious objects classified as Malware. Our calculations leave out File Anti-Virus detections of potentially dangerous or unwanted programs, such as RiskTool or adware.

Country/territory* %** 1 Turkmenistan 46.38 2 Cuba 29.70 3 Tajikistan 28.46 4 Afghanistan 28.19 5 Yemen 27.85 6 Burundi 26.82 7 Mozambique 25.01 8 Republic of the Congo 24.88 9 Syria 23.17 10 Uzbekistan 22.49 11 China 21.92 12 Nicaragua 21.60 13 Cameroon 21.47 14 Bangladesh 20.43 15 Democratic Republic of the Congo 20.25 16 Algeria 19.78 17 Uganda 19.48 18 Ethiopia 18.57 19 Tanzania 18.54 20 Mali 18.53

* Excluded are countries and territories with relatively few (under 10,000) Kaspersky users.
** Unique users on whose computers Malware local threats were blocked, as a percentage of all unique users of Kaspersky products in the country/territory.

On average worldwide, Malware local threats were detected at least once on 10.93% of users’ computers during Q2.

Russia scored 10.78% in these rankings.

Syndikovat obsah