Identity was the primary target in approximately 50% of all confirmed malicious activity investigated between May and July 2026.
MantaxOtax is a dual-threat Android malware that uses ransomware to encrypt files and spyware to steal sensitive data, including SMS and WhatsApp messages.
Sophos researchers have identified a stealthy Linux rootkit targeting F5 BIG-IP APM environments that hides malicious web shells in memory to evade detection.
Sandworm and Qilin ransomware groups are exploiting a critical authentication bypass vulnerability in Cisco Secure Firewall Management Center (FMC).
Threat actors are using infostealer malware like Lumma and Vidar to harvest session tokens, enabling them to bypass MFA and hijack premium AI services.