CVE Tools

IT threat evolution in Q2 2026. Non-mobile statistics

Kaspersky SecurelistBy AMR12 min read

ResearchMicrosoft DefenderFox TempestCheck Point Remote Access

Our summary

Kaspersky's latest quarterly report highlights a surge in ransomware activity, noting that over 71,000 users were targeted in Q2 2026. A significant portion of these attacks leveraged specific vulnerabilities: CISA confirmed active exploitation of the BlueHammer local privilege escalation flaw in Microsoft Defender (CVE-2026-33825), while Check Point linked zero-day attacks in its Remote Access products (CVE-2026-50751) directly to the Qilin ransomware group. The study also details how the PayoutsKing threat actor is abusing the legitimate QEMU emulator to hide Alpine Linux virtual machines for credential theft, evading standard security monitoring.

Read at Kaspersky Securelist

Below is the opening; the full story is at Kaspersky Securelist.

From Kaspersky Securelist

IT threat evolution in Q2 2026. Non-mobile statistics
IT threat evolution in Q2 2026. Mobile statistics

The statistics in this report are based on detection verdicts returned by Kaspersky products unless otherwise stated. The information was provided by Kaspersky users who consented to sharing statistical data.…

Continue at Kaspersky Securelist

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store