IT threat evolution in Q2 2026. Non-mobile statistics
ResearchMicrosoft DefenderFox TempestCheck Point Remote AccessOur summary
Kaspersky's latest quarterly report highlights a surge in ransomware activity, noting that over 71,000 users were targeted in Q2 2026. A significant portion of these attacks leveraged specific vulnerabilities: CISA confirmed active exploitation of the BlueHammer local privilege escalation flaw in Microsoft Defender (CVE-2026-33825), while Check Point linked zero-day attacks in its Remote Access products (CVE-2026-50751) directly to the Qilin ransomware group. The study also details how the PayoutsKing threat actor is abusing the legitimate QEMU emulator to hide Alpine Linux virtual machines for credential theft, evading standard security monitoring.
Below is the opening; the full story is at Kaspersky Securelist.
From Kaspersky Securelist
IT threat evolution in Q2 2026. Non-mobile statistics
IT threat evolution in Q2 2026. Mobile statistics
The statistics in this report are based on detection verdicts returned by Kaspersky products unless otherwise stated. The information was provided by Kaspersky users who consented to sharing statistical data.…
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.