The State of Ransomware Q2 2026

2026-08-13T20:52:17Z86b04daf889afa5001a5a08dbe27221addc027213b98468acef25301f8e8d0c0
AI-enabled-cybercrimeAI-securityCavern ManticoreCloudflare Code ModeCloudflare WorkersIran-linked-APTMOISNorth KoreaOilRigOperation Dream Jobaerospaceaviationbrowser-only-ransomwareclipboard-hijackercommand-and-controlcryptocurrency-theft-supply-chain-attackdefense-sector-targetingmemory-corruptionransomwareransomware-as-a-servicesandbox-escapethreat-intelligenceweaponized-pdfworkerdzero-day

What happened

Check Point Research feed covering ransomware trends, North Korea-linked Dream Job attacks using weaponized PDF viewers and zero-day exploitation, vulnerabilities in Cloudflare workerd affecting Code Mode and Workers, AI-enabled cybercrime, Iran-linked Cavern Manticore modular C2 activity, browser-only ransomware, crypto clipboard hijacking, supply-chain compromises, and recent breach and attack reports. The feed includes multiple reports describing significant ransomware, data theft, credential compromise, industrial control disruption, and third-party supply-chain incidents.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
checkpoint_research
Record identifier
86b04daf889afa5001a5a08dbe27221addc027213b98468acef25301f8e8d0c0
Enrichment time
2026-08-13T20:52:17Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.