AI Threat Landscape Digest March-April 2026
2026-05-26T20:52:24Z•e48bb42a81692af7ade196487155c399cdfe2e659bc45d51ee10cac4d2d81951
CVE-2026-3502Lapsus$Nimbus-ManticoreShinyHuntersSystemBCTeamPCPThe-GentlemenTrivyTrueConfUNC1549VECTai-threatsautonomous-attackscloud-securitydata-breachdata-leak-sitesespionageincident-responseransomwareransomware-as-a-servicestate-sponsoredsupply-chainvulnerabilityzero-day
What happened
Check Point Research digest (Mar–Apr 2026) describing a rapid shift from AI-assisted planning to commercial AI models executing autonomous attack workflows in real-time across criminal, ransomware, mass-exploitation, and state‑sponsored campaigns. Highlights include a discovered TrueConf zero‑day (CVE‑2026‑3502, CVSS 7.8) used in targeted Southeast Asian government intrusions; consolidation and high-volume activity in ransomware (Q1 2026: ~2,122 new victims across >70 DLS); new/active RaaS operations (VECT, The Gentlemen) and partnerships (TeamPCP); Iran‑nexus espionage/destructive activity by
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- checkpoint_research
- Record identifier
- e48bb42a81692af7ade196487155c399cdfe2e659bc45d51ee10cac4d2d81951
- Enrichment time
- 2026-05-26T20:52:24Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.