IT threat evolution in Q1 2026. Mobile statistics
2026-05-18T20:51:52Z•6fca577eaa4191d4b51181b0470221dcfe195b79bcafce9848d570a49f250608
CVE-2025-68670amazon-sesappleseeddata-leak-extortionedr-killersexploitsiot-threatskasperskykimsukymobile-threatsoceanlotuspc-threatspebbledashphishingpypiq1-2026ransomwaresilver-foxsparkcatsupply-chaintriadavalleyrat (ValleyRAT) or valleyrat?vulnerabilitiesxrdpzichatbot
What happened
Kaspersky Securelist RSS roundup (May 2026) covering Q1 2026 telemetry and multiple technical write-ups. Key items: Q1 mobile, PC and IoT threat statistics (including new SparkCat and Triada variants); analysis of Kimsuky campaigns using PebbleDash tools linked to the AppleSeed cluster; a ransomware trends overview (rise of EDR-killers and shift from encryption to data-leak extortion); disclosure of CVE-2025-68670 (pre-auth RCE in xrdp, promptly patched); a vulnerabilities-and-exploits quarterly summary; OceanLotus distributing ZiChatBot via malicious PyPI wheel packages (supply-chain attack);
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- kaspersky_securelist
- Record identifier
- 6fca577eaa4191d4b51181b0470221dcfe195b79bcafce9848d570a49f250608
- Enrichment time
- 2026-05-18T20:51:52Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.