📱 Our mobile app for Threat Actor Claim is coming soon to the App Store & Google Play. تطبيقنا للجوال لخدمة Threat Actor Claim قادم قريباً على App Store و Google Play. Learn more اعرف المزيد
← All research → كل الأبحاث
September 27, 2026

Threat Intelligence Briefing: 315 New Claims Tracked Across Global Sectors

موجز استخبارات التهديدات: تتبع 315 مطالبة جديدة عبر القطاعات العالمية

Forsan analyzes the latest threat landscape data from September 20 to September 27, 2026, highlighting dominant threat actors, sector targeting, and critical vulnerabilities.

يحلل فريق «فرسان» أحدث بيانات مشهد التهديدات للفترة من 20 إلى 27 سبتمبر 2026، مسلطاً الضوء على الجهات الفاعلة المهيمنة للتهديدات، واستهداف القطاعات، والثغرات الحرجة.

During the week of September 20 to September 27, 2026, Forsan's threat intelligence team tracked a total of 315 new claims across the global threat landscape. Among these recorded incidents, 87 were classified as high or critical severity, underscoring the persistent and aggressive posture maintained by malicious cyber actors against enterprise environments.

A breakdown of the activity by malicious motivation reveals a heavy concentration of traditional extortion and disruptive campaigns. Specifically, the data shows 199 ransomware claims compared to 2 hacktivist and DDoS-related claims, illustrating that financially motivated encryption and data theft continue to dominate the primary methods of compromise.

Activity at the threat actor level was led by killsec3, which accounted for 46 claims this week. Other notable actors contributing significantly to the volume include Unattributed groups with 28 claims, clop with 23 claims, qilin with 18 claims, and everest rounding out the top tier with 12 claims. The prominence of groups like Clop and Qilin highlights the ongoing threat posed by established ransomware-as-a-service ecosystems.

From a vertical perspective, targeting remained diverse with a heavy emphasis on operational and information-intensive industries. The top five targeted sectors for the week were Manufacturing with 26 claims, Professional Services with 21 claims, Technology with 17 claims, Healthcare with 16 claims, and Financial Services with 9 claims. This distribution suggests adversaries continue to exploit supply chains and intellectual property within manufacturing and professional services.

Regionally, our monitors recorded 6 Middle East-tagged claims during this reporting period. While representing a smaller fraction of the global total, regional organizations must remain vigilant against targeted campaigns and ensure their perimeter defenses are continuously audited.

In addition to extortion and actor tracking, organizations must maintain strict vulnerability management protocols. The most severe vulnerability highlighted this week is CVE-2026-100706, carrying a critical CVSS score of 9.9. Forsan advises all security teams to review their infrastructure for exposure to this flaw and prioritize immediate patching to mitigate potential exploitation risks.

خلال الأسبوع الممتد من 20 إلى 27 سبتمبر 2026، تتبع فريق استخبارات التهديدات في «فرسان» ما مجموعه 315 مطالبة جديدة عبر مشهد التهديدات العالمي. ومن بين هذه الحوادث المسجلة، تصنف 87 مطالبة ضمن مستوى الخطورة العالية أو الحرجة، مما يؤكد الموقف المستمر والعدواني الذي تحافظ به جهات التهديد الضارة ضد بيئات المؤسسات.

يكشف تحليل النشاط حسب الدوافع الضارة عن تركز كثيف لحملات ابتزاز تقليدية وحملات تخريبية. على وجه التحديد، تظهر البيانات 199 مطالبة برمجيات فدية مقارنة بـ 2 من مطالبات النشاط السيبراني (هاكتيفيزم) والهجمات المتعلقة بحجب الخدمة الموزعة (DDoS)، مما يوضح أن التشفير بغرض الربح المادي وسرقة البيانات يواصلان هيمنتهما على الطرق الأساسية للاختراق.

تصدّرت مجموعة killsec3 النشاط على مستوى جهات التهديد، حيث مسؤولة عن 46 مطالبة هذا الأسبوع. وتشمل الجهات الفاعلة البارزة الأخرى التي ساهمت بشكل كبير في الحجم مجموعات غير منسوبة (Unattributed) بـ 28 مطالبة، وclop بـ 23 مطالبة، وqilin بـ 18 مطالبة، وتُكمل everest الفئة العليا بـ 12 مطالبة. ويسلط بروز مجموعات مثل Clop وQilin الضوء على التهديد المستمر الذي تشكله منظومات برمجيات الفدية كخدمة الراسخة.

من منظور القطاعات، ظل الاستهداف متنوعاً مع تركيز كبير على الصناعات التشغيلية وتلك كثيفة المعلومات. وكانت القطاعات الخمسة الأولى المستهدفة لهذا الأسبوع هي التصنيع بـ 26 مطالبة، والخدمات المهنية بـ 21 مطالبة، والتكنولوجيا بـ 17 مطالبة، والرعاية الصحية بـ 16 مطالبة، والخدمات المالية بـ 9 مطالبات. يوحي هذا التوزيع بأن الخصوم يواصلون استغلال سلاسل الإمداد والملكية الفكرية ضمن قطاعي التصنيع والخدمات المهنية.

على الصعيد الإقليمي، سجّلت أدوات المراقبة لدينا 6 مطالبات تحمل وسم الشرق الأوسط خلال فترة التقرير هذه. ورغم تمثيلها لنسبة أصغر من الإجمالي العالمي، يجب على المؤسسات الإقليمية الحفاظ على يقظتها ضد الحملات المستهدفة وضمان تدقيق دفاعاتها المحيطية باستمرار.

بالإضافة إلى الابتزاز وتتبع الجهات الفاعلة، يجب على المؤسسات الحفاظ على بروتوكولات صارمة لإدارة الثغرات الأمنية. إن الثغرة الأمنية الأكثر خطورة التي جرى تسليط الضوء عليها هذا الأسبوع هي CVE-2026-100706، والتي تحمل تقييم خطورة حرجاً (CVSS) يبلغ 9.9. تنصح «فرسان» جميع الفرق الأمنية بمراجعة بنيتها التحتية بحثاً عن أي تعرض لهذا الخلل وإعطاء الأولوية للترقيع الفوري للتخفيف من مخاطر الاستغلال المحتملة.

Generated from Forsan's own live-ingested threat data for the reporting period, reviewed against the underlying statistics before publishing. Not a substitute for a full incident investigation.
تم إنشاء هذا التقرير من بيانات فرسان الحية المرصودة لفترة التقرير، وروجعت مقابل الإحصاءات الأساسية قبل النشر. لا يغني هذا التقرير عن تحقيق كامل في أي حادثة.
⏱

Still there?

For your security, you'll be signed out in 60s due to inactivity.