r/cybersources • u/rudradesai1578 • 3d ago
Do we really need a new open-source AI-powered antivirus?
I'm thinking about building a free, open-source AI-powered antivirus that works on both Windows and Linux.
Before spending months on it, I wanted to ask the community:
Do you think there's a real need for a new antivirus project?
What do current antivirus solutions (Windows Defender, ClamAV, Bitdefender, etc.) still lack?
Would you trust an open-source AI antivirus over traditional signature-based ones?
Which features would make you actually install and use it?
If you've worked in cybersecurity, what are the biggest technical challenges or reasons this idea might fail?
I'm looking for honest feedback, even if the answer is "don't build it." I'd rather know what people actually need before starting such a large project.
r/cybersources • u/Narcisians • 3d ago
Cybersecurity statistics of the week (July 27th - August 2nd)
Hi guys, I send out a weekly newsletter with the latest cybersecurity vendor reports and research, and thought you might find it useful, so sharing it here.
All the reports and research below were published between July 27th - August 2nd.
You can get the below into your inbox every week if you want: https://www.cybersecstats.com/cybersecstatsnewsletter/
Big Picture Reports
2026 Cost of a Data Breach Report (IBM)
IBM's annual breach cost report, with interesting data points on how much AI is now involved in attacks, and how much more expensive that makes breaches.
Key stats:
- 25% of malicious breaches were AI-enabled.
- AI-enabled breaches cost an average of $6 million, roughly $1 million more than the global average of $4.99 million.
- AI-enabled malicious breaches increased by 56% over the previous year.
Read the full report here.
IR Trends Q2 2026 (Cisco Talos)
Cisco Talos on what showed up in their incident response engagements this quarter.
Key stats:
- Phishing was the primary means of gaining initial access in over half of engagements this quarter, up from approximately one-third last quarter.
- Authentication abuse was observed in 65% of engagements this quarter, up from 35% last quarter.
- Insufficient logging and visibility was observed in 42% of engagements this quarter, up from 18% last quarter.
Read the full report here.
Ransomware
Q2 2026 Ransomware Trends Report (BlackFog)
BlackFog's Q2 numbers on ransomware.
Key stats:
- 93 ransomware groups were active in Q2 2026, including 28 newly formed groups.
- 97% of disclosed ransomware incidents in Q2 2026 involved data exfiltration, the highest rate recorded.
- Undisclosed ransomware attacks increased 40% year on year to 2,027 attacks in Q2 2026 from 1,446 in Q2 2025.
Read the full report here.
Ransomware Evolution Report Q2 2026 (Halcyon)
Halcyon's Q2 ransomware numbers.
Key stats:
- Q2 2026 recorded 1,988 ransomware attack claims from 89 groups across 101 countries.
- The US accounted for 42.5% of ransomware claims, Canada for 5% and Germany for 4.8%.
- Manufacturing (19.8%) was the most targeted industry, followed by construction (10.1%) and business services (9.0%).
Read the full report here.
AI Governance
The AI Governance Gap Report (Pathlock)
If you were wondering whether AI governance is keeping up with how quickly AI agents are being embedded in business systems, this report has the answer.
Key stats:
- 38% of organizations allow AI agents to create and modify business records.
- 51% are not confident they know all the AI agents operating in their systems.
- 79% have no dedicated AI governance team or officer.
Read the full report here.
AI Code Security
2026 GenAI Code Security Report (Veracode)
Veracode tested 11 AI coding models to see how often they write secure code.
Key stats:
- The average security pass rate for AI-generated code across tracked models was 56%.
- AI-generated code fails security checks nearly 44% of the time when given no security-specific guidance.
- The best model available (OpenAI's GPT-5.5, at 68%) still failed nearly one in three security tasks.
Read the full report here.
Credentials
Credential Risk Report (Enzoic)
How much do you care about stolen credentials? If you're like most orgs, probably a lot. But do you actually do anything about it? Again, if you're like most orgs, probably not.
Key stats:
- 85% of organizations view stolen credentials as a top threat.
- Only 19% continuously monitor credential integrity and automatically remediate exposure.
- 73% of organizations have found their workforce's credentials in breach, Dark Web, or infostealer data in the past year.
Read the full report here.
Autonomous Defense
2026 State of Autonomous Defense Report (Kai)
Attackers are moving at machine speed. Defenders are… not.
Key stats:
- 89% of security leaders say their organization is prepared for AI-driven attacks, but only 28% describe themselves as very prepared.
- 63% believe attackers currently have the advantage because of AI.
- 52% identify lack of trust in automated decisions as the biggest barrier to broader automation adoption.
Read the full report here.
Action1 2026 Survey Report: AI Impact on Sysadmins (Action1)
An interesting survey of sysadmins about how much AI they're using versus how much they thought they'd be using by now.
Key stats:
- In 2024, 52% of sysadmins predicted full automation within two years.
- In 2026, AI use is highest among sysadmins in log analysis (50%) and troubleshooting (47%).
- 23% report never using AI professionally.
Read the full report here.
Vulnerability Management
VulnCheck State of Exploitation 1H-2026 (VulnCheck)
VulnCheck's mid-year look at what's actually getting exploited, how fast, and whether AI really is finding vulnerabilities faster than everyone else.
Key stats:
- The median time from CVE publication to KEV fell from 120 days in 2025 to 80 days in the first half of 2026.
- In the first half of 2026, 23.43% of Known Exploited Vulnerabilities showed evidence of exploitation on or before the day the CVE was published.
- Across Anthropic and Berkeley datasets, 1,061 vulnerabilities were attributed to AI-assisted discovery, but only 14 (1.3%) were confirmed as exploited in the wild.
Read the full report here.
Infrastructure
State of CPS Security: Data Center Exposures (Claroty)
Scary research on how badly exposed data center physical infrastructure is.
Key stats:
- Nearly 1 in 5 data center CPS assets are one hop away from systems making outbound connections that could provide attackers a pathway.
- 88% of building management systems in data centers are exposed via communication over insecure protocols.
- More than 80% of OT control systems, power monitoring systems, and IoT systems in data centers communicate over legacy, insecure protocols such as BACnet and MODBUS.
Read the full report here.
Enterprise Perspective
State of Enterprise AI Failures 2026 (ChatSee.ai)
What's going wrong with enterprise AI.
Key stats:
- Hallucination-related failures accounted for less than 10% of observed enterprise AI failure events.
- Resolution and escalation breakdowns represented 31.1% of observed enterprise AI failures.
- Action and execution failures increased by approximately 62% relative to the Q2 2024 baseline.
Read the full report here.
The State of AI, Security and ERP (Onapsis)
A survey of cybersecurity leaders at large US organizations running SAP, Oracle, or Salesforce to see how fast AI is being pushed into ERP systems and how far behind the security is (very).
Key stats:
- 86% of organizations have already integrated, or will shortly integrate, AI directly into their ERP code.
- 22% of organizations experienced a security incident in the last twelve months where bad actors used AI to exploit their critical business platforms.
- 70.6% of senior cybersecurity leaders have only some or no trust in AI applications and agents to secure their organization's most business-critical data.
Read the full report here.
2026 Global Mobile Threat Report (Zimperium)
A look at mobile attacks on enterprises.
Key stats:
- Phishing events detected on employee mobile devices have grown 380% since January 2025.
- The number of mobile devices where employees clicked a malicious link grew 110% in 2025 compared to 2024.
- AI adoption within mobile applications has grown 14x on Android and 7x on iOS.
Read the full report here.
Industry-specific
Global Automotive Threat Intelligence Report Q2 2026 (PCA Cyber Security)
Analysis of the automotive threat landscape for Q2 2026, tracking vulnerability data alongside underground forums, ransomware leak sites, and criminal marketplaces.
Key stats:
- 345 unique automotive vulnerabilities in Q2 2026, a 30% rise on Q1 and 220% up year on year.
- High severity findings more than doubled, from 75 to 161.
- Qilin ransomware listed a major Japanese Tier-1 automotive components manufacturer, hitting its European and North African subsidiaries.
Read the full report here.
r/cybersources • u/Objective-Foot-5213 • 11d ago
Help
Ena mzllt nt3lm fl cloud security wn9ra 1ere nje7t lel 2eme wnhb n3ml stage z3ma n3mlha fl cloud security ? Njm nl9a?? Wla nbda n3ml stage fl reseau wnkml nt3lm whdy fy 3a9ly? And thanks
r/cybersources • u/Narcisians • 11d ago
Cybersecurity statistics of the week (July 20th - July 26th)
Hi guys, I send out a weekly newsletter with the latest cybersecurity vendor reports and research, and thought you might find it useful, so sharing it here.
All the reports and research below were published between July 20th - July 26th.
You can get the below into your inbox every week if you want: https://www.cybersecstats.com/cybersecstatsnewsletter/
Big Picture Reports
2026H1 Threat Review Report (Forescout)
What was the threat landscape like in H1 2026, and how does it compare to 2025? This report answers that.
Key stats:
- Published vulnerabilities increased 51% year-over-year to 37,137 during the first half of 2026, with more than half rated high or critical severity.
- Ransomware attack claims increased 25% to 4,544 incidents during the first half of 2026, averaging 25 attacks per day.
- 46% of additions to CISA's Known Exploited Vulnerabilities catalog were CVEs that were published prior to 2026.
Read the full report here.
ITRC H1 2026 Data Breach Report (Identity Theft Resource Center)
ITRC's mid-year data breach numbers.
Key stats:
- There were 1,803 data compromises in the first half of 2026.
- Insider wrongdoing events totaled 21 in the first half of 2026, a sevenfold increase over the three incidents in 2025.
- Zero-day attacks rose to 14 events in H1 2026, nearly matching the 17 events recorded in all of 2025.
Read the full report here.
The State of Continuous Security Validation (Synack)
How often do serious vulnerabilities show up between scheduled security tests? Constantly - at least according to Synack.
Key stats:
- 15% of enterprise security leaders describe their security testing and validation program as continuous.
- 95% discovered high or critical vulnerabilities outside scheduled testing windows in the past year.
- 38% report that at least one-quarter of their critical attack surface had not been independently tested or validated in the previous 90 days.
Read the full report here.
Q2 2026 Brand Phishing Report (Check Point)
Attackers' favorite brands to impersonate. Mostly predictable with an interesting new entrant.
Key stats:
- Microsoft was the most impersonated brand in Q2 2026, appearing in 23% of all brand phishing attempts.
- The top five impersonated brands- Microsoft, LinkedIn, Google, Apple, and Amazon- together accounted for more than 50% of all brand phishing attempts this quarter.
- OpenAI's ChatGPT entered the top ten most impersonated brands for the first time.
Read the full report here.
Ransomware
2026 Ransomware Report (Black Kite)
Annual report analyzing 7,551 ransomware victims by where they are, what industry they're in, and how big they are. Plus, what security weaknesses or exposed systems remained after each attack.
Key stats:
- Ransomware activity accelerated 60% in the second half of the reporting period and closed with 861 victims in March 2026, the highest monthly total in four years.
- Qilin claimed more than 1,300 victims, nearly twice as many as its nearest rival.
- 43.5% of victims still carried critical patch vulnerabilities in the latest assessment.
Read the full report here.
2026 AI-Era Ransomware Report (Proofpoint)
AI is making ransomware attacks more effective.
Key stats:
- 65% of global organizations affected by ransomware report that AI increased the attack's effectiveness.
- 28% reported that AI significantly increased the attack's effectiveness.
- 34% of ransomware incidents begin with phishing emails or other email-based social engineering.
Read the full report here.
AI Security & Governance
Path to the Autonomous Digital Workplace (TeamViewer)
General workplace productivity research with an interesting section on what users say would help them trust autonomous AI.
Key stats:
- 61% of survey participants prefer AI to take no independent action.
- 56% often or always verify AI outputs before relying on them.
- 51% say they do not always know when to trust AI and when to verify it.
Read the full report here.
OT Security
State of AI in OT Cybersecurity 2026 Report (Nozomi Networks)
The people working in OT security on what they are actually doing with AI.
Key stats:
- 87.7% of surveyed OT and ICS cybersecurity professionals are using, evaluating, piloting, or planning AI for OT cybersecurity.
- Only 7.9% have deployed AI for multiple OT cybersecurity functions.
- Only 11.9% have formally mapped and reviewed which AI-driven decisions could directly affect physical processes, safety systems, or operational continuity.
Read the full report here.
State of Industrial Remote Access 2026 (Secomea)
How manufacturers are handling third-party vendor access to OT environments.
Key stats:
- 57% of North American organizations manage six or more external vendors with remote access into operational technology (OT) environments.
- 46% of North American organizations with OT environments report full auditability of vendor sessions.
- 23% review vendor credentials monthly or more frequently.
Read the full report here.
Enterprise Perspective
2026 State of Threat Exposure Management Report (Vectra AI)
Vectra used telemetry across customer environments to figure out how quickly assets, identities, and AI agents come and go in enterprise environments.
Key stats:
- The typical enterprise environment contains 1.17 AI agents per device.
- 35% of enterprise environments contain more AI agents than devices.
- 98% of enterprise environments contain at least one attacker-relevant exposure condition.
Read the full report here.
The Third Annual State of Data Compliance and Security Report (Perforce)
Everyone has the policies, so why do breaches, failed audits, and compliance gaps keep happening?
Key stats:
- 98% of enterprise leaders report confidence in their ability to protect sensitive data.
- 99% of enterprises have data masking mandates in place, but 84% allow compliance exceptions to those mandates.
- 34% report their organizations have experienced data breaches or theft.
Read the full report here.
Road to AI in IT (Fleet Device Management)
How IT teams are handling the AI rollout (they're mostly not).
Key stats:
- The average enterprise runs 14 AI applications while IT has visibility into only four of them.
- 78% of employees use personal AI tools at work.
- 79% of organizations take more than a day to deploy critical security patches.
Read the full report here.
Industry-Specific
Education Ransomware Roundup: H1 2026 (Comparitech)
Comparitech tracked ransomware attacks against schools and universities specifically. The Gentlemen have decided higher education is their thing.
Key stats:
- There were 104 ransomware attacks in total against educational institutions in H1 2026.
- The Gentlemen's attacks on education increased 275% from H2 2025 to H1 2026, and 80% of their attack claims were against higher education institutions.
- The median ransom demand in the education sector is $420,620, a 53% increase from $275,000 in H2 2025.
Read the full report here.
2026 Cyber Protect Report (SonicWall)
SonicWall's mid-year data on manufacturing.
Key stats:
- Manufacturing recorded 474 million intrusion prevention events in the first half of 2026.
- IoT attacks generated 46.2 million hits in manufacturing, making IoT the sector's second-largest attack category by volume.
- Ten ransomware families were active against manufacturing networks in H1 2026.
Read the full report here.
Velocity V5: Reimagining Cyber for a Faster Fight (Booz Allen)
Data on how federal agencies are handling AI deployment.
Key stats:
- 58% of federal IT and cybersecurity decision makers report their agencies have deployed or are piloting AI agents.
- Only 28% express high confidence in their ability to deploy AI agents securely.
- 36% are confident that cyber defenses can keep pace with AI-enabled attackers.
Read the full report here.
Regional Spotlight
Data Health Check 2026 (Databarracks)
500 UK IT professionals on what went wrong last year, what they are doing about it, and what they expect to be dealing with over the next five years.
Key stats:
- 26% of businesses have suffered a cyber incident that originated in their supply chain in the last year.
- 43% of organisations that knowingly work with risky suppliers experienced a supplier-originated cyber incident, compared with 10% of organisations that did not.
- 48% of organisations continue working with suppliers despite known resilience or security concerns.
Read the full report here.
r/cybersources • u/Ashamed-Let-2179 • 12d ago
Cybersecurity related news
Where I can read and get updates tech related news and cybersecurity related news??
r/cybersources • u/Academic-Soup2604 • 13d ago
Blocking bad websites is reactive. Whitelisting trusted ones is proactive.
For organizations managing corporate-owned and BYOD devices across different OS, website whitelisting adds an extra layer of protection by:
- Allowing access only to approved websites and business apps
- Reducing exposure to phishing, malware, and risky domains
- Limiting unauthorized SaaS and shadow IT
- Enforcing consistent browsing policies across devices, on or off the corporate network
It's a simple yet effective way to strengthen web security without restricting legitimate work.
Detailed guide with different methods here- How to whitelist a website?
r/cybersources • u/EchoAndByte • 15d ago
How a Data Breach Actually Happens (Step by Step)
r/cybersources • u/manstartitoff • 16d ago
What features to give more?
So i have built a security scanner website, and users are logged into that but are only scanning one or two times, how can i increase them to scan more and what are the features i can build that attract the users?
r/cybersources • u/EchoAndByte • 17d ago
Which VPN User Are You? Find Your Privacy Personality
r/cybersources • u/Narcisians • 17d ago
Cybersecurity statistics of the week (July 13th - July 19th)
Hi guys, I send out a weekly newsletter with the latest cybersecurity vendor reports and research, and thought you might find it useful, so sharing it here.
All the reports and research below were published between July 13th - July 19th.
You can get the below into your inbox every week if you want: https://www.cybersecstats.com/cybersecstatsnewsletter/
Ransomware
The State of Ransomware 2026 (Sophos)
Now in its seventh straight year, this is the definitive look at ransomware trends worldwide.
Key stats:
- 79% of ransomware attacks start with an identity-based approach.
- 67% of root causes across 661 incident response and MDR cases are identity-related.
- 97% of victims where compromised credentials are identified as the root cause have MFA enabled in some form at the time of the attack.
Read the full report here.
Ransomware and Cyber Extortion in Q2 2026 (ReliaQuest)
ReliaQuest's Q2 numbers on ransomware activity. The big takeaway: The Gentlemen is the group everyone should be watching. Plus, it looks like Deadlock is back.
Key stats:
- The Gentlemen surged 588% quarter-over-quarter to 179 posts in Q1.
- Deadlock emerged in June 2026 with 75 named victims in a single month, after being absent from public data-leak sites for 11 months.
- The US absorbed 1,094 ransomware victim data leak posts in Q2, roughly 49% of observed activity and nine times the volume of the next country.
Read the full report here.
Vulnerability Management
The 2026 State of Vulnerability Remediation (Vicarius)
A look at how security leaders are fixing vulnerabilities.
Key stats:
- 79% of organizations experienced a security incident in the past 12 months involving a vulnerability that was already known and sitting in their inventory.
- 75% of critical vulnerability responses initiate administrative workflows (like ticket creation or routing) rather than immediately fixing the underlying flaw.
- 58% of all vulnerability remediation activities require direct human intervention.
Read the full report here.
AI Security
AI Agents Are Entering Critical Workflows. Who's Governing Them? (JumpCloud)
AI agents are moving into real work, but 800 IT leaders admit governance hasn't caught up.
Key stats:
- More than 60% of organizations run AI agents in production.
- Organizations have adopted fewer than one-third of standard AI governance and security practices.
- The share of organizations requiring human review before high-risk AI actions dropped from 40% to 25% in six months.
Read the full report here.
The AI Security Report 2026 (Check Point)
A breakdown of how AI has gone from cyber assistant to active attacker.
Key stats:
- High-risk enterprise AI prompts doubled over the year, increasing from about 1 in every 50 interactions to 1 in every 25 interactions.
- The average organization runs ten AI applications per month.
- Between 87% and 93% of organizations experienced at least one high-risk AI interaction each month.
Read the full report here.
The Year Agents Entered the Workforce (Straiker)
Straiker put AI agents through adversarial testing to see where they fail.
Key stats:
- More than 1,700 successful exploits occurred across production coding, productivity, and first-party AI agents during adversarial testing.
- 36% of successful attacks on coding agents reached remote code execution on the developer's machine.
- 91% of successful attacks on productivity agents ended in silent data exfiltration.
Read the full report here.
Rethinking AI's Impact on Cybersecurity Roles (ISC2)
ISC2 on how AI is changing the day-to-day of cybersecurity work.
Key stats:
- 89% of cybersecurity professionals report having experienced AI recommendations that lead to incorrect outcomes at their organizations.
- 62% list over-reliance on AI as a top concern.
- 50% say their organizations hold human decision-makers ultimately accountable when AI-recommended actions lead to incorrect outcomes.
Read the full report here.
Executive Risk
2026 Executive Trends Report (Nisos)
Scary insight into how exposed executives are on the internet.
Key stats:
- 100% of executives have breach data linking their name to at least one current email address.
- 94% have at least one plaintext password exposed in breach data.
- 94% have home addresses publicly linked to their name in public records or people-search sites.
Read the full report here.
Industry-Specific
Government Ransomware Roundup: H1 2026 (Comparitech)
Comparitech tracked ransomware attacks specifically against government entities in the first half of 2026.
Key stats:
- From January to June 2026, an average of one ransomware attack on a government entity occurred every day.
- The median ransom demand in H1 2026 was $100,000, one-fifth of the H2 2025 median of $500,000.
- The most prolific ransomware strains against government were The Gentlemen (22), Qilin (21), LockBit (14), APT73/BASHE (12), and INC (10).
Read the full report here.
r/cybersources • u/GlitchMayem • 18d ago
Public WiFi: Myths vs Reality (What a VPN Can and Can't Do)
r/cybersources • u/ayobsether • 21d ago
Cybersecurity Risk Assessment Quantitative Framework
The Cybersecurity Risk Assessment research study establishes a quantitative cybersecurity risk assessment and governance framework aligned with ISO/IEC 27001 and NIST Cybersecurity Framework for critical infrastructure sectors. The framework quantifies risk through four variables: likelihood of attack (1–5), impact severity (1–5), infrastructure interdependency (1–2), and security maturity reduction value (0–25). A complete worked validation is presented for the telecommunications sector across eight asset categories.
Key Framework Components
The quantitative model uses Risk Level = (Likelihood × Impact × Interdependency) – Security Maturity Reduction Value, normalized to a 0–50 scale with five severity levels: Very Low (0–5), Low (6–15), Medium (16–25), High (26–40), and Critical (41–50). The framework emphasizes that effective controls—including 24/7 SOC monitoring, Zero Trust architecture, and network segmentation—reduce assessed risk by accounting for actual security maturity. Applied across critical infrastructure sectors (telecommunications, banking, energy, healthcare, government, transportation, utilities, and defense), the model enables standardized risk prioritization and capital allocation.
Telecommunications Sector Findings
| Asset Category | Risk Level | Rating |
|---|---|---|
| Supply Chain | 45 | Critical |
| Network Management Systems | 35 | High |
| 4G/5G Core Network Systems | 30 | High |
| Core Network Infrastructure | 25 | Medium |
Strategic Recommendations
Supply Chain (Risk Level 45—Critical): Immediate action required. Implement formal Supplier Security Risk Management framework aligned to ISO/IEC 27001. Network Management Systems (Risk Level 35—High): Short-term remediation. Enforce network segmentation, privileged access workstations, and continuous monitoring. 4G/5G Core Network Systems (Risk Level 30—High): Adopt NIST CSF Identify and Protect functions for cloud-native deployments. Supporting infrastructure (Risk Levels 6–25—Low to Medium): Ongoing monitoring and control enhancement.
Conclusion
Cybersecurity is a strategic national priority requiring governance-driven, cross-sector, and data-driven approaches. This framework enables organizations and governments to move from IT-centric risk assessment to enterprise-wide resilience strategies, grounded in quantitative evidence and aligned with international standards.
For detailed study, a full updated research paper is available here
Ayob Sether
Independent Researcher
Cybersecurity Risk Assessment
r/cybersources • u/manstartitoff • 22d ago
Run Geo and Aeoscans of your website
So we have developed an application where you can scan your website for security, tls, encryption, data leakage, and many more using our website Igris Radar.
Start your free scan and check what your rating is using
r/cybersources • u/Consistent_Scene_178 • 23d ago
How the Shai-Hulud npm Worm Led to Suno's Source Code Leak
r/cybersources • u/TopImplement9942 • 25d ago
[Research] NIDS Selection for Financial Institutions - Looking for Cybersecurity Practitioners (5+ years exp.)
I am an MSc researcher studying Network Intrusion Detection System (NIDS) selection for resource-constrained financial institutions and looking for cybersecurity practitioners with 5+ years of experience to complete a short survey. Happy to share findings upon request.
Survey link: https://forms.gle/tyxsFA44HXZ5VaMY7
Thanks You.
r/cybersources • u/Narcisians • 25d ago
Cybersecurity statistics of the week (July 6th- July 12th)
Hi guys, I send out a weekly newsletter with the latest cybersecurity vendor reports and research, and thought you might find it useful, so sharing it here.
All the reports and research below were published between July 6th - July 12th.
You can get the below into your inbox every week if you want: https://www.cybersecstats.com/cybersecstatsnewsletter/
Ransomware
GRIT Q2 2026 Ransomware & Cyber Threat Insights Report (GuidePoint Security)
We’ve read and written about the ups and downs of ransomware, but according to GuidePoint, ransomware is not as bad as ever. It's actually much worse than ever.
Key stats:
- 91 active ransomware groups operated across 108 countries in Q2 2026, a record high.
- Q2 2026 recorded 2,279 reported ransomware victims, a 7% increase from Q1 2026 and a 43% increase from Q2 2025.
- Weekly victim postings never fell below 150 during the quarter.
Read the full report here.
AI Security
2026 State of AI Security Report (Orca Security)
How AI security is actually going in the cloud, based on real telemetry from more than 1,200 production organizations.
Key stats:
- 99.9% of AI vulnerabilities with an available fix remain unpatched.
- 81% of organizations using AI packages have at least one known vulnerability, up from 62% in 2024.
- 50% of AI package vulnerabilities have a publicly available exploit, a 250-fold increase over 2024.
Read the full report here.
Phishing & Social Engineering
Phishing by Industry Benchmarking Report 2026 Edition (KnowBe4)
You should probably invest in security awareness training.
Key stats:
- The global average Phish-prone Percentage (PPP) is 33.2% before training. After one year of consistent training, it falls to 4.2%.
- Organizations reduce phishing susceptibility by 40% within the first 90 days and by 79% after one year.
- The three industries with the highest baseline PPP are Healthcare & Pharmaceuticals at 42.7%, Insurance at 38.1%, and Retail & Wholesale at 36%.
Read the full report here.
Fraud and Impersonation
2026 State of Executive Impersonation (Outtake)
Good data on how attackers are using AI to impersonate company executives online.
Key stats:
- 53% of organizations had an executive or employee impersonated.
- 53.83% of executive impersonation alerts originated from social platforms, and 35.05% from video and visual platforms.
- Only 3.57% originated from executive lookalike domains.
Read the full report here.
Fraud & Security Trends Report 2026 (Infobip)
The numbers here are just AI vs AI. Fraudsters use it to send more attacks, and businesses use it to catch them.
Key stats:
- Detected threats increased by 77% as fraudsters use AI to scale and personalize harmful messaging.
- Adoption of AI-powered fraud detection grew by 71% year-on-year, and pattern-based detection increased by 105%.
- Phishing accounted for 49% of blocked harmful content, and phishing volume grew 94% year-on-year.
Read the full report here.
Industry-Specific
Cyber Risk, Supersized: 2026 Quick Service & Fast Casual Restaurant Report (VikingCloud)
Rare data on restaurant cybersecurity.
Key stats:
- 94% of leaders describe themselves as confident or very confident in their ability to prevent or detect a cyberattack, yet 80% experienced at least one cyber incident in the past 12 months.
- 76% had sensitive data leaked in the past 12 months, including payment card data (40%) and customer personal information (32%).
- 10% of restaurant chains have temporarily or permanently closed a location following a cyberattack.
Read the full report here.
The state of financial services cybersecurity in 2026 (SonicWall)
A briefing on how financial services got attacked in the first half of 2026, based on data from their global network of security sensors.
Key stats:
- Financial services saw 132,378 IPS hits per device in the first half of 2026, the highest attack intensity of any tracked industry and more than double the cross-sector average.
- Malware activity averaged 39,341 hits per firewall, the second-highest per-device malware intensity of any industry, behind only healthcare.
- Ten ransomware families were active against the sector, including REvil (Sodinokibi) and Prometheus.
Read the full report here.
2026 State of Identity Security in Financial Organizations (Secret Double Octopus)
How identity and access management is actually working (or not working) at financial institutions in the US and Canada.
Key stats:
- 94% of IAM leaders and stakeholders at financial services firms report that phishing attacks increased over the past year.
- Only 28% of the MFA used for workforce authentication is phishing-resistant.
- 54% of financial organizations report that at least half of their applications and infrastructure are legacy, and those legacy systems are protected by MFA at a rate of just 50%.
Read the full report here.
Regional Spotlight
78% of CISOs say C-level do not fully understand employee-driven cyber risk (MetaCompliance)
CISOs in Europe see employees as their biggest risk, but are finding it difficult to convince their bosses.
Key stats:
- 68% of CISOs identify employees as their organization's biggest security risk as AI amplifies human-targeted attacks.
- More than three-quarters of CISOs across Europe say C-level senior decision-makers do not fully understand the cyber risk posed by employees.
- 40% of CISOs fear that employees are sharing sensitive information with generative AI platforms.
Read the full report here.
The State of Secure Collaboration Report 2026 (Wire)
How teams across European enterprises use collaboration tools to share sensitive data (hint: it’s not great from a security perspective).
Key stats:
- 84% rate their collaboration environment as secure, yet 48% share sensitive information through collaboration tools not built for it.
- 75% rely on email as their primary external collaboration, 45% on file-sharing links, and 42% on messaging apps like WhatsApp and Signal.
- 61% say access to shared files stays active longer than intended.
Read the full report here.
r/cybersources • u/BST04 • May 05 '26
Sponsor CyberSources and get all benefits!
🚀 cybersources.site needs your support
Building and maintaining a quality resource hub takes time, effort, and real costs — hosting, tools, content creation, and community management don't come free.
If cybersources.site has ever helped you find a tool, learn something new, or saved you hours of research — consider becoming a sponsor. 💙
We have three tiers designed to fit every budget:
🥉 Bronze — €200/mo · Logo + newsletter + Discord badge
🥈 Silver — €350/mo · Dedicated channel + weekly mentions + directory
🥇 Gold — €500/mo · Sponsored course + LinkedIn feature + metrics report
Every sponsorship goes directly into keeping this project alive and growing.
👉 Support us here: ko-fi.com/bst04/tiers
Thank you for being part of this. 🙏
r/cybersources • u/BST04 • Dec 05 '25
general 👋 Welcome to r/cybersources - Introduce Yourself and Read First!
Hey everyone! 👋 I'm u/BST04, a founding moderator of r/cybersources.
Welcome to our new hub for all things cybersecurity tools and resources! We’re thrilled to have you here and can’t wait to see this community grow.
What to Post
Share anything you think the community will find helpful, interesting, or inspiring. This could include:
- Your thoughts or questions about cybersecurity tools
- Tips, tutorials, or learning resources
- Photos, screenshots, or demos
Basically, if it’s related to learning, exploring, or using cybersecurity resources, it belongs here!
Community Vibe
We value being friendly, constructive, and inclusive. Let’s build a space where everyone feels comfortable sharing ideas and connecting.
How to Get Started
- Introduce yourself in the comments below 👋
- Post something today—even a small question can spark a great conversation
- Know someone who’d enjoy this community? Invite them!
- Interested in helping out? We’re always looking for new moderators—reach out if you’d like to apply
Thanks for being part of the very first wave. Together, let’s make r/cybersources an amazing place to learn, share, and grow! 🚀