May 22, 2026 - Summary of persistent and high‑impact cyber risks: ransomware and extortion, supply‑chain compromise, AI‑augmented social engineering and identity‑centric attacks. Prioritize asset inventory, identity hardening, accelerated patching and tested immutable backups.

Current cyber security incidents

Note: I do not have live web access to pull the last seven days of telemetry. This report synthesizes persistent, high‑impact trends observed through mid‑2024 and extrapolates likely continuations; validate time‑sensitive details against current threat intelligence feeds and incident reports before operational changes.

Based on these continuing patterns, the dominant incident types remain ransomware and data‑extortion operations, often succeeding after initial access via third‑party compromise or exploited internet‑facing services. Supply‑chain intrusions and attacks against managed service providers continue to generate large blast radii, and high‑impact data theft followed by public extortion remains a frequent adversary aim. Concurrently, business email compromise and targeted fraud continue to cause direct financial loss, while state‑sponsored and hacktivist activity persistently target critical infrastructure and strategically important sectors.

Current attack methods and trends

Adversaries are increasingly professionalized: Initial‑Access Brokers and Ransomware‑as‑a‑Service reduce technical barriers, allowing a wider set of operators to mount disruptive campaigns. Social engineering has been scaled and refined through automation and generative AI, producing more convincing phishing and vishing lures; at the same time, credential stuffing and purchased credentials remain common paths to account takeover. Operators blend automated mass techniques with bespoke follow‑on exploitation to reach high‑value targets.

Technically, identity and cloud paths are prioritized over noisy network exploitation. Attackers exploit leaked credentials, OAuth consent abuse, stolen session tokens and MFA fatigue techniques to gain persistent access to SaaS and cloud environments. Living‑off‑the‑land techniques and fileless toolchains are routinely used to evade detection and complicate forensic analysis, while attackers increasingly target CI/CD pipelines, container runtimes and package repositories to weaponize the software supply chain.

Important CVEs and exploits (selection)

Some legacy and recently disclosed vulnerabilities continue to drive intrusions because of ubiquity and slow patching. Apache Log4j’s Log4Shell (CVE‑2021‑44228) remains a direct‑execution risk in many environments; Microsoft Office ‘Follina’ (CVE‑2022‑30190) is an enduring document‑delivered RCE vector; and ZeroLogon (CVE‑2020‑1472) still enables rapid domain compromise when domain controllers are unpatched. Historical Exchange server exploit chains (commonly known as ProxyLogon/ProxyShell) are also frequently leveraged where systems remain exposed.

Beyond specific CVEs, notable exploited classes include vulnerabilities in remote‑access and VPN appliances (e.g., FortiOS path traversal issues), zero‑days in widely deployed endpoint and cloud management agents, and logic flaws in SaaS integrations and file‑transfer platforms that have led to broad data exfiltration campaigns. Attackers are also exploiting indirect dependencies — open‑source libraries, CI/CD secrets and third‑party connectors — so defenders must prioritize both direct exposures and the upstream supply chain.

Greatest risks for companies

The primary business risk is identity compromise: once credentials, tokens or consented OAuth access are obtained, attackers can bypass perimeter controls, escalate privileges and access cloud resources and sensitive data stealthily. Organizations that lack complete asset inventories or maintain over‑permissive IAM policies face the highest impact from such compromises, because attackers can move laterally and escalate to domain or tenant level access.

Secondary risks include unpatched internet‑facing infrastructure, insufficiently protected backups (non‑immutable or untested), and immature detection and response capabilities that allow long dwell times. Third‑party and supply‑chain dependencies magnify these risks; a single compromised vendor or CI/CD pipeline can convert a localized vulnerability into a multi‑tenant breach with regulatory, operational and reputational consequences.

Recommendations

Immediate priorities are to inventory internet‑exposed assets and SaaS integrations and to accelerate remediation or virtual patching for known exploited components; strengthen identity hygiene by deploying phishing‑resistant MFA, rotating and constraining privileged credentials, monitoring for anomalous OAuth and token activity and applying conditional access policies; ensure backups are immutable, segregated and regularly tested for recovery; expand detection coverage across endpoints, cloud logs and network telemetry and develop hunt workflows focused on living‑off‑the‑land and token‑based persistence; and update incident response plans and tabletop exercises to cover ransomware/extortion and supply‑chain compromise scenarios while integrating timely threat intelligence for prioritization of patching and third‑party risk mitigation.