[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fZquKZjMUX60FJrisAtgxURie7goqCxS6PJWKRe7077E":3},{"article":4,"iocs":39,"watch_terms":59},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":18,"category":19,"article_tags":23},"ad8d2245-f4c9-4a4d-be30-7482a5279b66","Anatomy of a Cyber World Global Report 2026","anatomy-of-a-cyber-world-global-report-2026","The Kaspersky Security Services report describes cyberattack trends and statistics revealed by the Managed Detection and Response service. The report also includes Incident Response findings based on real-world cases identified and mitigated in 2025.","Kaspersky's annual Anatomy of a Cyber World Global Report 2026 analyzes threat data from Managed Detection and Response and Incident Response services, covering approximately 400,000 alerts and 39,000 investigated incidents in 2025. Key findings show high-severity incidents declining since 2021, Microsoft product vulnerabilities dominating exploitations, and trusted relationship attacks growing to 15.5% of attack vectors. The report identifies PowerShell, rundll32, and mshta as top living-off-the-land binaries, with Mimikatz and PsExec among the most exploited legitimate tools.","Kaspersky 2026 Global Report reveals cyberattack trends from MDR\u002FIR services covering 2025 incidents.","Table of Contents The scope of MDR and IR servicesMDR telemetryIncident statisticsKey trends and statistics Authors Kaspersky Security Services Kaspersky Security Services provide a comprehensive cybersecurity ecosystem, taking enterprise threat protection to another level. Services like Kaspersky Managed Detection and Response and Compromise Assessment allow for timely detection of threats and cyberattacks. SOC Consulting provides a practical approach ensuring the corporate infrastructure stays secured, while Incident Response is suited for timely remediation with a maximized recovery rate. High-level overview of the MDR, IR and CA connection This new report brings together statistics across regions and industries from our Managed Detection and Response and Incident Response services, and for the first time, it also includes insights from our Compromise Assessment and SOC Consulting services — all to provide you with more comprehensive view of different aspects of corporate information security worldwide. The scope of MDR and IR services Provision of Kaspersky’s MDR and IR services follows a global approach. The majority of customers accounted for the CIS (34.7%), the Middle East (20.1%), and Europe (18.6%). Distribution of customers by geographical region, 2025 MDR telemetry Following the previous year’s numbers, in 2025, the MDR infrastructure received and processed an average of 15,000 telemetry events per host every day, generating security alerts as a result. These alerts are first processed by AI-powered detection logic, after which Kaspersky SOC analysts handle them as required. Overall, a total of approximately 400,000 alerts were generated in 2025. After counting out false positives, 39,000 alerts were further investigated. MDR telemetry statistics, 2025 Incident statistics The distribution of remediation requests by industry has slightly changed as compared to previous years’ pattern. Government (18.5%) and industrial (16.6%) organizations are still the most targeted industries in regards to cyberattacks that require incident response activities. However, this year, the IT sector saw a growth in the number of IR requests, eventually being placed third in the overall industry distribution rankings and thus replacing financial organizations, which were targeted less often than in 2024. This is equally true for smaller-scale attacks that can be contained and remediated through automated means — the only difference is that medium- and low-severity incidents are more often experienced by financial organizations. Distribution of all incidents by industry sector, 2025 Key trends and statistics This section presents key findings and trends in cyberattacks in 2025: The number of high-severity incidents decreased, following a downward trend that we’ve been observing since 2021. The majority of those incidents account for APT attacks and red teaming exercises, which indicates two landscape trends. On the one hand, skilled adversaries make efforts to increase impact, while on the other, organizations spend more resources on probing their defense systems. The most common vulnerabilities exploited in the wild were related to Microsoft products. Half of all identified CVEs led to remote code execution, notably without authentication in some cases. Exploitation of public-facing applications, valid accounts, and trusted relationships remain the most popular initial vectors, and their overall share has increased, accounting to over 80% of all attacks in 2025. In particular, attacks through trusted relationships are evolving: their share has increased to 15.5% from 12.8% in 2024. They are also becoming more complex: for instance, we witnessed a case where adversaries had compromised more than two organizations in sequence to ultimately gain access to a third target. Standard Windows utilities remain a popular LotL tool. Adversaries use those to minimize the risk of detection during delivery to a compromised system. The most popular LOLBins we observed in high-severity incidents were powershell.exe (14.4%), rundll32.exe (5.9%), and mshta.exe (3.8%). Among the most popular legitimate tools used in incidents we flag Mimikatz (14.3%), PowerShell (8.1%), PsExec (7.5%), and AnyDesk (7.5%). The full 2026 Global Report provides additional information about cyberattacks, including real-world cases discovered by Kaspersky experts. We also describe SOC Consulting projects and Compromise Assessment requests. The report includes comprehensive analysis of initial attack vectors in correlation with the MITRE ATT&CK tactics and techniques and the full list of vulnerabilities that we detected during Incident Response engagements. Industrial threats MDR SOC Security services Incident response Cybersecurity Trusted relationship attack Mitre ATT&CK Compromise assessment AI CVE Anatomy of a Cyber World Global Report 2026 This site uses Akismet to reduce spam. Learn how your comment data is processed. Table of Contents The scope of MDR and IR servicesMDR telemetryIncident statisticsKey trends and statistics GReAT webinars From the same authors In the same category","https:\u002F\u002Fsecurelist.com\u002Fglobal-report-security-services-2026\u002F119233\u002F","https:\u002F\u002Fmedia.kasperskycontenthub.com\u002Fwp-content\u002Fuploads\u002Fsites\u002F43\u002F2026\u002F03\u002F25102423\u002Fglobal-report-featured-image.png","2026-03-25T11:00:56+00:00","2026-03-25T13:00:22.548308+00:00",7,[],"e7b231c8-5f79-4465-8d38-1ef13aea5a14",{"id":18,"icon":20,"name":21,"slug":22},null,"Threat Intelligence","threat-intelligence",[24,29,34],{"category":25},{"id":26,"icon":20,"name":27,"slug":28},"80544778-fabb-4dcd-aa35-17492e5dcf4f","Vulnerabilities","vulnerabilities",{"category":30},{"id":31,"icon":20,"name":32,"slug":33},"89f78b1c-3503-45a1-9fc7-e23d2ce1c6d5","Malware","malware",{"category":35},{"id":36,"icon":20,"name":37,"slug":38},"c5eccf7c-abbc-4bd3-bbed-e6da5cba8e73","Incident Response","incident-response",[40,44,47,50,53,56],{"type":41,"value":42,"context":43},"mitre_attack","T1566 (Phishing)","Exploitation of public-facing applications and trusted relationships as initial attack vectors",{"type":41,"value":45,"context":46},"T1059.001 (PowerShell)","Most common LOLBin in high-severity incidents (14.4%)",{"type":41,"value":48,"context":49},"T1218.011 (rundll32)","Second most popular LOLBin (5.9%)",{"type":41,"value":51,"context":52},"T1218.005 (mshta.exe)","Third most popular LOLBin (3.8%)",{"type":33,"value":54,"context":55},"Mimikatz","Most popular legitimate tool used in high-severity incidents (14.3%)",{"type":33,"value":57,"context":58},"PsExec","Lateral movement tool used in 7.5% of incidents",[]]