In the first quarter of 2026, the overall percentage of industrial control systems (ICS) computers experiencing malware infections continued its downward trend, reaching a three-year low. However, certain regions and industries, particularly biometric systems and manufacturing, saw increases in specific threat categories like spyware and internet-based threats. While ransomware and malicious documents saw significant decreases, malicious scripts, phishing pages, and denylisted internet resources remained prevalent.

The first quarter of 2026 saw a continued decline in the overall percentage of industrial control systems (ICS) computers affected by malicious objects, hitting a low of 19.6%. This marks the lowest figure in three years, a significant decrease from previous periods. Regionally, Northern Europe reported the lowest infection rate at 9.1%, while Africa experienced the highest at 27.4%. Despite the overall downward trend, five regions, including Southern Europe, Northern Europe, and Russia, observed an increase in blocked malicious objects. Southern Europe, in particular, saw notable growth in internet and email threats, as well as spyware and phishing pages.
Biometric systems consistently ranked highest among industries for ICS computer infections, with 26.4% of systems affected. This vulnerability is attributed to their internet connectivity, extensive email usage for data exchange, and often minimal cybersecurity controls. Biometric systems also led in email threats, surpassing internet threats, a unique characteristic compared to other industries. While most industries followed the global downward trend, the manufacturing sector experienced a slight increase of 1.0 percentage point in infections, with notable rises in Western Europe, Northern Europe, and Russia.
Kaspersky security solutions blocked malware from over 10,000 families on ICS in Q1 2026. Denylisted internet resources saw an increase after a prior decline, alongside a slight rise in AutoCAD malware. Malicious scripts and phishing pages remained a significant threat category, with a global average of 6.56% of ICS computers affected. Southern Europe showed the most substantial increase in these threats. Biometric and building automation systems, particularly in Southern Europe, recorded the highest percentages for malicious scripts and phishing pages.
Spyware, despite a recent decline to 3.73%, maintained its position as the second-highest threat category. Increases in spyware infections were observed in Southern Europe and Russia, affecting most industries except manufacturing in Southern Europe and construction in Russia. The oil and gas industry, along with engineering and ICS integration sectors, have seen consistent increases in spyware over the past six months and three quarters, respectively.
Denylisted internet resources saw an increase to 3.54%, with Southeast Asia experiencing the most significant rise. Electric power and construction industries in Southeast Asia reported the highest percentages for this threat. North America also noted a substantial increase in denylisted internet resources. Malicious documents, including Microsoft Office and PDF threats, reached a record low of 1.56%, with only Australia/New Zealand and Russia showing slight increases. Ransomware infections also dropped to a low of 0.14%, with minimal increases reported in North America and Northern Europe.
Miners in the form of executable files for Windows decreased to 0.59%, though several regions, including Africa, saw increases. Construction, biometric systems, and the oil and gas industry in Central Asia and the South Caucasus reported the highest percentages for these miners. Web miners continued their year-long decline, reaching 0.22%, but saw increases in South Asia, the Middle East, and Africa. Worm infections decreased to 1.33% across all regions, following a previous increase attributed to a widespread backdoor worm. Biometric systems in Central Asia and the South Caucasus reported the highest percentage for worms.

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.