Acronis Threat Research Unit (TRU) has published Cyberthreats Update for July 2026, a global threat report based on telemetry from more than one million unique endpoint devices worldwide. The report shows that the global cyber threat landscape continues to be intense, despite a slight decline in malware detections in June.
Critical Oracle vulnerability took center stage
The most high-profile incident during the month was the critical zero-day vulnerability CVE-2026-35273 in Oracle PeopleSoft PeopleTools.
The vulnerability allowed attackers to execute code remotely without authentication and was actively exploited before Oracle had time to issue security updates. According to Acronis, the attacks were linked to the ransomware group ShinyHunters, which reportedly compromised around 300 PeopleSoft installations at more than 100 organizations. Universities and other educational institutions, where sensitive student, financial and staff data is handled, were particularly hard hit.
Oracle recommends that all affected organizations immediately install the security updates and conduct a full audit of their environments to ensure that attackers have not established long-term access.
Malware decreased slightly, but the threat level remains high
In June, Acronis blocked malware on 6.0 percent of the monitored endpoint devices, a slight decrease from 6.2 percent in May.
Despite the positive development, the level is still significantly higher than at the beginning of the year and represents the fourth highest monthly level during the analyzed period. The report thus shows that cybercriminal activity is still at a historically high level.
Countries with the most malware detections
The three countries that recorded the highest percentage of malware detections in June were:
- Palestine, 42.6 percent
- Vietnam, 32.1 percent
- Iraq, 31.4 percent
Palestine and Vietnam recorded a slight decline compared to the previous month, while Iraq saw a clear increase. Despite the changes, all three countries maintained their positions at the top of the statistics.
Phishing and malicious URLs continue to increase
URL-based attacks and phishing campaigns continue to be one of the most common attack methods.
The highest levels were recorded in:
- Colombia
- India
- USA
- Brazil
- Mexico
At the same time, clear decreases were noted in New Zealand and Singapore, among others, which contributed to a somewhat more stable global development compared to previous months.
Data breaches and ransomware continue to dominate
Acronis notes that over 705 publicly reported data breaches was registered in June.
Meanwhile, ransomware groups continue to target both private and public organizations. The combination of data theft, extortion, and exploitation of critical vulnerabilities shows that attackers are increasingly focusing on organizations where downtime and information loss have major financial consequences.
Acronis recommends multi-layered protection
To reduce the risk of intrusion, Acronis recommends a security approach that is based on multiple layers of protection.
Among the most important measures, the company highlights:
- AI and behavior-based threat detection
- Ransomware protection
- Email security and URL filtering
- XDR for monitoring and incident management
- Fast installation of security updates
- Control over the use of generative AI services to reduce the risk of data leakage
Acronis emphasizes that modern cyberattacks are becoming increasingly sophisticated and that organizations need to combine preventive security efforts with continuous monitoring and rapid response to reduce the consequences of future attacks.








