KELA Research Center

Recent Research

2026 AI Threat Landscape Report

2026 AI Threat Landscape Report

KELA REPORT 2026 AI Threat Landscape:Offensive AI Has Gone Autonomous   From assistant to operator — the agentic shift already rewriting the threat landscape In 2026, AI stopped waiting for instructions.Autonomous, goal-directed agents now run intrusions end to end — finding vulnerabilities, writing exploits, hijacking sessions, and moving laterally at machine speed. Drawing on KELA’s…

Get Report: 2026 AI Threat Landscape Report
The State of Cybercrime 2026: STRATEGIC REPORT

The State of Cybercrime 2026: STRATEGIC REPORT

KELA REPORT The State of Cybercrime 2026: STRATEGIC REPORT Ground-truth intelligence from the KELA Cyber Intelligence Center on the threats that redefined 2025 and will dictate 2026 and beyond. 2025 was marked by the industrialization of zero-day exploits and the rise of high-velocity extortion. This retrospective provides the raw data and expert analysis required to…

Get Report: The State of Cybercrime 2026: STRATEGIC REPORT
OpenClaw Threat Assessment

OpenClaw Threat Assessment

KELA REPORT OpenClaw or OpenFlaw? The Essential Threat Assessment of the Agentic AI Ecosystem       Has your “productivity assistant” become a searchable entry point for global threat actors? The rapid transition from passive chat interfaces to autonomous OpenClaw agents has created a hyper-connected attack surface where a single compromise grants adversaries a persistent,…

Get Report: OpenClaw Threat Assessment
Alleged Knownsec Data Leak

Alleged Knownsec Data Leak

KELA REPORT Alleged Knownsec Data Leak Unmasking the convergence of commercial innovation and state-sponsored cyber espionage in China. In late October 2025, a significant data leak allegedly exposed the internal operations of Knownsec, one of China’s leading cybersecurity firms. This research report analyzes the 12,000+ file dataset to reveal a company operating under a “civil-military…

Get Report: Alleged Knownsec Data Leak
The Rise of macOS Infostealers: 2025 in Review

The Rise of macOS Infostealers: 2025 in Review

KELA REPORT The Rise of macOS Infostealers: 2025 in Review As Apple’s enterprise footprint expands, macOS has become an increasingly attractive target for threat actors. This report traces the rapid professionalization of macOS infostealers—fueled by Malware-as-a-Service (MaaS)—and shows how stolen credentials, cookies, and tokens translate into sellable corporate access. In KELA’s new report, you’ll learn:…

Get Report: The Rise of macOS Infostealers: 2025 in Review
Escalating Ransomware Threats to National Security

Escalating Ransomware Threats to National Security

REPORT EscalatingRansomware Threats to National Security A Rising Scale of Attacks on Critical Infrastructure Sectors In KELA’s new report, you’ll learn: Ransomware has evolved from an enterprise risk into a strategic national security threat. Once driven primarily by profit, it is now leveraged by organized cybercriminals and state-linked actors to disrupt critical infrastructure, destabilize economies,…

Get Report: Escalating Ransomware Threats to National Security
2025 Midyear Threat Report: Evolving Tactics and Emerging Dangers

2025 Midyear Threat Report: Evolving Tactics and Emerging Dangers

KELA REPORT 2025 Midyear Threat Report: Evolving Tactics and Emerging Dangers A Guide to Prepare for the Growing Threats of Hacktivists, Infostealers, Ransomware and More This report features critical data, real-world examples, and actionable recommendations to help organizations protect themselves against the growing complexity of cyber threats arising from geopolitical tensions to multi-extortion ransomware campaigns.…

Get Report: 2025 Midyear Threat Report: Evolving Tactics and Emerging Dangers
Unveiling Black Basta’s Use of PhaaS Platforms Report

Unveiling Black Basta’s Use of PhaaS Platforms Report

KELA REPORT Unveiling Black Basta’s Use of PhaaS Platforms How Top-Tier Ransomware Relies on External Phishing Services. A new investigation by KELA reveals how ransomware operators like Black Basta rely on professionalized Phishing-as-a-Service (PhaaS) offerings to scale their initial access operations. Based on leaked internal chats, the report exposes how these underground services play a…

Get Report: Unveiling Black Basta’s Use of PhaaS Platforms Report
Beyond the Perimeter: Strengthening Security with External Risk Management

Beyond the Perimeter: Strengthening Security with External Risk Management

INDUSTRY REPORT Beyond the Perimeter: Strengthening Security with External Risk Management Frost & Sullivan provides a guide on how to enhance threat visibility, response and resilience in an evolving cyber landscape. As cloud adoption, IoT, and remote work continue to expand the attack surface, many organizations are focusing inward – relying on EDR, firewalls, and…

Get Report: Beyond the Perimeter: Strengthening Security with External Risk Management
Inside the Infostealer Epidemic: Exposing the Risks to Corporate Security Report

Inside the Infostealer Epidemic: Exposing the Risks to Corporate Security Report

KELA REPORT Inside the Infostealer Epidemic: Exposing the Risks to Corporate Security How stolen credentials are fueling ransomware, fraud, and modern cybercrime With infostealer infections surging by 266% in recent years and attackers shifting to automated, subscription-based marketplaces, the cybercrime ecosystem is evolving rapidly – and becoming harder to stop. In this report, KELA analyzes…

Get Report: Inside the Infostealer Epidemic: Exposing the Risks to Corporate Security Report