The market moved.
See where your sector moved with it.
180-day snapshot of publicly disclosed incidents, exploited vulnerabilities and disclosure patterns.
Biggest shifts
Latest 30 days against the prior 30.
- 1+300%
- 2+150%
- 3+63%
Sector benchmark
Baseline = 100 (90-day daily rate). Activity is not a probability of breach.
| Rank | Sector | Activity index | Current | Vs 90D rate | Dominant public class | 2+ source domains |
|---|---|---|---|---|---|---|
| 1 | 100 | 215 | +115% | Supply chain / third party | 27% | |
| 2 | 100 | 176 | +76% | Data breach / intrusion | 22% | |
| 3 | 100 | 163 | +63% | Protocol exploit | 39% | |
| 4 | 100 | 100 | 0% | Supply chain / third party | 50% | |
| 5 | 100 | 74 | -26% | Cause not publicly established | 20% |
Read the signal, then read its limits.
Radar describes the public dataset—not the full market and not a company risk score.
What counts as an incident?
An accepted, deduplicated event unit supported by public reporting. Confirmed and probable events stay separate from unverified claims.
Which date drives the tape?
Disclosure date. The actual event date is often missing, approximate or published later, so it remains a separate dossier field.
What does the snapshot miss?
Undisclosed events, sources outside the collector, classification uncertainty and publication bias. Counts describe the dataset, not all cyber activity.
How fresh is this view?
Dataset 2026-ytd-clean-v1, generated Aug 27, 2026. Daily collection comes after interface validation.