Cybermatch
Cyber Attack Trends

Methodology version 1

How trends are ranked

Momentum, impact, and confidence are measured separately so a severe event is not automatically described as fast-rising.

Observed-activity momentum

50%

Growth in credible evidence of attacks or active exploitation.

Independent reporting momentum

25%

Growth in distinct evidence chains after citation and syndication deduplication.

Target expansion

15%

Newly affected industries, regions, organizations, or technologies.

Persistence

10%

Whether growth continues across multiple weekly observations.

Publication threshold

A trend requires two independent credible sources including an original report, or one authoritative source that explicitly confirms active exploitation or observed attacks.

Source policy

The source set prioritizes government advisories, national CERTs, original threat research, incident-response reporting, and reputable cybersecurity journalism.

Early Signals

Unconfirmed vulnerabilities and speculative developments remain separate and never affect the main attack ranking until the evidence threshold is met.

Editorial review

New trends, merges, contradictory evidence, material summary changes, and weekly email content receive human approval before publication.