Threat activity intensified as APT36, Bearlyfy, Silver Fox, TA446, TeamPCP, and UNC1069 leaned into credential theft, social-engineering lures, and quiet persistence, with several groups mixing classic phishing with browser-based exploits and cloud-identity abuse. Major exploits hit Apple, F5, Cisco, SharePoint, and NetScaler, while DarkSword, DeepLoad, and GlassWorm represented significant escalations in mobile, AI-assisted, and supply-chain malware.