Threat activity spiked as APT36, TA446, and UNC1069 leaned into credential theft and cloud-identity abuse, while Bearlyfy escalated politically driven ransomware. Silver Fox and TeamPCP pushed opportunistic access and data theft, and major exploits hit Apple, F5, Cisco, SharePoint, and NetScaler. Priorities for defenders include identity hardening, rapid patching, and post-compromise hunting.