Black Lotus Labs is the threat intelligence and research arm of Lumen Technologies. The team specializes in tracking, analyzing and disrupting advanced cyberthreats across the global internet.
Black Lotus Labs leverages one of the world's largest and most deeply peered fiber networks to observe malicious activity at scale, then performs advanced analytics and hands-on research to help you stay ahead of evolving threats.
Most threat reports analyze attacks after they hit an organization. This report focuses on how attacks are built upstream—before a single organization is targeted. That visibility differs the value of the report from a breach catalog to an early‑warning view of how modern attacks are staged.
The report is designed for security leaders and their operational team—from CISOs and SOC Directors to analysts and threat hunters—who need to understand how the threat landscape is changing, not just which malware families are popular.
The Lumen Threatscape Report helps security leaders move from reacting to breaches to disrupting attacks before they begin. The report reveals how threat actors use generative AI to build and rotate infrastructure—targeting edge devices, proxy networks and internet-based services long before impact.
Our global network visibility and advanced threat intelligence help you identify malicious infrastructure early and stop threats before they reach your environment. Block malicious traffic and mitigate attacks at the network edge with Lumen Defender℠, Lumen® DDoS Mitigation Service and other Lumen® Adaptive Network Security.
1 The Center for Applied Internet Data Analysis (CAIDA), AS rank, January 2025.