COMMENTARY: We had a lot of predictions in place at the start of 2026, most of which have come to fruition. But in several cases, reality moved even faster than we expected.
The biggest change we have seen so far in 2026 was not a single new attack technique. It’s the way several trends have come together. AI now helps attackers move much faster than before, identities are becoming more important than malware, and legitimate tools and trusted platforms are increasingly becoming the attack path themselves.
Cybercriminals gained a tactical advantage with AI
Our prediction that attackers would gain a tactical advantage from AI was confirmed and, in some areas, even exceeded.
[SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Read more Perspectives here.]
We saw AI helping to reduce the time and effort required to turn vulnerabilities into working attacks. The Copy Fail Linux kernel vulnerability, for example, generated more than 140 public exploit variants within weeks. Many were based on AI-assisted modifications of the original proof of concept. At the same time, AI-assisted security research has been finding vulnerabilities at a scale that would have been very difficult to achieve manually. Project Glasswing, using Claude Mythos, reported more than 10,000 high- and critical-severity vulnerability findings during its early deployments.
But this was not the part of the prediction that surprised me the most.
AI infrastructure itself has become an attack surface. MCP servers, LLM gateways, and other components connecting AI agents to enterprise systems increasingly have access to credentials, data and business applications. One exposed MCP setup, used in AI-assisted intrusion activity, contained more than 1,000 operational files: firewall configurations, credential dumps, vulnerability scanning templates and attack planning data.
We should therefore stop thinking about AI only as a tool attackers might use. AI systems are becoming infrastructure that we need to secure.
Vishing, deepfakes, and identity deception went mainstream
Attackers often impersonate someone the victim trusts, an employee, a helpdesk operator, a supplier or another legitimate user. Deepfakes and voice impersonation make this easier, but the underlying techniques are not new. The scale and quality of the deception has changed.
Today, attackers often don't need malware if they can obtain valid credentials and legitimate access.
The exploitation of the Oracle PeopleSoft vulnerability represents a useful example of the broader trend. Exploitation attributed to ShinyHunters affected more than 100 organizations, showing how quickly a widely-deployed enterprise platform can become an attractive attack path.
That’s why identity has become such an important part of the threat landscape. Once an attacker operates with legitimate credentials, distinguishing malicious activity from normal business activity becomes much harder.
Legitimate software became part of the attack chain
The definition of abusing legitimate software has changed. It’s no longer just about an attacker using PowerShell, remote-management software or another legitimate tool to avoid detection. We are increasingly seeing the platforms that organizations rely on every day, identity systems, device-management platforms, developer tools and CI/CD pipelines, being repurposed as part of the attack itself. During H1, campaigns associated with TeamPCP targeted GitHub Actions, npm, PyPI, Docker Hub, Visual Studio Code extensions and other developer infrastructure.
That creates a quite challenging problem for defenders. Blocking the tool is not necessarily an option because the organization needs it. And the attackers don’t need to bring their own tools, they can use ours.
The same applies to the software supply chain. If an attacker compromises a developer credential, publishing workflow or package repository, they can potentially turn trusted infrastructure into a distribution mechanism.
What comes next?
Looking ahead, security teams should focus less on individual attack techniques and more on where trust gets concentrated within the enterprise.
The predictions for 2026 largely came true. But the more important lesson gleaned from the first half of 2026: these trends are no longer happening independently. AI, identity, trusted software, and cloud infrastructure are increasingly part of the same attack chain. And that makes the next phase of the threat landscape particularly interesting. My updated predictions as we enter Q4 include:
- AI will become another enterprise security discipline, rather than a separate technology discussion.
- Identity will remain one of the primary attack surfaces.
- Trusted platforms will continue to attract attackers precisely because organizations cannot simply switch them off.
- The window between vulnerability disclosure and exploitation will continue to shrink.
The practical implication for all of us: security teams need visibility beyond endpoints and traditional network boundaries. They need to understand which identities have access to critical systems, what their trusted third parties can do, how software moves through the development pipeline, and where AI agents are connected to enterprise data.
Sergey Novikov, director of cybersecurity content, CyberProof
SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Each contribution has a goal of bringing a unique voice to important cybersecurity topics. Content strives to be of the highest quality, objective and non-commercial.