The big shift: attackers want trust, not noise
Intrusion activity rose about 4% over the past year. That may sound modest, but the more interesting signal is where attackers are spending effort.
The report suggests adversaries are leaning into targeted campaigns that exploit trusted access paths and legitimate infrastructure. In plain English: fewer obvious break-ins, more abuse of systems that already belong in the environment.
That matters because many security stacks are still better at spotting malware than spotting misuse.
AI is now an attack accelerator
AI is helping attackers move faster across the whole chain. Not just writing bad emails.
According to the report, threat actors are using LLMs to generate:
- malware
- phishing emails
- reconnaissance commands
- scripts used after compromise
They’re also using AI to identify vulnerabilities, create proof-of-concept exploits, and compress the time between public disclosure and active exploitation.
The practical takeaway is simple: AI doesn’t need to invent a brand-new attack to be useful. It just needs to reduce friction. And it apparently does that very well.
This fits the broader pattern around frontier AI models accelerating both offensive and defensive timelines.
The scary part isn’t only malware. It’s AI service abuse.
One of the more useful insights here is that AI is not only helping attackers build attacks. AI platforms themselves are becoming targets.
The report describes attackers exploiting AI server software to steal sensitive configuration data and deploy crypto miners. It also highlights abuse of enterprise AI platforms in so-called LLMJacking attacks.
That term sounds slightly goofy. The problem is not.
In one incident, attackers reportedly gained administrative access to a cloud account and then sent nearly 200,000 LLM requests within two minutes, burning through AI resources at the victim’s expense. If your company treats AI access like a product feature rather than a security boundary, that kind of abuse gets expensive fast.
Vulnerability windows are shrinking
This is the part defenders hate: public proof-of-concept code now appears to function like an alarm clock for attackers.
Between January and June 2026, most observed exploitation tied to vulnerabilities with public PoC code happened within 48 hours of release, according to the report. Some groups moved within 24 hours of a critical web app vulnerability becoming public.
The lesson is no longer “patch quickly.” It is “assume attackers are already testing while your ticket is still being assigned.”
For teams evaluating security tools, this shifts value toward products and workflows that reduce response latency, not just improve visibility, especially when the gap to active exploitation keeps shrinking.
Developer ecosystems are now attack highways
If you want scale, go where software spreads itself.
That appears to be why package registries, CI/CD pipelines, container registries, and IDE extensions are getting so much attention from attackers. Compromise one point in the developer ecosystem, and you may gain a path into production systems, cloud environments, and customer networks.
The report says the npm registry accounted for 87% of malicious software packages identified during the reporting period. That is a giant flashing sign over the software supply chain.
It also notes that attackers hid malware in public software packages, allowing malicious code to flow downstream to large numbers of users. In other words, dependency risk is no longer a niche AppSec talking point. It is operational risk with distribution.
Why software supply chain attacks keep working
Supply chain attacks are attractive for the same reason phishing still exists: leverage.
An attacker who compromises a supplier, dependency, or build process may get:
- access to multiple customers at once
- trusted execution paths
- fewer immediate detection triggers
- a cleaner route into cloud credentials and secrets
The report identifies North Korea-linked STARDUST CHOLLIMA and the financially motivated ALTERED SPIDER as especially active in software supply chain activity. One campaign allegedly compromised more than 300 software dependencies in a single day.
That is not subtle. It is efficient.
Vishing is having a very bad renaissance
The fastest-growing attacks are not always the most technical. Sometimes they are just well-timed phone calls.
Vishing continues to gain ground because it exploits two things machines struggle to verify: urgency and politeness. Attackers impersonate IT support, push employees toward fake login pages, or get them to approve remote access through legitimate tools like Microsoft Quick Assist.
The trick works because the login is real enough and the software is legitimate enough. Traditional security tools can miss that when valid credentials are doing the damage.
CrowdStrike observed a major rise in vishing-linked intrusions, with activity accelerating further in the first half of 2026.
Trusted logins are becoming the attacker’s favorite weapon
There’s a pattern across vishing, device code phishing, cloud credential theft, and LLM abuse: attackers prefer authenticated access.
Why fight perimeter defenses when you can borrow someone’s identity?
Groups cited in the report used vishing to compromise single sign-on accounts and then move into Microsoft 365 and Google Workspace environments. In one case, attackers reportedly went from account takeover to data theft in under five minutes.
That timeline is the story. Once a trusted identity is compromised, the gap between access and impact gets very small.
Cloud credentials are under pressure
Cloud-focused cybercrime jumped sharply over the past year, driven by credential theft, crypto mining, AI service abuse, and theft attempts targeting digital assets.
That lines up with a broader market reality: cloud accounts now hold too much value to ignore. They contain workloads, tokens, secrets, APIs, data stores, and often a straight path to business-critical systems.
Attackers are especially interested in:
- cloud credentials
- API keys
- authentication tokens
- secrets stored in cloud services
The challenge is that these intrusions may look normal at first. If the attacker is using a valid account, you’re not hunting for “unauthorized login” so much as “authorized behavior that makes no sense.”
Device code phishing deserves more attention
One standout trend is device code phishing, which abuses a legitimate Microsoft authentication flow.
Attackers persuade users to authorize a malicious login through a trusted process. The experience feels familiar, which is exactly why it works.
The report says these attempts increased dramatically over the past six months. That makes device code phishing worth watching not just as a Microsoft issue, but as a design lesson: trusted workflows can become attack surfaces when users are trained to approve first and question later.
The target list still looks familiar
Technology remained the most targeted sector, which makes sense. It holds valuable IP and can serve as a bridge into software supply chains.
Financial services also saw increased intrusion activity, while universities and research institutions posted the largest sector increase in the report. Academic environments remain attractive because they combine valuable research with often complex, decentralized IT.
So yes, the targets are familiar. What’s changed is how attackers reach them.
What this means for AI tool buyers and operators
For AiToolsObserver readers, the interesting angle is not just “cyber risk is rising.” It’s how that changes the way AI tools should be evaluated.
If you’re comparing AI platforms, copilots, model gateways, developer tools, or cloud AI services, security questions can’t stay buried in the last tab of the buying process.
Look harder at whether a tool touches:
- identity systems and SSO
- API keys and secrets
- cloud account permissions
- package ecosystems and developer pipelines
- logging, monitoring, and abuse controls
- admin access to AI usage and spend
An AI tool can be useful and still expand your attack surface in awkward ways. Especially if it plugs into everything.
For teams comparing security tools, this is a reminder that capability alone is not the full evaluation.
The trend behind the trends
This report points to a broader market shift: attackers are optimizing for speed, legitimacy, and scale.
AI helps them move faster. Trusted identities help them look normal. Software supply chains help them spread. Cloud and AI services help them monetize access.
That combination changes what “good security” looks like. It’s less about building a taller wall and more about limiting trust, watching behavior, and assuming anything with credentials can be abused.
As debates continue around Open models and cyber defense, the underlying pressure on trust and speed remains the same.
A practical takeaway
If your team adopted AI faster than it upgraded identity, cloud, and developer security, you may have built a very efficient attack surface.
The smartest next move is not panic. It’s priorities.
Start with the paths attackers now seem to love most: trusted logins, cloud credentials, software dependencies, and AI platform access. Those are no longer edge cases. They’re the main road.
Comments (0) No comments yet
Want to join this discussion? Login or Register.
No comments yet. Be the first to share your thoughts!