Cynet Report Reveals Shift in Cyberattacks from Exploits to Identity Abuse

  • Cynet's 1H 2026 CyOps ECHO Report highlights an 80% increase in host breaches initiated through stolen identities.
  • Attackers are increasingly using socially engineered sessions via Microsoft Teams and remote-support tools like Quick Assist and AnyDesk.
  • SSL-VPN appliances accounted for 27% of host breaches, often allowing attackers to bypass initial detection.
  • Threat actors are weaponizing legitimate tools such as PowerShell and signed Windows binaries to evade detection.

Cynet's report underscores a broader industry trend where cybercriminals are shifting from traditional code exploitation to abusing trusted identities and tools. This strategic pivot highlights the need for organizations to prioritize identity management and edge security, as attackers increasingly leverage socially engineered sessions to bypass conventional defenses.

Identity Protection
How organizations will adapt to the rise of identity-based attacks through enhanced verification and authentication measures.
Edge Security
Whether security teams can effectively mitigate SSL-VPN vulnerabilities with regular patches and phishing-resistant MFA.
Tool Weaponization
The pace at which attackers will continue to exploit legitimate tools, necessitating behavioral visibility and continuous monitoring.