Cynet Report Reveals Shift in Cyberattacks from Exploits to Identity Abuse
Event summary
- Cynet's 1H 2026 CyOps ECHO Report highlights an 80% increase in host breaches initiated through stolen identities.
- Attackers are increasingly using socially engineered sessions via Microsoft Teams and remote-support tools like Quick Assist and AnyDesk.
- SSL-VPN appliances accounted for 27% of host breaches, often allowing attackers to bypass initial detection.
- Threat actors are weaponizing legitimate tools such as PowerShell and signed Windows binaries to evade detection.
The big picture
Cynet's report underscores a broader industry trend where cybercriminals are shifting from traditional code exploitation to abusing trusted identities and tools. This strategic pivot highlights the need for organizations to prioritize identity management and edge security, as attackers increasingly leverage socially engineered sessions to bypass conventional defenses.
What we're watching
- Identity Protection
- How organizations will adapt to the rise of identity-based attacks through enhanced verification and authentication measures.
- Edge Security
- Whether security teams can effectively mitigate SSL-VPN vulnerabilities with regular patches and phishing-resistant MFA.
- Tool Weaponization
- The pace at which attackers will continue to exploit legitimate tools, necessitating behavioral visibility and continuous monitoring.
Related topics
