CyberSecurity SEE

Cloud and SaaS Environments Emergence as Primary Targets for Attackers

Cloud and SaaS Environments Emergence as Primary Targets for Attackers

Cybersecurity Landscape in 2026: New Threats Emerge in Cloud and SaaS Environments

In the first half of 2026, cyber threats have escalated significantly, particularly targeting cloud and Software-as-a-Service (SaaS) environments. According to a recent report by Darktrace, a well-known cybersecurity firm, this trend marks a continuation of the evolution observed in 2025, where attackers shifted their focus from traditional malware and vulnerabilities to identity compromise.

Historically, hackers primarily aimed at stealing account credentials. However, the findings from Darktrace reveal a broader range of targetable items in 2026. Threat actors have expanded their arsenal to encompass email authentication, cloud entitlements, software supply chains, AI gateways, remote administration tools, and even non-human identities. This shift is indicative of a larger trend where “trust” has emerged as a new attack surface, signifying a more complex and intricate landscape for cybersecurity professionals.

The implications of compromised cloud and SaaS environments are profound. Darktrace highlighted a particular instance in which a single compromised SaaS account enabled malicious activities across multiple layers, including email, SaaS, and network configurations. Such actions included alterations to inbox rules and the initiation of phishing attacks. One concerning aspect of these attacks is the difficulty in detection; individually, none of the actions may appear suspicious, but collectively, they signal a serious intrusion.

Further compounding the issue, the report elucidated instances where attackers exploited trusted digital supply chains to infiltrate victims in H1 2026. In April, a notable incident involved the hijacking of the Axios JavaScript library—downloaded over 100 million times weekly—by threat actors to disseminate remote access trojans (RATs). The Axios library is commonly used as a dependency in numerous development environments and Continuous Integration/Continuous Deployment (CI/CD) pipelines, making its compromise particularly dangerous.

Moreover, attackers have been observed leveraging legitimate blockchain infrastructure to distribute infostealers, including well-known malware strains like AMOS and Phexia. Darktrace researchers noted that such infrastructure is often utilized by users with minimal security capabilities, thereby allowing malicious actors to target a significantly larger pool of potential victims.

The report dated August 3 emphasized that today’s attackers do not necessarily need to circumvent existing trust controls; rather, they can inherit these controls through compromised identities, delegated access, and legitimate administrative tools. This evolving strategy not only complicates the tasks of cybersecurity professionals but also requires organizations to reevaluate their security frameworks comprehensively.

Email Attacks: A Shift Towards Quality

In addition to the rising threats in cloud environments, Darktrace’s study revealed a marked increase in the sophistication of email-based attacks. Cybercriminals appear to prioritize quality over sheer volume, with two-thirds of phishing emails dispatched in H1 2026 successfully passing the DMARC email validation protocols. This alarming statistic indicates that conventional authentication measures are no longer sufficient to safeguard against attacks.

The report further detailed that 37% of phishing emails contained a higher volume of text compared to the previous year, with instances increasing from 32% in the same timeframe in 2025. Notably, 39% of these phishing attempts showcased innovative social engineering techniques. Targeting high-profile individuals, often identified as VIPs, has become a common approach, appearing in 25% of the observed phishing attacks.

Another worrying trend is the rise of ClickFix social engineering, a tactic aimed at duping users into executing malicious code themselves. This method has persisted since 2025, highlighting the continuous evolution of cyberattack strategies.

AI’s Expanding Role in Cyber Threats

Another significant finding from the Darktrace study notes that the burgeoning use of artificial intelligence (AI) in business environments is creating new avenues for cybercriminals. Threat actors have begun to exploit AI tools, enabling them to launch attacks on a broader scale. A striking example includes the use of AI-generated malware that capitalized on the React2Shell vulnerability, where an attacker employed a large language model to generate exploit code and deploy it widely.

July 2026 saw the revelation of the world’s first fully AI-generated ransomware campaign, named JadePuffer. In this instance, an advanced threat actor exploited a vulnerability in an internet-facing server, culminating in a completely automated ransomware attack.

In conclusion, the report underscores a pressing concern for organizations globally: “AI is accelerating the path from vulnerability disclosure to operational exploitation,” the Darktrace researchers cautioned. This year’s findings serve as a stark reminder of the increasingly sophisticated tactics adopted by cybercriminals, compelling organizations to adapt their cybersecurity strategies and remain vigilant against emerging threats.

Source link

Exit mobile version