Breaking
Cyber CrimeDeveloping Story

Cloud and SaaS Now Primary Attack Targets

A new report identifies a strategic shift among threat actors, moving away from simple malware toward identity and trust-based exploits.

··1 hour ago·3 min read
diagram
Photo by Growtika on Unsplash

Cybersecurity operations have entered a phase where the conventional perimeters of cloud and Software-as-a-Service (SaaS) environments serve as the primary focal point for threat actors. As identified in recent reporting from Darktrace, the first half of 2026 marked a notable transition in how external entities approach network security, moving away from traditional malware deployment and isolated vulnerability exploitation in favor of compromising identity credentials.

The Evolution of Digital Trust

The 2026 threat landscape represents a progression from patterns established in 2025. While previous campaigns centered largely on acquiring account credentials, the scope of activity has expanded significantly to include email authentication, cloud entitlements, and software supply chains. This shift also encompasses the compromise of AI gateways, remote administration tools, and non-human identities, prompting researchers to categorize trust itself as a vulnerable attack surface.

“Increasingly, attackers do not need to bypass trust controls in these environments; they inherit them through compromised identities, delegated access, and legitimate administration tools.”

— Darktrace researchers, in a report published on August 3.

SaaS Infrastructure as a Conduit

Compromised SaaS environments offer adversaries diverse avenues for lateral movement. In a specific instance documented by the researchers, the breach of a single account enabled a cascade of malicious actions spanning email, SaaS, and network infrastructure. Tactics included unauthorized modifications to inbox rules and the initiation of phishing campaigns, a sequence of events that proved difficult to detect because individual signals appeared benign in isolation.

Supply Chain Vulnerabilities

Threat actors are increasingly leveraging trusted digital infrastructure to distribute malicious payloads. A prominent example occurred in April, involving hijacking Axios, a JavaScript library that functions as a dependency for numerous developer environments and CI/CD pipelines. By targeting a resource downloaded over 100 million times weekly, attackers were able to distribute remote access trojans (RATs). Additionally, infostealers such as AMOS and Phexia have been distributed through the abuse of legitimate blockchain services.

The Sophistication of Email Phishing

Email-based attacks are shifting toward high-quality, targeted social engineering over volume-based campaigns. Attackers are effectively bypassing security controls, with approximately two-thirds of phishing emails observed in H1 2026 successfully passing DMARC validation protocols. Furthermore, 39% of these communications utilized novel social engineering tactics, with 25% of incidents specifically targeting VIP users within organizations.

  • 37% of phishing attacks in H1 2026 contained a high volume of text, compared to 32% in H1 2025.
  • Over 100 million downloads per week are associated with the Axios JavaScript library.
  • Two-thirds of phishing emails passed DMARC validation in the first half of 2026.

AI-Driven Exploitation Cycles

The integration of artificial intelligence into enterprise operations has broadened the available attack surface. Attackers are utilizing Large Language Models (LLMs) to generate working exploit code for vulnerabilities like React2Shell, allowing for large-scale deployment. This trend reached a notable milestone in July with the emergence of JadePuffer, a campaign described as the first fully agentic ransomware, which utilized an automated process to exploit an internet-facing server.

Consequences for Enterprise Security

The strategic shift toward inheriting trust through identity and administrative tooling suggests that traditional authentication methods may no longer suffice for robust defense. The reliance on AI by threat actors to accelerate the cycle between vulnerability disclosure and operational exploitation likely places additional pressure on patch management and incident response cycles. For organizations, the implications point toward a need for monitoring that can correlate disparate, low-signal events across SaaS and cloud environments to detect intrusion before a breach becomes fully realized.

#cloud security#saas#phishing#ai security#cyber threats

Sources

Iliyas

Editor, Xploitwire

This article was researched and drafted with AI assistance from the sources listed above, then checked against those sources through our automated fact-check process, under the editorial policies set by Iliyas. Our AI Policy →

← Back to all stories