Cloud and SaaS Now Primary Attack Targets
A new report identifies a strategic shift among threat actors, moving away from simple malware toward identity and trust-based exploits.
Cybersecurity operations have entered a phase where the conventional perimeters of cloud and Software-as-a-Service (SaaS) environments serve as the primary focal point for threat actors. As identified in recent reporting from Darktrace, the first half of 2026 marked a notable transition in how external entities approach network security, moving away from traditional malware deployment and isolated vulnerability exploitation in favor of compromising identity credentials.
The Evolution of Digital Trust
The 2026 threat landscape represents a progression from patterns established in 2025. While previous campaigns centered largely on acquiring account credentials, the scope of activity has expanded significantly to include email authentication, cloud entitlements, and software supply chains. This shift also encompasses the compromise of AI gateways, remote administration tools, and non-human identities, prompting researchers to categorize trust itself as a vulnerable attack surface.
“Increasingly, attackers do not need to bypass trust controls in these environments; they inherit them through compromised identities, delegated access, and legitimate administration tools.”
— Darktrace researchers, in a report published on August 3.
SaaS Infrastructure as a Conduit
Compromised SaaS environments offer adversaries diverse avenues for lateral movement. In a specific instance documented by the researchers, the breach of a single account enabled a cascade of malicious actions spanning email, SaaS, and network infrastructure. Tactics included unauthorized modifications to inbox rules and the initiation of phishing campaigns, a sequence of events that proved difficult to detect because individual signals appeared benign in isolation.
Supply Chain Vulnerabilities
Threat actors are increasingly leveraging trusted digital infrastructure to distribute malicious payloads. A prominent example occurred in April, involving hijacking Axios, a JavaScript library that functions as a dependency for numerous developer environments and CI/CD pipelines. By targeting a resource downloaded over 100 million times weekly, attackers were able to distribute remote access trojans (RATs). Additionally, infostealers such as AMOS and Phexia have been distributed through the abuse of legitimate blockchain services.
The Sophistication of Email Phishing
Email-based attacks are shifting toward high-quality, targeted social engineering over volume-based campaigns. Attackers are effectively bypassing security controls, with approximately two-thirds of phishing emails observed in H1 2026 successfully passing DMARC validation protocols. Furthermore, 39% of these communications utilized novel social engineering tactics, with 25% of incidents specifically targeting VIP users within organizations.
- 37% of phishing attacks in H1 2026 contained a high volume of text, compared to 32% in H1 2025.
- Over 100 million downloads per week are associated with the Axios JavaScript library.
- Two-thirds of phishing emails passed DMARC validation in the first half of 2026.
AI-Driven Exploitation Cycles
The integration of artificial intelligence into enterprise operations has broadened the available attack surface. Attackers are utilizing Large Language Models (LLMs) to generate working exploit code for vulnerabilities like React2Shell, allowing for large-scale deployment. This trend reached a notable milestone in July with the emergence of JadePuffer, a campaign described as the first fully agentic ransomware, which utilized an automated process to exploit an internet-facing server.
Consequences for Enterprise Security
The strategic shift toward inheriting trust through identity and administrative tooling suggests that traditional authentication methods may no longer suffice for robust defense. The reliance on AI by threat actors to accelerate the cycle between vulnerability disclosure and operational exploitation likely places additional pressure on patch management and incident response cycles. For organizations, the implications point toward a need for monitoring that can correlate disparate, low-signal events across SaaS and cloud environments to detect intrusion before a breach becomes fully realized.
Sources
- Infosecurity Magazine Original source
- hijacking Axios Also reporting
- infostealers Also reporting
Continue Reading
Russian APT29 Targets Hotel Wi-Fi Access
Microsoft identifies a state-sponsored campaign exploiting hotel captive portals to deploy infostealers and harvest credentials.
Brinks Home Breach Exposes Data Files
The extortion group ShinyHunters has leaked 41 gigabytes of data following a security incident at the Dallas-based home security firm.
INC Ransomware Targets SonicWall Flaws
Threat actors are actively chaining two critical SonicWall vulnerabilities to deploy ransomware and escalate privileges to root.