Q2 2026 saw threat activity converge around a shared reliance on trusted platforms, legitimate tooling, and commoditized infrastructure. Financially motivated actors, state-sponsored operators, and geopolitically driven attackers increasingly built on the same foundational techniques, blurring the lines between criminal and state-nexus activity.
The quarter also marked a clear industrialization of access. AI-integrated phishing kits, self-perpetuating supply chain campaigns, and pre-positioned destructive capabilities point to a threat landscape where barriers to entry are falling and adversaries are building options for disruption well ahead of the events that would trigger their use.
Download this report to:
- Understand how threat activity is evolving
- Identify risks relevant to your industry
- Make stronger decisions with clarity and context
