X-Force Threat Intelligence Index 2026

Recommendations

Cyber adversaries continue to achieve scale and impact by exploiting fundamental weaknesses in identity, access control and credential management, rather than relying on highly sophisticated or novel techniques. While attack tooling and automation have advanced, the underlying conditions enabling compromise remain largely unchanged.

Once access is established, attackers consistently pursue credential harvesting, privilege escalation and session hijacking, enabling lateral movement across hybrid, cloud and SaaS environments. This activity was further amplified—according to this year’s report data—by the fact that more than half of vulnerabilities disclosed required no authentication, allowing attackers to gain footholds without bypassing identity controls altogether.

What’s more, the exposure of AI chatbot credentials on underground markets demonstrates AI platforms have rapidly become part of the enterprise identity attack surface. Although the credentials observed were no longer valid, their consistent association with infostealer malware underscores the growing risk posed by unmanaged credentials and poor identity hygiene across SaaS and AI ecosystems.

At the same time, a nearly 4-fold increase in major supply-chain and third-party breaches over the past 5 years reflects adversaries’ increasing reliance on compromised identities, shared credentials and over-trusted integrations to gain access and maintain persistence.

Given these trends, how should organizations respond, and where should they start? And how can they turn security into a true business advantage, and not just a risk mitigation effort?

Prepare for AI‑accelerated attacks—where speed, scale, and automation break traditional defenses

As threat actors use AI to put pressure on security teams—scaling their phishing campaigns, speeding up malicious code creation and fine-tuning social engineering—security leaders need a proactive rather than reactive approach to these threats. They should future-proof their organizations with AI-driven, end-to-end security.

This “shift left” strategy—from a reactive, tactical response to a proactive plan—means first gaining a holistic view of the rapidly evolving threat landscape, incorporating the latest threats and the broader context and insights into their plan.

These insights can be provided by security partners, using agentic-AI powered threat detection and response, and preparing for post-quantum threats. This shift-left action must also include a strong foundation of risk management, assessment and posture.  With AI Security Posture Management (AISPM), organizations can gain greater visibility and protection for AI-powered applications across cloud environments, enabling organizations to monitor and govern AI assets while safeguarding deployments against threats such as data poisoning and adversarial attacks.

Shifting left should also take into account an organization’s business context—and its risk appetite. It should prioritize securing critical assets and data by business impact, understanding adversary motivations and capabilities, and identifying and actively managing supply‑chain and third‑party dependencies.

The recent rise of autonomous security operation centers, which use agentic AI to augment the roles of security workers, can orchestrate multiple agents to work across the entire threat lifecycle—from threat hunting to remediation—giving organizations the tools they need to detect and mitigate increasingly complex AI-generated attacks.

Monitor human and non-human identities—and detect threats—with AI

For organizations, protecting identities has always posed a challenge. It’s about to get harder. As attackers fine-tune their credential‑driven operations, IT and security leaders must turn to AI to help them gain visibility into identity-based risks and threats across their IT landscape. By combining AI-powered identity threat detection and response (ITDR) and identity security posture management (ISPM) services and solutions, organizations can move more quickly and efficiently to identify vulnerabilities and prevent attacks from happening.

If it still needs saying: identity must be treated as critical infrastructure. Security leaders who haven’t already should elevate their identity systems to the same level of resilience, governance and monitoring as core infrastructure components.


If it still needs saying: identity must be treated as critical infrastructure. Given the sensitivity of AI-driven data and agentic workflows, security leaders who haven’t already should elevate their identity systems to the same level of resilience, governance and monitoring as core infrastructure components. They should centralize identity access management and governance across workforce, customer, partner and machine identities.

They should also apply continuous, risk-based access controls informed by context such as user behavior, device posture and workload characteristics. This shift will also require specialized threat-hunting capabilities, AI-specific protections and infrastructure-level security controls to defend against increasingly sophisticated external attacks.

Embed identity controls in application and API security

Beyond the risk of compromised credentials, the rise in vulnerabilities not requiring authentication shows the importance of integrating identity directly into application architectures.

To secure those architectures, security teams should provide strong authentication and authorization enforcement for public-facing and internal applications, APIs and service-to-service communications. Identity-aware access policies should be used to limit exposure and prevent application-level exploits from escalating into broader compromise.

Test and hunt for vulnerabilities

There’s nothing attackers like more than an overlooked or ignored vulnerability. Fortunately, security leaders know how to handle this—by getting back to foundational, first principles. That means adopting a continuous, proactive approach to identifying weaknesses across environments, such as looking for:

- Insecure code

- Weak or reused credentials

- Misconfigurations

- Unauthorized changes

- Insecure defaults

- Risky user behavior

- Missing patches

If an attacker does break through, here are three things that can help prevent an initial exploitation from progressing into credential harvesting or data exfiltration: proactive remediation, strong configuration hygiene and continuous monitoring of application behavior.

Regular penetration testing across the full technology stack—including applications, networks, cloud infrastructure, AI models, mainframes, hardware and even personnel—is also needed to uncover vulnerabilities and configuration gaps that could lead to unauthorized access or exposure of sensitive systems and data.

Prioritize AI platform security

AI chatbots and agentic workflows must be secured and governed with the same—or even greater—rigor as other enterprise SaaS platforms. Too often, in the high-pressure rush to deploy, this is not what happens. That’s a problem because the risks and threats from AI present significant challenges for organizations.

Agentic AI has introduced new risks, and amplified others. Security leaders need a comprehensive AI governance solution to scale AI with trust and transparency, and in a way that generates value. To avoid vendor lock in, the solution should be open, hybrid and platform-agnostic, meaning organizations can use the right model for the right use case, and deploy their AI where it makes the most sense.  

Model governance allows for evaluation of underlying AI, to test for performance, accuracy and safeguard against inappropriate behavior. Keeping up with regulations that pertain to the use of AI is critical to maintain compliance and reduce risk.

Organizations should assess AI adoption across the enterprise, including enforcing strong authentication and conditional access controls, securing AI systems, protecting AI service credentials and tokens, and monitoring for abnormal access patterns or credential exposure.

Map your footprint and track the signals that attackers watch

Security misconfigurations, data breaches, and plain old human error can lead to the public exposure of an organization’s valued brand, domain, IP addresses or client-specific assets. This highlights the risk that resides outside your network perimeter’s control. Security teams should work with a trusted partner to identify the exposure of these valuable assets across the public-facing surface web, the unindexed deep web and black-market sites on the dark web. These specialized services include monitoring capabilities for credential theft, suspicious domains, CVEs and security bulletins.

Accelerate data security

As data and AI play an increasingly vital role in today’s digitized organizations, and across our digital economy, security leaders must innovate and adapt at the speed of AI-driven change. To do this, they and their teams should make sure they have the right data protection controls—such as encryption, access controls, data loss prevention, monitoring and auditing, and secure data classification—to secure the organizational data and manage what data is being fed into AI to prevent inadvertent exposure of sensitive data.

While data security has always been important, it gains even more importance in the AI world—discovering where the sensitive data lives, understanding how it’s used and exposed, prioritizing data risks based on context and using proactive controls—all while meeting the stringent compliance requirements such as GDPR, CCPA, PCI-DSS and many more.

3d sphere and cube shapes surrounded by locks
Related solutions
Identity and access management (IAM) services

Strengthen security and compliance with IBM IAM services, streamlining identity across hybrid cloud environments.

Explore IAM services
Threat detection and response services

Optimize your security program with IBM’s global, vendor-independent threat response services.

Explore threat detection services
IBM Verify

Build a secure identity foundation with IBM Verify to simplify access, improve authentication, and scale with confidence.

Explore IBM Verify
Take the next step

Book a personalized discovery briefing to explore how IBM X-Force® can help you reduce cyber risk, validate your defenses and build lasting cyber resilience with offensive and defensive expertise.

  1. Schedule a discovery session with X-Force
  2. Explore IBM X-Force