Current threat landscape / research added Sep 8, 2026

The cybersecurity threats that matter in 2026.

Not a prediction list and not vendor marketing. This page prioritizes attack patterns repeatedly validated by current incident-response investigations, breach data, threat hunting, government advisories, and technical research — then connects each one to a full explainer and source evidence.

September research update

New evidence for the threats you’re learning.

Ten source updates connect recent campaigns, vendor advisories, and official guidance to the existing encyclopedia. Sources checked . Dates below identify publication, revision, or application; campaign periods are stated separately.

Technical ValidationResearch / emerging practice

Google documents agent-enabled credential harvesting and AI resource theft

2026-09-08Google Threat Intelligence Group / Mandiant

Google's September 8 report describes a Q2 2026 case in which attackers compromised a cloud resource and planned, built, and executed an agent-enabled credential-harvesting campaign in under six hours. It also documents theft of AI credentials and unauthorized use of victim cloud resources.

Original source — Google Threat Intelligence Group / MandiantEvidence context and limitations →
Technical ValidationOperational validation

Chrome release addresses a V8 vulnerability with an exploit in the wild

2026-09-03Google Chrome

Google's September 3 desktop release includes 12 security fixes and states that an exploit for CVE-2026-85046 exists in the wild. The notice lists Chrome 152.0.7977.82/.83 for Windows and Mac and 152.0.7977.82 for Linux.

Original source — Google ChromeEvidence context and limitations →
Technical ValidationOperational validation

Cisco revises IOS XR hardening details on September 8

2026-09-02; revised 2026-09-08Cisco PSIRT

Cisco groups internally discovered issues under seven CVE identifiers, including two rated 9.8. It reports no known malicious use and no workarounds. Advisory version 1.4, dated September 8, updates superseded MPLS-TE software maintenance updates.

Original source — Cisco PSIRTEvidence context and limitations →
Technical ValidationOperational validation

Fake IT-support contacts use Teams to obtain user-approved remote access

2026-09-02Microsoft Threat Intelligence

Microsoft describes external Teams contacts impersonating support staff and persuading users to grant remote access. The documented chain includes implant deployment, discovery, and lateral movement, following user authorization through legitimate support tools.

Original source — Microsoft Threat IntelligenceEvidence context and limitations →
Technical ValidationResearch / emerging practice

Invisible Unicode characters appear in phishing keyword evasion

2026-09-03Microsoft Security Research

Microsoft describes invisible Unicode characters inserted into phishing text to obstruct keyword parsing. Signature activity increased from February 9 and remained elevated on weekdays for roughly three months. Layered protections flagged most of the messages.

Original source — Microsoft Security ResearchEvidence context and limitations →
Technical ValidationOperational validation

Counterfeit vendor pages deliver changing malicious installers

2026-09-01Microsoft Threat Intelligence

Microsoft describes look-alike software download pages distributing malicious installers whose contents change between downloads. Observed affected devices were predominantly associated with China-based operations and Chinese-speaking users across several industries.

Original source — Microsoft Threat IntelligenceEvidence context and limitations →
Government / AuthoritativeStandard / framework

EU manufacturer reporting duties apply from September 11, 2026

Applies 2026-09-11European Parliament and Council

The Cyber Resilience Act's Article 14 covers actively exploited vulnerabilities and severe product-security incidents: early warning within 24 hours and notification within 72 hours of awareness. Final vulnerability reports are due within 14 days after a corrective or mitigating measure becomes available; final severe-incident reports within one month after the incident notification.

Original source — European Parliament and CouncilEvidence context and limitations →

2026 signal check

89%

of Unit 42 investigations involved identity as an affected attack surface

Unit 42 2026 IR

31%

of breach entry points involved vulnerability exploitation

Verizon 2026 DBIR

15×

increase in monthly device-code phishing attempts in 1H 2026

CrowdStrike 2026 THR

89%

year-over-year increase in AI-enabled adversary operations

CrowdStrike 2026 GTR

What changed

Trust is the attack surface.

Attackers increasingly win by looking legitimate: valid identities, real authentication flows, trusted SaaS tools, cloud APIs, software dependencies, help-desk processes, and AI services.

The second shift is speed. New vulnerabilities can move from disclosure to exploitation in hours, while automation and AI let attackers personalize, iterate, and scale operations faster than traditional response cycles.

Priority threat themes

Learn what defenders are actually seeing.

These are ordered as a learning path, not a fake universal ranking. Different industries and organizations will face different exposure.

01
Identity SecurityThreat

Identity-Driven Intrusion

An intrusion in which stolen, manipulated, over-privileged, or otherwise abused identities become the attacker’s primary path into and through an environment.

4 evidence recordsLearn it →
02
Vulnerability & ExploitationAttack Technique

Rapid Vulnerability Exploitation

The exploitation of newly disclosed vulnerabilities at machine-speed or near-machine-speed, often within hours of public technical details or proof-of-concept code becoming available.

3 evidence recordsLearn it →
03
Identity SecurityAttack Technique

Device Code Phishing

A phishing technique that tricks a user into entering an attacker-controlled device code into a legitimate authentication page, authorizing the attacker’s session instead of the user’s device.

2 evidence recordsLearn it →
04
Identity SecurityAttack Technique

Adversary-in-the-Middle Phishing (AiTM)

A phishing technique that proxies a real authentication session so the attacker can capture credentials and session tokens in real time, potentially bypassing non-phishing-resistant MFA.

1 evidence recordLearn it →
05
Threats & Social EngineeringAttack Technique

Vishing

Phishing conducted by voice, phone, or voice-enabled communication in order to manipulate a person into granting access, revealing information, or taking an unsafe action.

3 evidence recordsLearn it →
06
Cloud SecurityThreat

SaaS Account Takeover (SaaS ATO)

Unauthorized control of a legitimate software-as-a-service account, often using stolen credentials, tokens, MFA enrollment, OAuth grants, or compromised SSO access.

3 evidence recordsLearn it →
07
Application & Software SecurityThreat

Software Supply Chain Compromise

An attack that compromises software, dependencies, build systems, developer tooling, updates, integrations, or trusted vendors so malicious access is inherited by downstream users.

4 evidence recordsLearn it →
08
Network SecurityAttack Technique

Edge Device Exploitation

Compromise of internet-facing infrastructure such as VPNs, firewalls, gateways, routers, or other edge appliances to gain durable access while avoiding endpoint-focused defenses.

3 evidence recordsLearn it →
09
AI SecurityThreat

AI-Accelerated Cyberattacks

Cyber operations in which attackers use AI to increase the speed, scale, personalization, adaptability, or technical capability of reconnaissance, social engineering, exploitation, malware, or evasion.

7 evidence recordsLearn it →
10
Cloud SecurityAttack Technique

Living off the Cloud (LOTC)

Abuse of legitimate cloud identities, APIs, services, storage, automation, and administrative capabilities to conduct malicious activity while blending into normal cloud operations.

3 evidence recordsLearn it →
11
Threats & Social EngineeringThreat

Data Extortion

Theft of sensitive information followed by threats to publish, sell, misuse, or otherwise weaponize the data unless the victim pays or complies with the attacker’s demands.

1 evidence recordLearn it →
12
Threats & Social EngineeringThreat

Deepfake Impersonation

Use of AI-generated or manipulated audio, video, images, or personas to impersonate a trusted person and make a fraudulent request appear authentic.

1 evidence recordLearn it →
13
AI SecurityThreat

Shadow AI

Use of AI applications, agents, models, browser extensions, or integrations outside approved governance, visibility, or security controls.

2 evidence recordsLearn it →
14
AI SecurityThreat

LLMJacking

Unauthorized use of another organization’s cloud or API credentials to consume paid large-language-model services, steal AI capacity, or support further malicious activity.

2 evidence recordsLearn it →
15
Identity SecurityAttack Technique

Session Token Theft

The theft or reuse of a token, cookie, or other session artifact that represents an already-authenticated user or application.

3 evidence recordsLearn it →
16
Threats & Social EngineeringAttack Technique

Help Desk Social Engineering

Social engineering aimed at IT or identity-support personnel to reset credentials, enroll attacker-controlled MFA, recover accounts, or change trusted access.

2 evidence recordsLearn it →

Editorial rule

A current-threat page has to stay current.

We will treat this as a maintained layer of the encyclopedia. Threats can be added, reordered, or de-emphasized when evidence changes. Every claim should remain traceable to a reviewed source rather than becoming stale “top ten” content.