SpyCloud, a leader in identity threat protection, has released its annual 2026 SpyCloud Identity Threat Report, revealing that non-human identities (NHIs)—including AI agents, service accounts, API keys, and authentication tokens—have become the most common entry point for attackers targeting enterprises. According to the survey of 750 cybersecurity professionals across North America, the UK, and select European markets, compromised NHIs accounted for 31% of primary attack entry points, nearly twice the rate of phishing and social engineering at 17%. NHI-related misuse was also the most frequently reported identity-based event, cited by 42% of respondents. Despite the growing threat, organizations have limited visibility into machine identities. While 95% of respondents believe they have adequate visibility into AI- and NHI-related exposures, only 36% actively monitor them. Meanwhile, 91% of organizations use AI tools or agents with access to internal systems, applications, or data, but only 56% have formal governance and ownership over those privileges. Overall, 68% of organizations experienced an identity-based event during the measured period, with affected organizations reporting an average of eight incidents. The report also highlights the growing importance of stolen session cookies and authentication tokens, which can allow attackers to bypass controls such as MFA. Organizations with visibility into stolen session cookies reported lower identity-event rates (37%) than those without such visibility (50%). Phishing and malware remain major delivery mechanisms, while malware-infected third-party devices and exposed vendor API keys or application access were the leading causes of supply-chain identity events. SpyCloud’s findings emphasize that continuous monitoring and automated remediation can significantly improve resilience. Organizations relying heavily on manual remediation reported higher incident-response costs and greater loss of customer or partner trust than highly automated organizations. The report introduces SpyCloud’s Identity Threat Protection Maturity Model, showing that mature programs combine continuous identity exposure monitoring, strong governance, automation, and rapid remediation to reduce the window in which stolen identities remain usable.
Healthcare technology provider Veradigm disclosed a data breach involving a third-party vendor after attackers obtained vendor credentials that provided access to a limited Veradig...
A sophisticated, multi-stage malware campaign has been observed combining fake Google CAPTCHA verification pages, WebDAV infrastructure, malicious Cloudflare Workers and BNB Smart ...
Cisco has confirmed active exploitation of CVE-2026-20079, a critical authentication-bypass vulnerability in Cisco Secure Firewall Management Center (FMC) Software with CVSS score ...