Cybertech Frontier — What Is Next

September 29, 2026
blog image

Most trend lists are a vendor roadmap with the release notes filed off. Rank the changes by the evidence behind them and 2025–26 has one shape: the cost and the latency of an attack have collapsed, onto an identity surface that is no longer mostly human. Quantum doom and the end of the SOC are on slower clocks than the marketing says.

ENSI research — built on a library of 164 primary documents and 52 company dossiers.


The argument, before the list

In mid-September 2025 Anthropic’s threat-intelligence team watched a Chinese state-sponsored group it designates GTG-1002 run reconnaissance, exploitation, credential harvesting and exfiltration against roughly thirty technology companies, banks, chemical manufacturers and government agencies. The human operators did between 10% and 20% of the work. The model did the rest — “approximately 80–90% of all tactical operations independently”, at “sustained request rates of multiple operations per second”, with the humans intervening only to approve the move from reconnaissance to exploitation, to authorise harvested credentials, and to decide what was taken (Anthropic 2025). It is the first documented case of an AI system orchestrating intrusions into confirmed high-value targets.

A few months later Verizon published the largest Data Breach Investigations Report ever assembled — more than 31,000 real incidents, more than 22,000 confirmed breaches, 145 countries — including a section on what threat actors do with AI when someone measures rather than asserts. In behavioural data classified against MITRE ATT&CK, the median piece of AI-assisted malware had 55 existing, known malware examples performing the same function, and fewer than 2.5% of observations involved a technique with one or fewer known precedents (Verizon 2026, p. 12). The framing of the whole report is two words: refinement, not revolution.

Both findings are true. Almost every “cyber trends 2026” list picks one and sells it.

This report tries to do the other thing. It ranks what is changing by how much evidence actually supports the change, and it keeps apart three things the genre melts together. Behaviour is what attackers measurably do differently, established by incident telemetry. Market is what defenders buy, established by funding rounds and acquisition prices. Capability is what is genuinely new in the technology, established by experiment and proof of exploitation. A trend list becomes marketing at the exact moment it presents a market movement as a behaviour change — “attackers are now targeting X” when what happened is that a new category of product for X was funded. A good deal of what circulates as threat intelligence in 2026 is a budget line wearing a threat actor’s clothes.

Sorted this way, the period has one defining shift, and it is a collision between two curves.

The first is the collapse of the cost and the latency of attack. Exploitation of vulnerabilities is now the most common initial access vector in the DBIR at 31%, up from 20% — a 55% rise in a year — overtaking credential abuse at 13% (Verizon 2026, p. 15). Twenty-nine per cent of vulnerabilities in CISA’s Known Exploited Vulnerabilities catalogue were attacked before public disclosure. A tool-using LLM agent exploited 87% of a benchmark of real one-day vulnerabilities from the advisory text alone, at about $3.52 a run against roughly $25 of expert time — and 7% without the text, which locates the danger precisely in the window between publication and patch (Fang et al 2024). In December 2025 an AI agent wrote a working malware framework, VoidLink, in six days. Christopher Koch’s formulation is the one to carry: agentic AI is an attack compression technology, lowering the cost of reconnaissance, lure production, credential abuse, CVE-to-patch-gap matching, exploit adaptation and post-compromise decision support (Koch 2026, p. 1).

The second curve is an identity surface that grew faster than anyone’s controls and stopped being human. Non-human identities — service accounts, API tokens, workload identities, agents — grew 44% year on year and now outnumber human identities by 144:1, up from 92:1 twelve months earlier; across 230 billion permissions analysed by Veza, the share classified safe and compliant fell from 70% to 55% in a single year while ungoverned permissions rose from 5% to 28%; one in twenty AWS machine identities carries full administrator privilege; and enterprise IAM teams are responsible for only 44% of machine identities at all (Kurtz and Krawiecka 2026, pp. 18–20). The DBIR, from a different dataset entirely, points defenders to the same place: “we should pay special attention to service and machine accounts, as those will likely be the ones leveraged in our potential agentic AI future” (p. 22).

Put the curves together and the mechanism is unglamorous. Cheap, fast, tireless offence is being pointed at whatever is simultaneously exposed and over-privileged — and in 2026 exposure has a name (an unpatched internet-facing appliance) and privilege has a name (an ungoverned machine credential). Everything else in this report is a consequence of that collision, a market response to it, or a genuinely separate clock.

Two of the loudest items run on those separate clocks. Quantum: 37% of executives expect quantum technologies to affect cybersecurity within twelve months (WEF 2026, p. 48), while NIST’s own arithmetic says standardisation to full integration historically takes ten to twenty years, the federal target is 2035, and 112-bit classical public-key algorithms are deprecated after 2030. The urgency is real, but it is a crypto-inventory urgency, not an imminent-break urgency. “AI will replace the SOC”: the strongest rigorous evaluation to date, DARPA’s AI Cyber Challenge final, ran seven autonomous systems for roughly 143 hours over 53 real open-source projects and found that pairing a proof-of-vulnerability with a patch worked 92% of the time, with patch quality the practical bottleneck (Zhang et al 2026). An extraordinary result for autonomous repair of code you own. Not an autonomous security operations centre.

There is a third correction, less discussed and more useful to a national agency. Counting incidents without weighting impact manufactures alarm. In ENISA’s curated set of 4,875 incidents affecting the EU between July 2024 and June 2025, DDoS accounts for 76.7% of recorded incident types and hacktivism for almost 80% of recorded incidents — overwhelmingly low-impact noise — while intrusions are 17.8% (pp. 6, 8). A national threat picture built on incident counts will be dominated by hacktivist DDoS and will point budgets at the wrong thing.

This is the fifth report in the ENSI series on Israeli cybersecurity, and it asks a different question from the first four. Report 1 ranked the fifty companies that make Israel a cyber power; Report 2 extracted sixteen principles a state can copy; Report 3 specified the twenty-four features of the most advanced defensive system anyone could assemble. This one asks what a CISO, a founder and a national agency should believe about the next eighteen months — and what they should refuse to believe. The Israeli company evidence appears here as market evidence: who is putting capital behind which trend, priced by people with their own money at stake. The “we” is a mid-sized European state and its companies, with the Czech Republic as the default home example.

Summary of main points

  • Rank trends by evidence, and separate three things — what attackers do (behaviour, from incident telemetry), what defenders buy (market, from rounds and exits), and what is technically new (capability, from experiment). Most trend lists present the second as the first.

  • The defining shift is a collision. The cost and latency of attack collapsed — exploitation up to 31% of initial access, 29% of KEV bugs attacked before disclosure, agentic offence at a few dollars a run — at the same time as an identity surface growing 44% a year and now 144:1 non-human.

  • Exploitation has overtaken credentials as the front door, and remediation is getting worse. KEV remediation fell from 38% to 26%; median time to full resolution rose from 32 to 43 days; 42,595 new CVEs, up 27%. The least glamorous finding in the library and the highest-confidence one.

  • AI is industrialising the known, not inventing the unknown — with two thresholds crossed. APT28’s PROMPTSTEAL querying an LLM at runtime against Ukraine, and GTG-1002 at 80–90% autonomy. Hallucination remains a tax on offensive autonomy, in the attacker’s own telemetry.

  • Non-human identity is the single highest-confidence trend — four sources, four methods, one conclusion — and the cheapest high-leverage fix available to a CISO or a state.

  • Supply chain is now roughly half the breach population, sitting on maintenance debt: 92% of codebases carry components four or more years out of date. In March 2026 two security vendors in these dossiers were themselves the vector.

  • Agent security became a discipline in eighteen months — OWASP’s ASI01–ASI10, the “Least-Agency” principle, and the first rigorous analysis of MCP, which measured attack success rising from 26.4% to 52.8% against non-MCP baselines.

  • Ransomware’s economics inverted: more attacks, less money. In 48% of breaches, up from 44%, but 69% of victims did not pay and the median payment fell to $139,875.

  • The APT-versus-criminal taxonomy is losing analytic value. State actors are abandoning bespoke tooling for the criminal ecosystem; commodity malware on a Czech network no longer implies a commodity adversary.

  • Regulation is consolidating, not expanding. Europe’s binding constraint is reporting burden and certification latency — one scheme adopted in seven years — not a shortage of rules.

  • The market’s answer to all of it is consolidation: $67bn of Israeli security companies changed hands in fourteen months. The platforms are buying bundles, and nobody has assembled the loop.

  • For a Czech-scale state: fund patch latency, machine-identity governance and validation; ignore quantum panic-buying, unaudited “autonomous SOC” claims and agentification without a use case. Five moves close the report.


How we sort signal from hype

Every claim here was put through the same three tests, and the ranking that follows is a ranking of how well each trend survives them.

One: at least two independent sources, using different methods. A finding in one vendor’s telemetry is a product observation. A finding in ENISA’s curated incident set and Verizon’s breach census and a peer-reviewed measurement study, reached by three different instruments, is a fact about the world. Where a trend rests on one source, this report says so and ranks it lower, however important it would be if true.

Two: incident data over survey sentiment. The WEF’s Global Cybersecurity Outlook 2026 surveyed 804 qualified respondents from 92 countries, including 316 CISOs and 105 CEOs. That is an excellent instrument — for measuring beliefs. When 94% say AI will be the most significant driver of change in the year ahead, the honest reading is that is where the budget is going, which is a real and forecastable fact about the market and no evidence at all about attacker behaviour. Telemetry tells you what happened; surveys tell you what will be bought. Confusing the two is the commonest failure in the genre. This report uses both and labels which is which.

Three: a named falsifier. Every trend below states what would have to be observed for the call to be wrong — a number in next year’s DBIR, ENISA or Black Duck that would move it down the list. A trend with no falsifier is a slogan, and several claims that felt obvious in drafting did not survive the question.

Four caveats about the evidence base, because the sources are not equally clean. ENISA states its own limitations better than anyone in the genre, conceding that open-source collection is incomplete and that sectoral and geographic vagueness biases its dataset (2025, p. 7) — which is why its numbers are trusted here even where they conflict with vendor figures. Vendor reports carry sample bias their headlines do not: Black Duck’s audit data comes from 947 codebases examined during mergers and acquisitions, so it over-samples companies being bought and sold, and where mean and median diverge sharply this report quotes the median. Company figures are frequently self-reported — acquisition prices are hard, valuations and ARR mostly are not, and a 2021 valuation is not the same currency as a 2026 one. And some of the most important research here is a single paper: the MCP protocol analysis and the machine-identity taxonomy are the best work in their areas precisely because there is so little, and neither has been independently replicated.

The twelve trends sit in four evidential tiers. Tier A (1–4) rests on census-grade incident data from at least two independent collectors. Tier B (5–6) rests on strong but contested telemetry. Tier C (7–10) rests on protocol experiments, product evidence and market behaviour rather than breach counts. Tier D (11–12) covers changes whose direction is certain and whose timing is routinely overstated. Each section follows one shape: what is changing · the evidence · why it is happening · who is building for it · the hype check and the falsifier · what to do about it now.


Tier A — the census-grade trends

1. The front door is an unpatched appliance, and the patch queue is losing

What is changing. For fifteen years the standard opening move of an intrusion was a stolen password. It is now an unpatched internet-facing device. That reordering is the most consequential and least discussed finding of 2025–26, and it is displacing a whole management discipline: the quarterly vulnerability list is giving way to continuous, exploitability-aware exposure validation, because the list has become uncountable and the window unmeetable.

The evidence.

  • Verizon (2026) — exploitation is now the single most common initial access vector at 31%, up from 20%, a 55% increase, overtaking credential abuse at 13%, across 22,000+ confirmed breaches in 145 countries (pp. 10, 15).

  • ENISA (2025), measuring the EU independently across 4,875 curated incidents, puts exploitation lower by volume — 21.3% against roughly 60% for phishing — but far higher by yield: nearly 70% of vulnerability cases culminated in an intrusion and 68% ended in malicious code deployment, against 27% of phishing cases (p. 8). Phishing is the volume channel; exploitation is the conversion channel.

  • Remediation is going backwards. Only 26% of CISA KEV-catalogued critical vulnerabilities were fully remediated in 2025, down from 38%; median time to full resolution rose from 32 to 43 days; organisations carry 50% more critical vulnerabilities than a year earlier (Verizon 2026, p. 10).

  • The work grew faster than the capacity to do it: 42,595 new vulnerabilities, up 27%, 64% network-exploitable (ENISA 2025, p. 57) — while 29% of KEV vulnerabilities were attacked before public disclosure (Verizon 2026, p. 109).

Why it is happening. Three forces, none of them about AI. Edge devices — VPN concentrators, firewalls, file-transfer appliances, identity gateways — are internet-facing by design, cannot host an endpoint agent, and belong to teams with no maintenance window. Multi-factor authentication worked, raising the cost of the credential path enough to push attackers onto the software path. And the arithmetic of triage broke: patching capacity is roughly fixed while disclosure volume grows a quarter a year, so the backlog compounds mechanically.

Who is building for it. The most commercially mature trend here, and the Israeli ecosystem effectively invented the category.

  • XM Cyber — the attack-path twin behind the choke-point argument: in its Cyentia-analysed data, 80% of exposures come from misconfiguration and credentials, under 1% from CVEs, and 2% sit on choke points · sold to Schwarz Group for $700M in 2021; on 16 July 2026 CrowdStrike agreed to buy the intellectual property alone — 45-plus patents and the source code.

  • Armis — asset intelligence across IT, OT, IoT and medical · ServiceNow paid $7.75bn cash, closed April 2026, on ARR above $340M growing more than 50% — roughly 23 times ARR, the largest price ever paid for exposure management.

  • Zafran — scores a CVE against controls the customer already owns · $60M Series C, December 2025, led by Menlo Ventures, past $140M with strategic money from American Express Ventures and Cisco Investments in 2026.

  • Pentera and Cymulate — automated adversarial validation · Pentera passed $100M ARR in 2025 yet raised its $60M Series D at a flat “over $1bn” and cut about 20% of staff in 2026; Cymulate has not raised since September 2022 at roughly $500M. Validation works, and is priced below the platforms that absorb it.

  • Oligo, Upwind and Sweet Security — runtime reachability, so a vulnerability counts only if the function executes · Oligo’s $60M Series C (August 2026) came on ARR up 300%; Upwind raised ~$300M at about $3.8bn in September 2026; Sweet’s $75M Series B included Munich Re Ventures — an insurer funding runtime security.

The hype check. Three things the evidence does not support. This is not an AI story — the shift appears in data that predates agentic offence. Credentials are not dead: the DBIR flags that part of credential abuse’s fall is an artefact of newly tracking pretexting (p. 15), and ENISA still puts phishing near 60% of cases by volume. And the claim that context shrinks the problem by two orders of magnitude — Zafran’s “99% of critical vulnerabilities are not exploitable in context”, XM Cyber’s under-1% — is self-measured: plausible, directionally corroborated by ENISA’s yield data, never validated by anyone without a product to sell.

Falsifier: if the 2027 DBIR shows exploitation falling back below credential abuse, or KEV remediation recovering above 38% with median time-to-resolution under 32 days, the call was wrong.

What to do about it now. Publish patch latency as a governed metric — median hours from KEV listing to mitigation on internet-facing assets. Separate that estate from everything else and give it a faster process with standing maintenance authority. Buy validation, not lists: the question is “is this reachable, and is it already blocked?” And build the compensating-control path — virtual patching, segmentation, exposure removal — because it is the only one that operates within hours.


2. Identity is the control surface, and most of it is no longer human

What is changing. Enterprise identity used to be a human-resources problem with a technology component. It is now a machine-population problem. Service accounts, API tokens, workload identities, CI/CD credentials and autonomous agents outnumber employees by one to two orders of magnitude, are created at machine speed, reviewed at human speed, and mostly belong to nobody. This is the single highest-confidence trend in the library — four independent sources, four methods, one conclusion.

The evidence.

  • Kurtz and Krawiecka (2026) triangulate five sources. Entro Labs: non-human identities grew 44% year on year and outnumber humans 144:1, up from 92:1. ESG: 20:1 on average, with two-thirds of organisations having suffered a successful attack via a compromised non-human identity. Research and Markets: 17:1 conservatively, 96:1 in financial services. Veza, across 230 billion permissions: permissions classified safe and compliant fell from 70% to 55% in one year while ungoverned permissions rose from 5% to 28%, and one in twenty AWS machine identities carries full administrator privilege (pp. 18–19).

  • Governance is nowhere near. CyberArk’s survey of 2,600 decision-makers in 20 countries: IAM teams are responsible for only 44% of machine identities, 68% lack identity security controls for AI, and 47% cannot secure shadow AI usage at all.

  • The incidents are costed. The July 2024 CrowdStrike outage — one ungoverned automated update agent across 8.5 million systems — produced $5.4bn in Fortune 500 losses and up to $10bn globally, insured at 10–20%. 23.7 million secrets were exposed on public GitHub in 2024, 26% in CI/CD workflows. The Marks & Spencer intrusion, which began by impersonating an employee to a third-party IT provider, ended in 46 days of suspended online ordering and roughly £300m of lost operating profit.

  • State actors got there first. Silk Typhoon, Salt Typhoon and Volt Typhoon have operationalised ungoverned machine credentials as primary espionage vectors, with privileged-access-management provider credentials a named Silk Typhoon target. Microsoft’s formulation of the era: “adversaries aren’t breaking in, they’re logging in” (2025, p. 5).

Why it is happening. Three structural reasons explain why incremental IAM spending has not worked: the visibility problem — no authoritative registry of which machine identities should exist; the governance velocity mismatch — identities minted by infrastructure-as-code in seconds, reviewed by humans in quarters; and identity debt, which “has compounding dynamics that existing IAM approaches are not reversing” (p. 20).

Who is building for it.

  • CyberArk — privileged access extended to machines and agents · acquired by Palo Alto Networks for ~$25bn, closed 11 February 2026, on ARR of $1.44bn, and relaunched as “Idira”. It had already bought Venafi, the machine-identity and certificate company, for $1.54bn in 2024.

  • Astrix Security — non-human identity, the category it named · acquired by Cisco, completed 29 June 2026, at roughly $400M on about 120 staff. Its $45M Series B (December 2024) was led by Menlo Ventures through the Anthology Fund it runs with Anthropic — a frontier lab’s venture arm funding agent identity a year before anyone measured the problem.

  • Cyera — valued at $12bn in June 2026 · bought Oasis Security for about $1bn (completed 3 September 2026), Ryft for $100–130M and Otterize: a data-security company buying into machine identity because the two problems turned out to be one. CrowdStrike paid $627.9M for SGNL in January 2026.

  • Silverfort — agentless multi-factor authentication inside the authentication layer, across more than 10 billion authentications a day · $222M raised, last priced near $1bn. The pattern worth noticing across all of them: the money moved to identity before the incident data did — the one place in this report where the market ran ahead of the telemetry rather than behind it.

The hype check. The direction is unanimous; the magnitude is not. 144:1 comes from one vendor’s telemetry, and the four estimates disagree by an order of magnitude — 144:1 against 17:1. Gartner’s projected 45 billion agentic identities is a forecast, not a count. The defensible claim is “machine identities outnumber humans by at least an order of magnitude, are growing fast, and are largely ungoverned”, which every source supports. The second overstatement is that non-human identity is a new category: service accounts have been the weakest link since Kerberos, and much of what is sold as NHI governance is privileged access management relabelled.

Falsifier: a vendor-neutral census — the kind NIST’s NCCoE agent-identity project could produce — finding machine-to-human ratios stable, or the share of breaches involving machine credentials flat in the next DBIR. Watch the insurers too: 88% of organisations already report insurers mandating enhanced privilege controls for machine identities, and a withdrawal would signal the loss data does not support it.

What to do about it now. Build the registry before the controls — you cannot govern a population you cannot count. Adopt zero standing privilege and just-in-time credentials as the target state, with SPIFFE/SPIRE as the workload identity standard, because both remove credentials at rest. Give every agent its own identity, never a borrowed human one: without one, an agent “operates in an attribution gap that makes enforcing true least privilege impossible” (OWASP 2025, p. 15). And treat secret sprawl in source control as an identity problem — 23.7 million exposed secrets is a credential population, not a set of lint errors.


3. Offence has industrialised — and two real thresholds were crossed

What is changing. Not the taxonomy of attacks. The economics. AI has lowered the cost of reconnaissance, lure production, credential abuse, CVE-to-patch-gap matching, exploit adaptation and post-compromise decision support — Koch’s “attack compression”. The consequence is not that every criminal becomes elite, but that targets previously too small to justify a tailored operation are now economic.

The evidence.

  • Anthropic (2025) — GTG-1002 ran against roughly 30 entities in mid-September 2025 with the AI executing approximately 80–90% of all tactical work independently, orchestrated through Claude Code and open-standard MCP servers that decomposed each attack into tasks which “appeared legitimate when evaluated in isolation”. Tooling was commodity open-source pentest software; the custom work was integration. The jailbreak was social — operators role-played as employees of a legitimate security firm.

  • Google Threat Intelligence Group (2025) — “adversaries are no longer leveraging artificial intelligence just for productivity gains, they are deploying novel AI-enabled malware in active operations” (p. 2). PROMPTSTEAL, used by Russia’s APT28 against Ukraine, queries Qwen2.5-Coder-32B through the Hugging Face API to generate Windows commands at runtime — the first observation of malware querying an LLM in live operations. PROMPTFLUX queries Gemini hourly to rewrite its own source for evasion. The underground market for illicit AI tooling “has matured in 2025”.

  • Verizon (2026) is the counterweight from the same period: median AI-assisted malware had 55 known precedents, and fewer than 2.5% of observations involved a technique with one or fewer known examples (p. 12).

  • Social engineering went mobile and vocal: human element in 62% of breaches; median click rates on voice and text vectors 40% higher than email. ENISA reports AI-supported phishing at “more than 80 percent of observed social engineering activity worldwide” by early 2025.

  • Shadow AI became an insider-risk category: 67% of users access AI services from non-corporate accounts on corporate devices, regular AI users rose from 15% to 45%, and the most commonly exfiltrated data type is source code (p. 13).

Why it is happening. Because capability is being packaged, not invented. Anthropic’s conclusion is the proliferation argument: “cyber capabilities increasingly derive from orchestration of commodity resources rather than technical innovation” — and an orchestration layer over commodity tools is cheap to copy. Koch’s dated forecast is the most useful planning artefact in the library: 0–6 months, better lures and faster credential abuse; 6–18 months, semi-autonomous reconnaissance and targeting of AI agents and non-human identities; 18–36 months, crimeware-as-a-service packaging agentic workflows.

Who is building for it.

  • Dream Security — sovereign AI cyber defence sold to states · $260M at a $3bn valuation, June 2026, led by Group 11, on ARR above $100M from fewer than ten customers · in August 2026 its researchers published a four-day fully autonomous AI-agent intrusion into Asian government agencies, running up to eight sub-agents and taking 2,500+ records — the second documented case of the GTG-1002 pattern.

  • Irregular (formerly Pattern Labs) — measures the offensive cyber capability of unreleased frontier models for OpenAI, Anthropic, Google DeepMind and the UK government · ~$80M raised in September 2025 at about $450M, on roughly 25 people. It co-authored RAND’s model-weight security framework (SL1–SL5).

  • Pentera and Cymulate — continuous automated offence against your own estate, the only defensive control that scales the way attack compression does.

  • KELA — cybercrime intelligence on the market GTIG says “matured in 2025” · its 2026 report counts 2.86 billion credentials stolen in 2025 and 7,549 ransomware victims, up 45%.

The hype check. Two claims fail. “Autonomous AI attacks are here and everything has changed” — half true, and the caveat comes from the attacker’s own telemetry: Anthropic records that “Claude frequently overstated findings and occasionally fabricated data during autonomous operations, claiming to have obtained credentials that didn’t work”, and calls hallucination an obstacle to fully autonomous attack. GTIG is equally careful on influence operations: “None of these attempts have created breakthrough capabilities for IO campaigns”. “Every criminal is now an elite hacker” — refuted by Koch and the NCSC and OpenAI assessments he cites: “The expected change is not universal elite capability; it is capability packaging”.