Cloud and SaaS Environments Are Now Attackers' Favorite Targets
Want more insights like this?
Cybersecurity firm Darktrace says cloud and SaaS environments were attackers' top targets in the first half of 2026 — and increasingly their preferred operating environment, not just their destination. The shift is notable: threat actors have moved away from malware and vulnerability exploitation toward identity compromise, now extending attacks to email authentication, AI gateways, and software supply chains.
One compromised SaaS account triggered malicious activity across email, SaaS, and network layers simultaneously — the kind of attack that's hard to catch because no single indicator looks alarming alone. Attackers also hijacked Axios, a JavaScript library downloaded 100 million times weekly, to spread remote access trojans.
Email phishing is getting sharper too — two-thirds of phishing emails now pass DMARC validation. Meanwhile AI-generated malware, and JadePuffer — which researchers at Sysdig claim is the first ransomware campaign driven entirely by a large language model — signal that AI is closing the gap between vulnerability discovery and exploitation.
Source: Infosecurity Magazine