Industry executives and experts share their predictions for 2026. Read them in this 18th annual VMblog.com series exclusive.
By Andrew Speir, Vice President of Advanced Cyber Solutions at Core4ce
Over the next year and beyond, cyber operations will be defined less by isolated attacks and more by sustained, automated campaigns designed to quietly shape geopolitical and economic outcomes. Artificial intelligence and automation are enabling threat actors to scale reconnaissance, personalize social engineering, and maintain persistent access with minimal human involvement, often by exploiting basic identity and access weaknesses that many organizations continue to underinvest in addressing. What once required skilled labor is now infinitely repeatable, fundamentally altering the economics and speed of cyberattacks.
At the same time, these capabilities are being applied more deliberately against critical infrastructure, healthcare systems, and the digital supply chains that support them. The shift is less about new threats and more about how existing capabilities are being applied. Cyber activity is becoming more strategic, more automated, and harder to detect, and 2026 will push these pressures to a new level.
1. AI-Augmented Social Engineering Will Reach Unprecedented Scale
Social engineering is no longer a supporting tactic, it will be the primary delivery mechanism for intrusion at scale. Large language models enable threat actors to conduct highly personalized spear-phishing campaigns with near-perfect grammar, cultural context, and real-time conversational adaptation. Increasingly Autonomous AI agents will be used to perform reconnaissance, build psychological profiles, and execute multi-stage attacks with minimal human supervision. The economics have shifted. What once required skilled labor can now be executed repeatedly and at scale, making social engineering faster, more convincing, and far more pervasive than previous campaigns.2. Supply Chain and Firmware Attacks Will Become Strategic Weapons
Expect expanded targeting of Unified Extensible Firmware Interface (UEFI) firmware, Baseboard Management Controllers (BMCs), and hardware supply chains as adversaries prioritize persistence over immediate disruption. These attacks provide pre-boot persistence access that survives operating system reinstallation and evades most detection tools. The strategic value lies in long-term access and quiet pre-positioning, consistent with the approach demonstrated in Volt Typhoon operations.3. “Store Now, Decrypt Later” Will Shift From Long-Term Theory to Near-Term Risk
The prospect of future quantum decryption is already shaping how adversaries collect data today and will increase. Nation-state actors are aggressively harvesting encrypted communications, biometric databases, and cryptographic keys in anticipation of quantum capabilities. Because many forms of sensitive data retain value for 10-20 years, encryption that is sufficient today may not protect information over its full lifespan. Even seemingly innocuous applications, such as aging apps that request camera access, may store biometric images indefinitely, creating data troves vulnerable as quantum decryption matures. Any data with long-term sensitivity, including state secrets, biometric records, and financial information, is exposed to this risk.4. Adversarial Machine Learning Will Target the Models Themselves
As organizations rely more heavily on AI-driven detection and decision-making, attackers will focus less on bypassing perimeter controls and more on manipulating the models themselves. This will include adversarial inputs designed to bypass detection, poisoning of training data to introduce hidden biases or backdoors, and model-output manipulation that distorts operational decisions. Early research in autonomous systems has already demonstrated how subtle perturbations can mislead AI models, and these techniques will increasingly appear in facial recognition, fraud detection, and network security systems.5. Cloud, Identity, and OT Environments Will Remain the Most Exposed
The hardest environments to defend will be those defined by complexity, interdependence, and limited visibility. Cloud-native and multi-cloud architectures introduce sprawling attack surfaces driven by serverless functions, microservices, and identity permissions, where misconfigurations remain common and perimeter defenses are ineffective. OT and IT convergence zones continue to expose legacy SCADA and ICS systems that were never designed for connectivity and often cannot be patched without operational disruption. As the perimeter dissolves, identity becomes the primary security boundary, where a single compromised credential can enable enterprise-wide access.6. Cyberwarfare Will Intensify Below the Threshold of Armed Conflict
Cyber operations will play an even larger role in geopolitical competition without crossing into open conflict. Nation-states will expand gray-zone activities involving espionage, infrastructure pre-positioning, ransomware through proxies, and AI-enabled disinformation. Public acknowledgments of foreign access to national infrastructure signal a shift toward cyber presence as strategic deterrence. Critical infrastructure, energy, water, healthcare, and transportation, will remain a primary target, with attacks designed to produce cascading societal effects. AI-generated synthetic media and automated influence campaigns will further expand cognitive warfare against public trust and democratic processes.
Evolving Faster in 2026
As AI and automation transform both offensive and defensive capabilities, the cyber threat landscape is evolving faster than most organizations are prepared for. AI is not introducing isolated risks; it is amplifying every dimension of cyber activity, from individual targeting to nation-state competition, particularly across critical infrastructure, healthcare, and supply chains. Pressure is converging across identity systems, supply chains, critical infrastructure, and healthcare environments. Organizations that recognize this interconnected shift and adapt accordingly will be better positioned not just to respond to incidents, but to withstand sustained pressure as cyber operations continue to evolve beyond 2026.
##
ABOUT THE AUTHOR
Andrew Speir is the Senior Vice President of Advanced Cyber Solutions at Core4ce, where he leads a highly specialized team delivering cybersecurity services to federal and commercial clients. He built and now leads Core4ce’s Advanced Cyber Solutions business, bringing together seasoned cyber professionals with deep experience across offensive and defensive operations.
Under his leadership, Core4ce supports the Defense Health Agency by securing the global MedCOI network for more than 250,000 users and delivers defensive cyber operations as part of the Naval Information Warfare Center Atlantic Cyber Security Service Provider, one of only 23 USCYBERCOM-accredited providers.





