Opens in a new tab
vmblog logo 2024 wht (updated)

Cloud Chaos and AI Havoc: My 2026 Cybersecurity Predictions

Share: 

David Marshall | Published: October 31, 2025

   

Industry executives and experts share their predictions for 2026.  Read them in this 18th annual VMblog.com series exclusive.  

By Matt Mullins, Head Hacker and Offensive SME, Reveal Security

We have seen a tumultuous 2025; massive SaaS breaches, vibecoded ransomware attacks, and insane cloud access identity token flaws. With all of this in mind, we aren’t out of the woods yet – I predict that 2026 will be just as wild, if not more so, given the nature of what we have seen emerging.

Azure in the Crosshairs

As more and more organizations migrate to the cloud, there will be more and more interesting attacks that emerge against Azure. AWS and GCP have a much more minimalist footprint due to their interest in providing IaaS as a solid infrastructure choice. Azure, given its unique Microsoft background, is much more interested in being the “core” of a hybrid environment. This might be due to their reign as the “core” of enterprises and business for years now. This comes at a cost though – with more and more interest in allowing a similar granularity of control via IdP and IAM in Azure, there will be more and more people focusing on ways to abuse it. The god-token flaw discovered should be alarming to anybody using their infrastructure. Aside from this, there have been a number of well defined flaws that allow attacks to go from on-prem to cloud as well as vice-versa. Due to these reasons, I predict we will see more flaws emerging that target Azure and more tradecraft emerging that causes high impact issues. 

AI Will Give Rise to Attack Automation

With the rise of AI, regardless of how effective it is, we will have a rise in attack automation. I know there are people who claim that red teaming, pentesting, etc. cannot be replaced (and to a degree that is true) by AI, or that AI creates a “negative space” issue with regards to coverage and capabilities, but all of these perspectives miss the most important part: attackers at a large scale aren’t utilizing novel attacks every time. Attackers use strategies that work on a macro scale for a number of reasons, be it blending of TTPs to obscure identification or simply cost of effort, and said reasons all will be augmented by the utilization of agentic/AI tradecraft. We can expect more, and faster, ‘typical’ breaches and ransomware attacks. 

Supply Chain Trust Falls

Given the previous point, we can also expect to see more breaches via connected services. We saw initial access to infrastructure being supplied by breached third parties, as well as connected services, multiple times in 2025. This isn’t a new issue at all and one could argue it’s just the same  supply chain attack that has migrated with the enterprise. Connected services, specifically things like GitHub, will become much more juicy as attackers step up their planning. Connected services via binaries (such as G-Drive for desktop, Slack, OneDrive) will also see more utilization from a tradecraft side. Candidly, this last bit shocks me considering that we haven’t seen more of that in the past year. 

Goodbye Malware, Hello Living-off-the-Land

My final prediction: a continued migration away from malware by threat actors in lieu of stolen credentials, leaked tokens, or valid tool abuse. This is already starting to uptick in recent breaches and I predict this will become normalized tradecraft by next year. For many years, EDR tooling became the hardest hurdle for Red Teams to breach, with some speculating that ceded access is the only real timely value add for multiple operations. There were even comments of the Red Team being merely the “EDR bypass team” since it absorbed so much operational time via R&D efforts. Adversaries have bypassed this hurdle by merely installing trusted tools that are already signed and deemed “safe” by organizations and OS developers. Since this drastically cuts down on development time, along with the utilization of AI for faster operations, we will see more attacks using this method in my opinion. To further this, the utilization of AI in social engineering will also be on the rise, pushing the attack chain time-to-target to be significantly less!

Detection Evolves or Dies

As attackers abandon malware and embrace automation, defenders need a new playbook. Static detection and signature-based models won’t cut it when adversaries are using your own tools against you.

That’s why at Reveal Security, we’re focused on AI-driven behavioral anomaly detection – using machine learning to identify identity-based attacks and insider threats before harm is done. The future of defense lies in understanding behavior, not just blocking code.

2026 will be the year that cybersecurity finally shifts from reacting to predicting. Those who fail to evolve will be left chasing ghosts.

##

ABOUT THE AUTHOR

Matt Mullins 

Matt Mullins is Reveal Security’s Head Hacker, executing as an Offensive Security SME, and is responsible for providing perspective with regards to internal testing, product validation, and general Red Team mindset. He is passionate about current TTPs, novel attacks, SaaS attack surface, emerging identity threats, and an avid fan of the ‘dark arts’ in general. Matt has extensive experience in Offensive Security ranging from penetration testing (from appsec to netsec) and Red Teaming (as an operator to building programs from scratch). His background includes Fintech, Financial Services, Healthcare, Startups, Gov, and more.