Industry executives and experts share their predictions for 2026. Read them in this 18th annual VMblog.com series exclusive.
By Chris Usserman, Global Public Sector CTO, Infoblox
The cyber threat landscape is entering a new era of convergence: where artificial intelligence, service-based criminal economies and hyper-connected digital ecosystems collide. By the end of 2026, attackers will no longer be limited by skill or scale. Instead, they’ll operate within a fully industrialized cybercrime economy, leveraging AI-powered tools and outsourcing everything from exploit kits to network access. At the same time, supply chain and IoT vulnerabilities will expand the attack surface exponentially, creating cascading risks across entire industries.
As cybercriminals harness AI to refine evasion and persistence techniques, their innovations may unintentionally shine a light on stealthier nation-state operations embedded in the same environments-blurring the boundaries between cyber espionage and financially motivated attacks. Meanwhile, regulators and enterprises alike will intensify their push for ‘security by design’ and enforce Zero Trust principles more rigorously to keep pace. The result: a faster, more unpredictable threat environment where technology, regulation and human ingenuity collide in a high-stakes race for resilience.
The Rise of Cybercrime-as-a-Service (CaaS)
Gone are the days when a cybercriminal’s impact was limited by their expertise. Fueled by an AI-enabled underground economy, financially motivated threat actors are already leveraging ready-made services – from exploit kits and ransomware frameworks to stolen credential marketplaces and initial access brokers.
In 2026, this CaaS economy will reach new levels of maturity, allowing even novice adversaries to orchestrate advanced, multi-stage attacks using AI tools. The traditional distinction between opportunistic hackers and elite cybercrime groups will continue to blur, amplifying both the scale and sophistication of financially motivated attacks.
AI-Enabled Innovation and the Irony of Exposure
There’s been growing media attention to “AI-ware”: malware that’s directly leveraging AI as part of the attack chain. However, real-world examples of this remain scarce – highlighting a gap between alarmist narratives and operational reality. Still, the rapid evolution of AI, autonomous agents and scalable compute suggests that this gap may not remain wide for long. That said, in the race to weaponize AI, cybercriminals will likely pioneer novel methods in the race to “root” – including advances in vulnerability, information and trust exploitation, as well as new techniques for evasion and persistence. Yet, innovation comes with unintended consequences. In their attempt to outsmart defenders, some cybercriminals may inadvertently shine light on stealthy nation-state campaigns that have been operating undetected for years.
This irony, where financially driven intrusions expose geopolitical espionage, could make headlines. It will also reveal how AI experimentation by cybercriminals is reshaping not only threat and defense tactics, but also the global intelligence landscape itself.
The Expanding Attack Surface
Third-party vendors and managed service providers will become prime targets in 2026. Threat actors recognize that compromising one trusted intermediary can unlock access to hundreds of downstream customers: a “one-to-many” model already seen in major supply chain breaches.
As a result, organizations will face mounting pressure to extend Zero Trust principles beyond their internal boundaries. Expect to see increased investment in continuous vendor monitoring, stricter certification and compliance demands, and a greater emphasis on visibility into partner networks.
IoT as the Perennial Blind Spot
From factory floors to hospital wards, billions of connected devices now form the invisible backbone of critical operations. Unfortunately, these Internet of Things (IoT) endpoints often remain minimally secured, making them easy entry and bounce points for attackers.
In 2026, IoT exploitation will remain a go-to tactic for gaining initial access and moving laterally within networks. Yet, momentum is building for change. New regulations, such as cybersecurity requirements for medical device manufacturers, signal a shift toward security-by-design as both a regulatory and market imperative.
Enterprises must prepare for intensified compliance scrutiny and embrace DNS- and network-layer defenses (such as those aligned with the forthcoming NIST 800-81r3 update) to secure even unmanaged or agentless assets.
The convergence of AI innovation, service-based cybercrime, and expanding digital ecosystems will make 2026 a defining year for financially motivated threat actors. As their tools become more accessible and their methods more unpredictable, defenders will need to evolve just as quickly: adopting automation by default, intelligence-driven security, and a holistic Zero Trust approach to stay ahead in this escalating cyber arms race.
##
ABOUT THE AUTHOR
Chris Usserman brings over 35 years of US Intelligence Community (IC) expertise, specializing in both offensive and defensive cyber operations. Currently at Infoblox, Chris is pivotal in collaborations with CISA, the Department of Defense, the 5EYES intelligence alliance, and extended partner nations to actively shape global cybersecurity strategies and enhancing international cyber defenses.






