Industry executives and experts share their predictions for 2026. Read them in this 18th annual VMblog.com series exclusive.
By Andy Syrewicze, Security Evangelist at Hornetsecurity
Reflecting back on our predictions in 2025, cyber criminals acted as expected: Throughout the year, we have seen malicious use of AI, the rise of convincing deepfakes, increased AI-related legal and regulatory hurdles, and a surge in malicious software.
As we head into 2026, the year will be defined by the accelerating AI arms race between defenders and attackers. Adversaries will leverage agentic AI to automate complex attacks, forcing defenders to close gaps created by rapid technology adoption. Our predictions highlight three key focuses for the upcoming year: AI and automation threats, persistent identity and access vulnerabilities, and the rise of new attack surfaces.
The escalation of AI and automation threats
The adoption of AI across organizations is creating a complex new threat landscape, where the speed of innovation is outpacing security protocols and enabling sophisticated, low-effort attacks.
- Uncontrolled AI adoption: Organizations are adopting AI faster than security teams can keep up, leading to critical visibility gaps and an expanded attack surface which can lead to prompt injection and data leakage.
- Weaponization of agentic AI: Autonomous AI systems are already being weaponized to lower barriers for attackers, enabling them to script and launch multi-vector campaigns covering the entire attack lifecycle with minimal expertise.
- Ransomware 3.0, integrity-focused: Ransomware is evolving past simple encryption and exfiltration. The next phase involves LLM-driven orchestration and a shift to data integrity manipulation to compromise trust and create prolonged chaos.
While AI can be used for assistance and greater efficiency on the one hand, business leaders are concerned that AI use by threat actors will expose them to more attacks. In Hornetsecurity’s 2026 Cybersecurity Report, we noted that 77% of CISOs identified AI-generated attacks as serious and emerging threats.
It is imperative that heading into 2026, organizations remain even more vigilant of AI usage.
Exploitation of weak identity and access management
Identity has become a major key for cyber-attacks, and threat actors are finding new ways to exploit weaknesses in authentication and recovery processes, even bypassing robust security measures like standard multi-factor authentication (MFA).
- Attacker-in-the-middle bypasses MFA: Phishing kits are routinely bypassing standard MFA to steal tokens. Phishing-resistant MFA such as FIDO2 keys and passkeys must become mandatory.
- Identity verification is a major flaw: Account enrolment and recovery processes, especially for admin accounts via outsourced help desks remain a weak link, proving that security is measured by how hard it is to subvert recovery, not just daily login.
- Passkey adoption slowed by UX: Passkeys are the future of phishing-resistant MFA, but adoption is hindered by fragmented user experiences and the challenge of managing non-syncable corporate credentials.
Not cutting corners is the key to ensuring sensitive information remains secure going into 2026. For example, in September of this year, a ransomware attack completely halted Jaguar Land Rover production across its factories in the UK, Slovakia, Brazil, and India. Even four weeks after the incident, only limited production had resumed, indicating the massive scale of the disruption. The incident has had a huge financial impact, affecting Jaguar Land Rover and over 5,000 organizations in its supply chain, with some suppliers expected to go bankrupt. Unfortunately for Jaguar Land Rover, they reportedly did not have adequate cybersecurity insurance, forcing them to bear the full cost of the disaster.
This goes to show that staying prepared for an incident is always the best strategy rather than scrambling to rectify a situation once a disaster occurs. An incident such as a ransomware attack can become extremely costly and can lead to long-term effects that organizations might not be able to recover from.
The expansion of new attack surfaces
Traditional perimeter defences are becoming less effective as critical data and corporate identities move beyond the network to the cloud and the end-user’s browser. Organizations must focus on securing these new, highly accessible surfaces.
- SaaS Aapps are the new attack surface: Attacks increasingly bypass traditional network defences and EDR by compromising cloud data and identities through the browser, making specialized browser protection essential.
- Browser extensions are a growing risk: Both vulnerable and malicious browser extensions are becoming a major vector for compromise, necessitating better tracking and blocking mechanisms.
This past August, the compromise of the Salesloft-Drift integration was revealed, prompting the disabling of the associated Drift integration. This supply chain attack involved breaching Salesloft’s resources to steal OAuth tokens belonging to Drift’s customers. OAuth tokens are really powerful, and once they are in the threat actor’s possession, only revoking them and the integration itself will protect you, not through MFA or resetting credentials.
This demonstrates that organizations need to prioritize updated security defences in the new year, as customers are consistently at threat of sensitive information being compromised. Due diligence is essential to ensure we are taking the proper precautions to protect ourselves.
Strategic threats and long-term cyber challenges
While some threats may seem distant, the time to prepare is now. Planning for cryptographic shifts is essential to prevent future compromises from current data harvesting activities. This includes making plans for quantum computing.
While a Cryptographically Relevant Quantum Computer (CRQC) is years away, organizations must start migrating to quantum-resistant algorithms such as the new NIST standards FIPS 203, 204, 205, today to thwart “Harvest Now, Decrypt Later” threats.
The accelerating pace of threats requires a shift from reactive defence to proactive cyber resilience. By focusing on identity controls, securing new cloud-based attack surfaces, and adopting future-proof strategies against AI-driven threats and quantum computing, organizations can transform these predictions into actionable defence plans. AI will continue to advance rapidly in 2026 so the time for strategic preparation is now.
##
ABOUT THE AUTHOR
Andy Syrewicze, Security Evangelist at Hornetsecurity
Andy is a 20+ year IT Pro specializing in M365, cloud technologies, security, and infrastructure. By day, he’s a Security Evangelist for Hornetsecurity, leading technical content. By night, he shares his IT knowledge online or over a cold beer. He holds the Microsoft MVP award in Security.






