Industry executives and experts share their predictions for 2026. Read them in this 18th annual VMblog.com series exclusive.
By Chris Wallis, Founder and Chief Executive Officer (CEO) at Intruder
The cybersecurity industry finds itself navigating the hype of artificial intelligence (AI) while grappling with persistent, often simple threats that continue to cause the most widespread damage. Cyber experts must attempt to avoid the distractions of the flashy threat of AI and focus on the fundamentals. For years, the narrative has centered on an escalating arms race, however the reality is much simpler. While AI will undeniably impact the velocity and volume of attacks and provide new attack vectors through vibe coding, the core successful strategies for both attackers and defenders remain tethered to fundamentals. Next year, the industry must confront the gap between future-focused hype and today’s operational reality.
The Hidden Flaws of AI-Accelerated Code
In 2026, defenders will see more vulnerabilities introduced by AI-generated code. Vibe coding as a practice will become more widespread. Compounding this threat is the lack of security review processes that can handle the increased volume of code. These processes are overwhelmed by the combined development speed and the additional abstraction inherent in AI-generated code.
However, defenders won’t always be able to identify the source as AI. Most developers will be committing AI-assisted code under their own names, effectively obscuring the origin of the weakness. This lack of traceability makes the problem uniquely challenging.
Patching Fast: Rethinking Prioritization in Vulnerability Management
The financially motivated ransomware gangs (including basic, low-sophistication ones) will increasingly take advantage of exploitation windows for simple vulnerabilities. For example, the React2Shell vulnerability was exploited within hours of discovery. For defenses to be effective, they must be able to respond in a similar timeframe.
This constant low-effort, timely targeting necessitates a shift in defensive strategy for organizations that do not wish to become targets. Prioritizing vulnerabilities based on exploitability (either known exploited or highly likely to be) will become a necessity for defenders. Linking this with intel about which exploitable vulnerabilities have an attack path to sensitive information or systems will increasingly become the norm. Due to this trend, annual and quarterly pentests will no longer be viable in this environment. Nothing but responsive immediate scanning will do for companies wanting to avoid breaches.
Stop AI Fear Mongering: The Power of Simple Attacks
AI attackers don’t require AI defenders. All AI is doing is making existing attacks slightly easier to scale (like crafting better phishing emails), we already had tools doing that-just not Large Language Models (LLMs). The real threat landscape is dominated by the same simple, effective attacks that have worked for decades. Vendors may claim that “AI enabled nation state actors are weaponising polymorphic malware, the AI browser is the new attack surface,” however the reality is that a teenager in their bedroom is going to call your help desk and ask them to reset your admin password like it’s 1989. And they’re going to do it.
The industry needs to pivot away from the hype-driven arms race and return to solving the simple, repeatable flaws that lead to 99% of successful breaches.
Preparing for the Future
There is a stark difference between the tens of thousands of vulnerabilities released annually and the few vulnerabilities that eventually lead to breaches. Defenders are attempting to make this distinction but gaps still exist. Moving forward, successful vulnerability management will refocus on the nature of vulnerabilities identified, as opposed to just the quantity. Identifying which vulnerabilities will cause the most damage if unaddressed is the question defenders need to be able to answer in order to effectively prioritize.
##
ABOUT THE AUTHOR

Chris Wallis is Founder and Chief Executive Officer (CEO) at Intruder. He has previously worked as Senior Security Specialist at WorldPay, Lead Security Consultant at Context Information Security and Security Consultant at Deloitte. Chris is an alumnus of the University of Bath.





