Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Cloud and SaaS Environments Now Top Targets for Attackers

August 4, 2026

Russia Charges Telegram Founder Pavel Durov With Aiding Terrorist Activity

August 4, 2026

WhatsApp Scam Hijacks Accounts via Linked Devices Feature

August 4, 2026
Facebook X (Twitter) Instagram
Tuesday, August 4
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Cloud and SaaS Environments Now Top Targets for Attackers
News

Cloud and SaaS Environments Now Top Targets for Attackers

Team-CWDBy Team-CWDAugust 4, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Cloud and Software-as-a-Service (SaaS) environments have become top targets for cyber-threat actors this year, according to a new report by Darktrace.

The cybersecurity firm noted that H1 2026 saw a continuation of an evolution observed in 2025 where attackers shifted away from malware and vulnerability exploitation towards compromising identities.

However, whereas in 2025 threat actors primarily targeted account credentials, the first half of 2026 has seen attacks extend to email authentication, cloud entitlements, software supply chains, AI gateways, remote administration tooling and non-human identities. Darktrace said this trend makes “trust” the new attack surface.

Compromised cloud and SaaS environments in particular provide enormous opportunities for attackers.

In one case highlighted by Darktrace, a single compromised SaaS account led to malicious activity across email, SaaS and network layers, such as inbox rule changes and the launch of phishing attacks. This type of attack is difficult to detect as none of the indicators were decisive in isolation, but together represented a clear intrusion.

The vendor also cited several cases where attackers exploited trusted digital supply chain infrastructure used by victims in H1 2026. This included threat actors in April hijacking Axios to spread remote access trojans (RATs). Axios is a JavaScript library downloaded over 100 million times a week and used as a dependency in countless developer environments and CI/CD pipelines.

Atatckers were also observed abusing legitimate blockchain infrastructure to distribute infostealers, including AMOS and Phexia. The researchers noted that such services are frequently used by users with limited security resources and often enable malicious actors to reach a far wider victim base.

“Increasingly, attackers do not need to bypass trust controls in these environments; they inherit them through compromised identities, delegated access, and legitimate administration tools,” the researchers noted in the report published on August 3.

Email Attacks Prioritize Quality Over Quantity

The study found that email-based attacks are growing in sophistication, with attackers investing in quality over “noise.”

Around two-thirds of phishing emails sent in H1 2026 passed the DMARC email validation protocols, which the researchers said show that authentication is no longer sufficient to protect accounts.

More than a third (37%) of phishing attacks contained a high volume of text in H1 2026, up from 32% in the same period in 2025.

In addition, 39% of phishing featured novel social engineering techniques and VIP users were targeted in 25% of observed attacks. This suggests that threat actors are increasingly customizing attacks to specific targets.

ClickFix social engineering, a technique designed to trick users into running malicious code themselves, continued to be a common attack vector from 2025.

AI is Growing the Attack Surface

The growing use of AI in enterprises has significantly expanded opportunities for cyber attackers, according to the Darktrace study.

This includes threat actors leveraging AI tools to launch attacks at scale. This was demonstrated with the use of AI-generated malware exploiting the React2Shell vulnerability, in which an attacker used an LLM to produce working exploit code and deploy it at scale.

In July, the world’s first fully AI-generated ransomware campaign, dubbed JadePuffer, was highlighted by security researchers. An agentic threat actor exploited a vulnerability in an internet-facing server before launching a fully automated ransomware attack.

“AI is accelerating the path from vulnerability disclosure to operational exploitation,” the Darktrace researchers wrote.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleRussia Charges Telegram Founder Pavel Durov With Aiding Terrorist Activity
Team-CWD
  • Website

Related Posts

News

Russia Charges Telegram Founder Pavel Durov With Aiding Terrorist Activity

August 4, 2026
News

Cybercriminals Bypass AI Safety Controls by Splitting Malicious Tasks

August 4, 2026
News

Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass

August 4, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA

July 11, 20268 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202523 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Why children’s data is a long-term identity risk

June 3, 2026

What parents should know to protect their children from doxxing

November 28, 2025

Is Poshmark safe? How to buy and sell without getting scammed

February 19, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.