H1 2026 Threat Report: Attackers Are Hiding in Plain Sight, Not Breaking In
New research from Recorded Future shows that in the first half of 2026, cybercriminals continued to favour a stealthy strategy: using legitimate software, developer tools, remote access utilities, payment systems, and third-party services already present in business environments to break in, steal credentials, move around networks, and cash out. Rather than relying on new technical tricks, attackers are exploiting the trust businesses place in everyday tools, making malicious activity harder to spot until real damage is done.
The report also highlights the growing role of artificial intelligence in cyberattacks, though its impact so far has been more of an accelerant than a revolution. AI is helping researchers and attackers alike find vulnerabilities faster, which could shorten the window businesses have to patch before an exploit appears. On the malware side, AI is mostly being used for specific tasks such as maintaining persistence on infected systems, mimicking user interfaces, and assisting with malware development and delivery, rather than running entire attacks on its own.
Together, these trends point to a threat landscape where evasion through normal-looking activity is just as dangerous as outright technical novelty. Recorded Future stresses that businesses need stronger management of their exposed systems, tighter control over identities and credentials, better behavioural detection, secure development practices, resilient backups, fraud monitoring, and closer oversight of third-party vendors.