of a nation-state campaign executed by AI — GTG-1002, disrupted Nov 2025
<1hr
first fully autonomous in-the-wild intrusion, start to finish (Sysdig / marimo)
autonomous-agent.log< 1 HR
01recon → mapped the environment
02exploit → pre-auth RCE, CVE-2026-39987
03harvest → pulled cloud credentials
04evade → fanned calls across many IPs
05pivot → secrets store → bastion host
06exfiltrate → full DB dump in under 2 min
›In GTG-1002, AI ran an estimated 80–90% of tactical work with only 4–6 human decision points, at thousands of requests per second.
›The limiter is real: models still overstate and fabricate findings, forcing human validation — and that tell is itself a detection signal.
03 — identity
Attackers log in. They don't break in.
~90%
of incident-response cases involved an identity weakness (Unit 42)
82%
of detections were malware-free — valid logins, not tools (CrowdStrike)
>10×
surge in device-code phishing in early 2026 (Huntress)
›Infostealers feed a liquid market in stolen tokens; attackers then abuse device-code and OAuth flows and adversary-in-the-middle kits to sidestep MFA entirely.
›One control blunts it all: phishing-resistant MFA plus short-lived, least-privilege tokens.
04 — ransomware
Consolidation at a high plateau
2,122
leak-site victims in Q1 2026 — second-highest Q1 on record
71%
of all victims claimed by just the top ten groups
Qilin
338
The Gentlemen
166
LockBit 5.0
163
Akira
150
Qilin led for most of H1 — until The Gentlemen overtook it in June 2026.
05 — the-edge
The catalog isn't enough
42%
of exploited flaws were used before public disclosure (CrowdStrike)
430K
FortiGate devices turned into passive credential harvesters
110M
credential sets captured in that single edge campaign
›Most exploited edge flaws never enter the CISA KEV catalog, and its backlog keeps growing.
›June 2026 — CISA replaced its flat directive with the risk-based BOD 26-04: rank by exposure and impact, not by list. Treat KEV as a floor, never a ceiling.
06 — your-ai
Your AI is an insider with valid tokens
>85%
success rate of prompt-injection, even against current defenses
26,000
AI agents hijacked by one fake "skill" in a trusted marketplace
›An agent reads a file, page, or repo that carries hidden instructions and treats them as commands — because models process trusted instructions and untrusted data as one stream.
›That makes indirect prompt injection an architectural problem, not a bug to patch. Least privilege on agents and human approval for irreversible actions are the real controls.
07 — the-counter
Fight machine speed with machine speed
If attackers operate at machine speed, defenders that stay human-speed lose the timing contest by construction. In May 2026, CrowdStrike embedded Claude into its Falcon platform — AI now hunts AI.
›The same capability that enables autonomous exploitation, under governance, becomes autonomous defense — which is exactly why the most capable models are gated behind cyber-safety measures.
›The realistic posture on both sides is human-supervised automation, not full autonomy on either.
08 — what-to-do
The edge you need isn't new tech. It's fundamentals.
01
Make identity the first line.Phishing-resistant MFA everywhere; control the device-code flow; short-lived tokens.
02
Prevent exfiltration, not just encryption.Egress control and DLP now matter as much as backups.
03
Prioritize by exposure and impact.KEV as a floor; blend EPSS and SSVC; internet-facing and end-of-life assets first.
04
Secure your own AI.Inventory agents and tokens, least privilege, human approval, assume injection.
05
Treat regulation as resilience.Rehearse tiered notification; document board oversight; map every jurisdiction.
09 — assume-breach
If they operate at machine speed, assume they're already inside.
The old model
Detect known malware
Match known signatures
Respond after the alert
→
The new reality
Faster than signatures can be written
Identity abuse leaves little or no malware
The attacker looks like a legitimate user
The question is no longer “Will they get in?” It's “How long before we find them?”
›Hunt behavior, not signatures: abnormal authentication, privilege escalation, lateral movement, persistence, and data-access anomalies — plus suspicious use of legitimate identities.
›Assume the attacker is present, assume persistence exists, assume something was missed. Success is measured by how fast you find and remove hidden access.
The goal is not to detect the attack. The goal is to find the attacker.
10 — code-blue
One platform to prepare and lead through the crisis.
All of Code Blue, orchestrated by Blue Castle
tap Blue Castle, CIR, or any capability for detail
A condensed, visual read of The Cyber Front — Global Semi-Annual Review (H1 2026). To receive the full report, contact Code Blue. info@codebluecyber.com
11 — full-picture
Want the full picture?
This interactive briefing highlights the key trends shaping the cyber landscape in H1 2026. For deeper analysis, additional data, and expert insights, access the full report.