Threats

Biggest Cybersecurity Threats to Companies

The threat everyone talks about isn't the one hitting you#

Walk into any security conference this year and you'll hear about self-modifying AI malware and criminal gangs running their own neural networks. It makes for a great keynote. It's not what shows up when I get the incident-response call.

The reality is more boring, and that's exactly why it works. Nobody needs a supercomputer to get into a corporate network when they can just ask for the admin's login. Attackers pick the path of least resistance, and in 2026 that path runs straight through your people and their digital identities - not your firewalls.

I spend my time on both sides: breaking into companies with permission, and cleaning up after the people who did it without. Here's what's actually working right now, and what stops it.


1) Identity attacks: why pick the lock when you have the key#

Endpoint detection (EDR) got genuinely good. So attackers largely stopped hunting for software bugs. Buying or stealing a valid user's credentials is cheaper, faster, and quieter than burning a zero-day.

The important shift: MFA is no longer a wall, it's a speed bump. The technique behind most of the account takeovers I see is Adversary-in-the-Middle (AitM). Using off-the-shelf phishing kits like Tycoon 2FA or Evilginx, the attacker sits between you and the real Microsoft or Google login page. You type your password, you approve the push, everything works - because it's the real site behind the proxy. What they walk away with isn't just your password; it's your live session token (the cookie that proves you already passed MFA).

With that cookie replayed into their own browser, they're inside your Microsoft 365 or SaaS tenant with no second prompt, because as far as the system is concerned MFA already happened. From there it's mailbox rules, OAuth app consent, and privilege escalation through Entra ID or Active Directory.

The lesson: the kind of MFA matters more than whether you have MFA. SMS and app-approval MFA both fall to AitM. Only phishing-resistant factors survive it (more on that below).


2) ClickFix: the copy-paste attack that skips your email filter#

Your staff got better at not clicking sketchy attachments. Good. So the attackers moved the malicious step out of email entirely.

ClickFix is the technique of the year. You land on a page - often a fake Cloudflare or CAPTCHA "verify you're human" screen, or a bogus "your browser needs to fix this" error. (The consumer cousin of this is smishing - same social engineering, delivered by text.) It tells you to press Win+R, paste in a "verification code," and hit Enter. That code is a PowerShell or mshta command already copied to your clipboard. There's no attachment and no download for a filter to catch, because you are the delivery mechanism.

The result is that the victim runs the loader by hand, which pulls down an infostealer (Lumma, StealC and friends) or a ransomware foothold. A newer twist, sometimes called FileFix, tricks users into pasting the command into the File Explorer address bar instead - same idea, different box.

The tell is simple and worth drilling into people: no legitimate website will ever ask you to open PowerShell, the Run box, or a terminal and paste something in. Ever.


3) Abusing the tools that are supposed to help (RMM abuse)#

Attackers love "living off the land" - using software that's already trusted so nothing looks out of place. In 2026 the favourite is remote monitoring and management (RMM) tools: ConnectWise ScreenConnect, Atera, Tactical RMM, MeshAgent.

These are signed, legitimate IT admin tools, which is precisely the point. An attacker gets a foothold (often via the ClickFix trick above), silently installs a real RMM agent, and now has full hands-on-keyboard remote access that your EDR is inclined to trust because it's a known-good product. No custom malware to detect, no obvious command-and-control.

If your IT team uses one RMM tool, every other RMM tool running in your environment is a red flag worth investigating today.


4) The identities nobody's watching (machine identities)#

We pour attention into human accounts and forget the non-humans. API keys, service accounts, CI/CD pipeline tokens, containers, OAuth app integrations - every one of them authenticates to something, and there are now far more of them than there are employees.

These machine identities are the soft underbelly: they usually have no MFA, they're often over-permissioned ("it worked, ship it"), their secrets get hard-coded into repos and config files, and they rarely get rotated. Attackers hunt them deliberately - a single leaked long-lived cloud key or a service account with domain admin is a faster route than any human login, and it doesn't trip "impossible travel" alerts the way a person's account might. Supply-chain access through managed service providers (MSPs) makes this worse, because their tokens often reach into dozens of client tenants.


5) Supply chain: worms in your dependencies#

If you write software, this one is aimed at you. The Shai-Hulud worm that tore through the npm ecosystem was a genuine escalation, not a theoretical one. It wasn't just a poisoned package - it was self-replicating. Once it infected a maintainer's machine, it used their credentials to inject itself into the other packages they published, spreading on its own.

And it wasn't there to vandalize. It ran secret-scanning (using tools like TruffleHog) across the developer's environment to harvest cloud credentials, npm tokens, and GitHub secrets, then exfiltrated them - in some waves by publishing them to public repositories. One compromised laptop could poison a chain of widely-used packages and drain the cloud accounts behind them.

The takeaway: your security posture now includes every dependency you pull, and the machines of the people who maintain them. If you run Node anywhere in your stack, CISA's alert on the npm compromise and Unit 42's technical breakdown are the two worth reading in full - particularly the part where removing the bad package does not end the compromise, because the credentials it already harvested stay valid until you rotate them.


How to actually defend against this#

Notice that none of the above is beaten by a better AI. It's beaten by hygiene, visibility, and treating identity as the perimeter. The strategy shift is from "guard the network edge" to Zero Trust - verify every request, trust nothing by default.

Concretely:

  • Go phishing-resistant on MFA. SMS and app-approval codes don't stop AitM. FIDO2 passkeys and hardware keys (e.g. YubiKey) do, because the credential is cryptographically bound to the real domain and there's no code or token to steal through a proxy. Start with email, admin, and finance accounts.
  • Shorten and shrink sessions. Reduce token lifetimes and require re-authentication for sensitive actions, so a stolen cookie has a short shelf life. Bind sessions to the device where you can.
  • Allowlist your remote-access tools. Decide which RMM tool IT uses, and block every other one by default. Anything unapproved should be an instant alert, not a shrug.
  • Watch what leaves, not just what arrives. Beacons, exfiltration and unapproved tooling all show up as outbound connections. Most default host firewalls - macOS's included - only inspect inbound traffic, so egress is the direction nobody is looking at.
  • Least privilege, for machines too. Scope service accounts tightly, kill standing admin rights, and rotate secrets automatically from a vault - not from a spreadsheet. Inventory your non-human identities; you can't protect what you can't see.
  • Scan your supply chain. Pin dependency versions, watch for suspicious new package releases, scan repos and build environments for leaked secrets, and lock down publish tokens with hardware-backed MFA.
  • Train for ClickFix specifically. The one rule that stops it: a real website never asks you to paste a command into PowerShell, Run, or File Explorer. Make sure everyone knows that sentence.

Cybersecurity in 2026 isn't a contest over who has the smartest algorithm. It comes down to hygiene, visibility, and understanding that your employees' identities are now the front line of your defence. Protect those, and you've shut the door on most of what I see actually working.


Summary#

  1. Identity is the perimeter. Attackers log in far more often than they break in - stolen sessions and adversary-in-the-middle proxies beat passwords and codes alike.
  2. Move email, admin and finance accounts to passkeys or hardware keys first. They're the only MFA that survives an AitM proxy, because the credential is bound to the real domain. See password best practices for the how.
  3. Cut session lifetimes. A stolen cookie is only useful while it's valid; short tokens and step-up auth on sensitive actions shrink the window.
  4. Allowlist your remote-access tooling. Pick the RMM your team uses, block the rest by default, and alert on anything unapproved.
  5. Inventory machine identities. Service accounts and API tokens outnumber your staff and usually have standing privilege nobody reviews.
  6. Treat dependencies as part of your attack surface. Pin versions, scan for leaked secrets, and put hardware-backed MFA on publish tokens.
  7. Teach the one ClickFix sentence: no legitimate website ever asks you to paste a command into PowerShell, Run or File Explorer.

This is general threat guidance, not a security assessment of your specific environment. If you want to know how your organisation would hold up against these techniques, a penetration test or phishing simulation will tell you far more than any checklist. Get in touch.

Subscribe

Get new posts as we publish them

We publish hardening guides, threat notes and a weekly cybersecurity roundup. Add our feed to your reader and new posts turn up on their own - no email address, no account, no tracking.

Subscribe via RSS

New to feeds? A reader such as NetNewsWire, Feedly or Thunderbird watches this URL for you: https://bluwarden.com/feed.xml