Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The most dangerous attack techniques reported in 2025 and 2026 combine familiar weaknesses—vulnerable software, stolen credentials and trusted developer tools—with faster exploitation and more automation. The five below are an editorial assessment of speed, scale, reach and likely impact, not an official ranking or a claim that every method is wholly new.

How the five techniques compare

The figures below come from separate reports with different datasets and methods. They should not be treated as directly comparable measures of prevalence or severity.

Technique Initial access or enabling weakness Speed and potential reach Evidence and likely impact
AI-assisted vulnerability discovery and exploit development AI used to research flaws, develop exploits or write malware Could shorten the path from vulnerability research to a usable exploit; mass exploitation was planned in the reported case GTIG reported a suspected AI-developed zero-day exploit, but said its discovery may have prevented the planned operation
Rapid exploitation of third-party software and zero-days Exposed enterprise, edge or other third-party software with a vulnerability Google Cloud observed disclosure-to-exploitation intervals shrink from weeks to days in H2 2025 Google Cloud’s observed initial-access data and GTIG’s 2025 zero-day tracking document the shift; successful exploitation can provide broad access to affected systems
Identity compromise through password spraying, vishing and stolen tokens Weak or reused passwords, social engineering, or SaaS tokens Can provide access across accounts and services; token theft may enable quiet data theft Microsoft and Google Cloud report substantial identity-related activity in their respective datasets, using different denominators
AI-assisted evasion and more autonomous operations AI-assisted obfuscation, decoy logic or agents that interpret system state and act May automate multiple stages; GTIG observed one campaign completed in under six hours after cloud resource compromise GTIG describes observed activity and experiments, not universal autonomous operation by attackers
Software-supply-chain compromise targeting developers and AI tools Trojanized packages or MCP servers, compromised developer accounts, and exposed CI/CD credentials A foothold in a developer environment can expose downstream projects, build pipelines and tools GTIG describes activity involving PyPI, npm, Docker Hub, CI/CD tokens and AI coding assistants

1. AI-assisted vulnerability discovery and exploit development

AI can help attackers research software, develop exploits and write malware. The important risk is that assistance may lower the effort or time needed to move from finding a vulnerability to attempting an intrusion; it is not evidence that AI routinely produces working zero-days.

In May 2026, Google Threat Intelligence Group (GTIG) reported identifying a threat actor using a zero-day exploit it believed had been developed with AI. The group planned a mass exploitation event, but GTIG’s counter-discovery may have prevented the exploit’s use. The report also describes AI-assisted research, exploit development and malware coding. Read GTIG’s account of AI-assisted vulnerability exploitation and initial access.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

2. Rapid exploitation of third-party software and zero-days

Attackers are exploiting vulnerable third-party software, including enterprise and edge systems, at a pace that leaves defenders less time to patch. Google Cloud Security writes that it observed “the window between vulnerability disclosure to active exploitation collapse from weeks to days” in the second half of 2025. In its observed initial-access vectors, third-party software exploitation rose from 2.9% in H1 2025 to 44.5% in H2 2025. Weak or absent credentials accounted for 47.1% in H1 and 27.2% in H2. These are Google Cloud observations, not measurements of all organizations or all attacks. See the Google Cloud Threat Horizons Report H1 2026.

GTIG tracked 90 vulnerabilities disclosed in 2025 that were exploited as zero-days; 43, or 48%, affected enterprise software and appliances. The dataset was cut off on December 31, 2025, and GTIG notes that the figures may change as incidents are discovered. A zero-day is a vulnerability exploited before a fix is available to the affected organization, so defenders may have little or no warning before an attack begins. GTIG’s 2025 zero-day review provides its tracking and scope.

3. Identity compromise through password spraying, vishing and stolen tokens

Identity attacks are not limited to guessing one person’s password or sending a conventional phishing email. Password spraying tries a small number of common passwords across many accounts; voice phishing, or vishing, uses calls or voice messages to manipulate people into granting access or sharing credentials. Stolen third-party SaaS tokens can let an attacker use an already-authorized session, potentially enabling data exfiltration without repeatedly prompting the victim to sign in.

Microsoft reports that 97% of identity attacks in its data were password-spray attacks. Separately, Google Cloud Threat Horizons reports identity compromise in 83% of observed compromises and describes a shift toward voice-based social engineering and harvesting third-party SaaS tokens. The figures have different publishers, datasets and denominators; they are not interchangeable estimates of the same thing. Read the Microsoft Digital Defense Report 2025 and the Google Cloud Threat Horizons Report H1 2026.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

4. AI-assisted evasion and increasingly autonomous operations

AI can also help attackers make malicious activity harder to recognize. GTIG describes AI-assisted obfuscation and decoy logic, as well as malware that can interpret system state and generate commands. Its reporting describes a progression from basic prompting toward agentic workflows—systems that can plan and carry out linked tasks with less step-by-step human direction.

In a Q2 2026 observation reported in September, GTIG said attackers compromised a cloud resource and then planned, built and executed an agent-enabled mass credential-harvesting campaign in under six hours. That is a documented example, not proof that criminal groups generally operate autonomously or that every step was performed without human involvement. GTIG’s report on the shift from prompting to autonomy distinguishes observed activity from broader assessments.

5. Software-supply-chain compromise targeting developers and AI tools

A software supply chain includes the packages, accounts, build systems and tools developers rely on to create and distribute software. Compromising one trusted component can give an attacker a route into projects or organizations that use it. GTIG describes UNC6780, also known as TeamPCP, targeting ecosystems such as PyPI, npm and Docker Hub, along with trojanized Model Context Protocol (MCP) servers and compromised developer accounts.

The reported activity includes stealing credentials and manipulating CI/CD tokens and AI coding assistants. CI/CD systems automate the building, testing and delivery of software; their tokens can grant access to code repositories, build jobs or deployment workflows. An attacker who gets into that chain may be able to move beyond a single developer’s machine. GTIG’s reporting treats developer environments and AI tools as part of the attack surface, rather than as inherently unsafe technologies. GTIG’s AI-threat reporting discusses these evolving operations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What organizations can do to reduce exposure

The reports point to familiar defensive priorities: strengthen identity controls, patch exposed software quickly, monitor cloud and SaaS activity, and protect software development and delivery systems. Because the techniques overlap, no single control addresses all five.

  • Reduce identity risk: enforce strong authentication, review privileged access, and monitor for unusual sign-ins, password-spray patterns and unexpected token use. Where a service supports it and users enroll it, a FIDO2 security key can provide a phishing-resistant sign-in option; it does not fix vulnerable software or prevent every form of social engineering.
  • Shorten patch exposure: maintain an inventory of internet-facing and third-party software, prioritize vulnerabilities under active exploitation, and verify that updates reach edge devices and appliances as well as servers and endpoints.
  • Improve cloud and SaaS visibility: review administrative changes, app authorizations and token activity, and make sure teams can investigate suspicious access across services rather than only within one product.
  • Protect development workflows: review dependencies and package sources, secure developer accounts, limit CI/CD token permissions and lifetime, and monitor build pipelines for unexpected changes or access.
  • Prepare for fast response: define who can disable credentials, revoke tokens, isolate a compromised resource and assess potentially affected software when an alert arrives.

The broader pattern in the 2025–2026 reporting is a combination of established entry points with faster exploitation, automation and new trust relationships. AI use is real but uneven: observed incidents and vendor assessments should not be mistaken for proof that every attacker can deploy autonomous, AI-generated attacks at scale.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.