Find notable cyber news and cases, enriched with sources, timelines, and signals.

Cloud and SaaS targeting shifts toward identity, email auth, and non-human accounts in H1 2026

Trend
First reported
Last updated
Happening score
H score 28
1 unique sources, 1 articles

Summary

Hide ▲

Cloud and SaaS environments became top targets in H1 2026, with attackers shifting from malware and vulnerability exploitation toward identity compromise and trust-layer abuse. The trend expands risk across email authentication, cloud entitlements, supply chains, AI gateways, remote administration tooling, and non-human identities.

Related Happenings

Global phishing and identity-compromise trend across Darktrace customers in 2025

Trend
H score61 First: 26.02.2026 17:00 Last: 26.02.2026 17:00 Sources 1

About this happening: Darktrace telemetry showed a sharp rise in identity-driven phishing across its global customer base in 2025, with more than 32 million high-confidence phishing...

Timeline

  1. 04.08.2026 14:30 2 articles · 2h ago

    Attackers target cloud and SaaS identities across email, supply chains, and AI gateways

    Campaign Scope Update

    Darktrace reported that attackers in H1 2026 increasingly targeted cloud and SaaS environments by compromising identities and abusing trust controls rather than relying on malware or vulnerability exploitation. The shift extended to email authentication, cloud entitlements, software supply chains, AI gateways, remote administration tooling, and non-human identities, with examples including inbox rule changes, phishing, and a compromised SaaS account that drove activity across email, SaaS, and network layers.

    Show sources