Unit 42 Global Incident Response Report 2026

This year’s Palo Alto Networks report outlines key trends in cyber threats and highlights insights into evolving attack tactics and defensive strategies.

  • Thursday, 26th February 2026 Posted 2 months ago in by Sophie Milburn
Palo Alto Networks has released its latest Unit 42 Global Incident Response Report, analysing more than 750 incidents across 50 countries. The findings provide insight into current cyber threat trends and outline observations on evolving attack strategies and security considerations.

The report notes a shift in how artificial intelligence is being used in cyber attacks. According to the findings, threat actors are operationalising AI to enhance their tactics. It highlights an increase in exfiltration speeds — from five hours to approximately 72 minutes — indicating that AI may be contributing to faster attack execution.

Browsers are identified as significant targets, with 48 percent of incidents involving browser-based activity. The report suggests that routine digital interactions, including email use and access to SaaS tools, can create potential entry points for malicious activity.

Modern cyber threats are described as increasingly complex. The report states that 87 percent of intrusions involve multiple attack surfaces, with some spanning up to 10 different platforms. Attackers are observed coordinating activity across varied infrastructure, including cloud environments, networks, identity systems and SaaS applications.

Identity-related vulnerabilities are also highlighted. In nearly 90 percent of the incidents analysed, weaknesses in identity management contributed to intrusions. Around 65 percent of breaches originated from identity-based techniques, including social engineering. The findings emphasise the importance of strengthening identity controls to reduce risk.

The report also points to a rise in software supply chain breaches, particularly through third-party SaaS applications. The abuse of trusted connections has increased, with APIs and OAuth tokens identified as common vectors for lateral movement within environments.

At the same time, the report notes a decline in encryption-focused extortion. The proportion of incidents involving encryption-based tactics decreased from 92 percent to 78 percent, with attackers increasingly focusing on direct data theft rather than encrypting systems. The report states that the speed and discreet nature of these thefts present challenges for detection and response.

Overall, the Unit 42 report outlines changes in threat activity and highlights areas where organisations may need to review and adapt their security measures in response to evolving tactics.

Enterprise AI hits the wall

Posted 3 days ago by Phil Alsop
Demands for privacy and sovereignty expose limits of architectures built for centralised and borderless data flows.
Abnormal AI strengthens its team with key executive hires amid rising AI-generated cybersecurity threats, aiming to enhance product innovation and...
At its 2026 Relate event in Colorado, Zendesk outlined its push towards an autonomous service workforce, revealing new AI platform capabilities. The...
SolarWinds research reveals growing confidence in automation, however concerns around accuracy, skills and oversight remain.
IT leaders survey finds that despite rising hardware costs and sustainability goals, 1/3 of mobiles, laptops and drives destroyed to protect data...
HCLTech has released findings from its latest Enterprise AI Market Report, The AI Impact Imperatives, 2026, highlighting a growing execution gap as...

SMBs hit a cybersecurity breaking point

Posted 4 days ago by Phil Alsop
New global research shows internal teams can’t keep pace, fueling demand for always-on, outcome-driven security services.

Zendesk reveals autonomous service workforce

Posted 5 days ago by Sophie Milburn
Zendesk has outlined a new AI-focused strategy for customer service centred on combining AI capabilities with human support workflows to improve...