"AI is a mimic of a human. It is incredibly fast but also incredibly stupid in some respects. We use AI in our business to help code, to help research, to help thinking, but I say it’s the fastest dumb person you can find." - Danny Jenkins
What's happening: AI's acceleration of cyberattacks is not only a concern because of the increase in threats. It is also increasing the number and pace of alerts coming through to SOC teams, creating an overwhelming amount of noise. False positives and alert fatigue delay response time into real threats as well as strategic security projects, and they increase operational costs.
Why it matters: AI threats grab headlines, but analyst burnout and turnover are becoming an equally serious concern. Many cybersecurity professionals report increased stress and say their teams are understaffed. Alert fatigue only heightens these concerns.
The big picture: Zero Trust protects your organization in more ways than one. By blocking unauthorized activity before it generates endless detections, Zero Trust helps security teams spend more time responding to real threats instead of chasing noise.
What's happening: Microsoft has announced that by February 2027, passkeys will become the default sign-in experience in Microsoft Entra. Passkeys are more secure and less susceptible to phishing than passwords or one-time codes, but they are not threat-proof. Instead of trying to steal passkeys, attackers will target the process that tells an account to trust a new passkey. Okta Threat Intelligence recently reported that one in five of the warnings it sent over the last month involved phishing domains containing the word "passkey."
Why it matters: Passkeys significantly reduce credential phishing, but authentication is only one layer of security. Organizations still need to secure enrollment and recovery processes, verify trusted devices, and limit what authenticated users and applications are allowed to do.
The big picture: Passkeys make credential theft harder, but attackers rarely stop when one technique disappears. Defenders should assume authentication alone is never enough by continuously verifying users and devices and limiting what trusted identities can do after they sign in.
Broad permissions create unnecessary risk, especially with agentic AI
What's happening: How do you enable AI to assist productivity without compromising security? By applying the principle of least privilege. When an AI agent is given a task, it will work to achieve that task in the most direct way possible, so long as it is given those permissions. Every unnecessary permission increases the potential blast radius if an AI agent is compromised, manipulated, or behaves unexpectedly, and AI can act at a speed that makes mistakes far more difficult to contain.
Why it matters: Many organizations fall into the trap of granting broad permissions for easier deployment. This is even more dangerous with AI agents than it is human users or traditional software because AI agents do not always behave within a scope of predefined tasks.
The big picture: AI hasn't changed the principles of cybersecurity, but it has amplified the consequences of ignoring them. Limiting AI's reach is not meant to diminish its usefulness. It is meant to ensure that every permission and every action have a business justification.
A compromised management platform can become an attacker's control center
What's happening: CVE-2026-18577 is an authentication bypass vulnerability in N-able N-central being actively exploited to give unauthenticated attackers full administrative access ("god mode") to the platform. Once inside, attackers can use legitimate N-central capabilities to run scripts, deploy tools, open remote sessions, and move across endpoints. N-able released an emergency fix and advises customers to upgrade to the latest version 2026.3.1.7 immediately.
Why it matters: Remote monitoring and management platforms are designed to administer thousands of systems from a single console. When one is compromised, attackers inherit those same trusted capabilities, enabling rapid lateral movement and large-scale compromise.
The big picture: Tools like N-able are essential to many organizations, which makes them a high-value target for attackers. Patching is the first step. Applying least privilege to administrative tools helps limit what attackers can do if one of these platforms is ever compromised.
Kali365 phishing kit weaponized Microsoft login process
Attackers abuse authentication process instead of stealing passwords
What's happening: A new Kali365 phishing campaign is abusing Microsoft's Device Code authentication flow and targeting U.S. organizations. Attackers use the kit to trick users into entering a device code on a real Microsoft login page, allowing them to capture OAuth tokens and gain access to Microsoft 365 accounts without stealing passwords. The kit supports AI-generated lures, brand impersonation templates, and tools for spreading attacks.
Why it matters: The legitimate Microsoft login page is what makes this attack appear trustworthy and how it bypasses many traditional defenses. Once they obtain OAuth tokens, attackers can access Outlook, Teams, SharePoint, and more without a password.
The big picture: Strong authentication is only one layer of security. Attackers are increasingly abusing identity workflows versus stealing passwords, meaning organizations should assume authentication can be bypassed and limit unnecessary permissions to contain threats.
“ThreatLocker gave us the granular control we were looking for and provided real peace of mind. It helped our director and me sleep better at night because we knew there was another layer of protection helping watch over our environment and keep our best interests in mind. ThreatLocker saved us time and money—a lot in overhead and a lot in manpower.”