The security landscape in 2026

Adversary trends and defender strategies derived from real-world telemetry
The security landscape is undergoing a rapid transformation.

Adversaries’ AI-driven threat innovation is evolving at an accelerated pace via streamlined information synthesis and automated workflows. This is resulting in more diverse adversary capabilities and new, indirect avenues of access. AI’s role on both sides of the cyber battle is anticipated to shift significantly as these technologies become more widespread.

The Elastic Global Threat Report uncovers real-world threat activities, revealing a fundamental shift in how adversaries achieve success today. It also includes a new section describing our visibility from non-telemetry sources, highlighting which malware families and threat behaviors were seen externally.

Access brokers are increasingly using information stealers to maintain a distance from collective defense efforts, significantly escalating the risks of credential exposure through cloud storage and other services. Trojanised software, which represented about 61% of all malware samples observed, was a major contributor; the ClickFix methodology is one of the most common techniques used to deliver trojans and infostealers. More than 24% of malware samples on Windows represented named infostealer code families.

The Elastic Global Threat Report

This report from Elastic in late 2025 covers the following key trends in depth:

  • Adversary priorities on Windows are changing
  • The cloud attack surface is highly concentrated
  • Adversaries are weaponising AI to lower the barrier to entry for cybercrime
  • The theft of browser credentials has industrialised

The Elastic Global Threat Report
More in Cyber Security
Sleighing cybersecurity threats
Sleighing cybersecurity threats

How the North Pole is preparing for more AI mischief in 2026.


Culture change
Culture change

Is there a clear line between manipulation and influence, and should security leaders care?


The human side of infosec
The human side of infosec

Why we often overlook arguably the most important piece of the security puzzle.


Why PR is vital in cyber breaches
Why PR is vital in cyber breaches

Narrative control and the impact on trust, brand perception, and legal outcomes.


VIDEO: What will it take to tackle AI-driven threats?
VIDEO: What will it take to tackle AI-driven threats?

Improving your incident response in 2025.


You're invited! Exclusive lunch in London with Elastic's CISO
You're invited! Exclusive lunch in London with Elastic's CISO

Connect, discuss security trends, and gain insights that can help shape your approach to digital security.


You're invited! Networking for security professionals in London
You're invited! Networking for security professionals in London

A relaxed afternoon full of expert discussion, informal networking, and a look ahead at what’s possible.


The hot trends in AI cyber security tools
The hot trends in AI cyber security tools

How AI augments cybersecurity teams.


VIDEO: Defenders vs hackers
VIDEO: Defenders vs hackers

AI in security - hype cycle or real-time game changer?


VIDEO: Staff aren't villains, but their use of AI opens the door
VIDEO: Staff aren't villains, but their use of AI opens the door

Rethinking insider threats in the age of AI.


VIDEO: Two sides of the same cyber breach
VIDEO: Two sides of the same cyber breach

Unpatched: PR and cybersecurity.


Share this story

We're a community where IT security buyers can engage on their own terms.

We help you to better understand the security challenges associated with digital business and how to address them, so your company remains safe and secure.

Interested in what you see? Get in touch, and let's start a conversation Get in touch