Expel-Annual-Threat-Report-2026.md
ID: 5a19b076-f0cd-481f-8ee8-edcdc32b40c9
STIX ID: report--5a19b076-f0cd-481f-8ee8-edcdc32b40c9
Threat Score
70/100
Uploaded: 2026-08-14
Published Date: 2026-03-17
Last Modified Date: 2026-03-17
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Expel’s 2026 Annual Threat Report analyzes nearly a million alerts from 2025 and finds identity-based attacks dominated incidents (68.6%), followed by endpoint malware (29%) and smaller but high-impact cloud incidents (2.5%); notable findings include widespread credential theft and MFA bypass via PhaaS, prevalent infostealers (e.g., Vidar, StealC) and ClickFix-driven malware, a supply-chain worm (Shai Hulud 2.0) that harvests IAM secrets, and a critical server-side vulnerability (React2Shell), with recommendations to prioritize fundamentals like conditional access, FIDO2 MFA, application whitelisting, secret monitoring, and targeted detections.
