logo

Expel-Annual-Threat-Report-2026.md

ID: 5a19b076-f0cd-481f-8ee8-edcdc32b40c9

STIX ID: report--5a19b076-f0cd-481f-8ee8-edcdc32b40c9

Threat Score

70/100

Uploaded: 2026-08-14

Published Date: 2026-03-17

Last Modified Date: 2026-03-17

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Expel’s 2026 Annual Threat Report analyzes nearly a million alerts from 2025 and finds identity-based attacks dominated incidents (68.6%), followed by endpoint malware (29%) and smaller but high-impact cloud incidents (2.5%); notable findings include widespread credential theft and MFA bypass via PhaaS, prevalent infostealers (e.g., Vidar, StealC) and ClickFix-driven malware, a supply-chain worm (Shai Hulud 2.0) that harvests IAM secrets, and a critical server-side vulnerability (React2Shell), with recommendations to prioritize fundamentals like conditional access, FIDO2 MFA, application whitelisting, secret monitoring, and targeted detections.