Cloudflare’s Cloudforce One released its inaugural 2026 Cloudflare Threat Report, warning that attackers are increasingly “industrializing” operations by weaponizing the same cloud and SaaS services organizations rely on. The report highlights how identity- and token-based compromise (e.g., stolen session tokens) can deliver outcomes comparable to complex malware or zero-days, while blending into legitimate cloud traffic and exploiting “seams” between interconnected services. It also forecasts broader normalization of platform abuse, with adversaries using public cloud infrastructure for phishing delivery, infrastructure provisioning, and operational cover.
The report further argues that AI is compressing attacker timelines—speeding target selection, reconnaissance, and execution—by optimizing for attacker “Measure of Effectiveness (MOE),” where low-effort techniques (like token theft) can outperform higher-cost exploit development. It cites trends including more convincing social engineering (e.g., deepfakes), faster exploit iteration, and continued high-scale disruption such as hyper-volumetric DDoS activity, alongside ongoing state-backed intrusions into critical sectors. Separate items in the set—workforce burnout survey results, a detection-engineering newsletter, a vendor “security briefing” covering multiple unrelated February items, and a generic AI security tips article—do not materially add to the specific Cloudflare report story.

Track how attackers are adapting to this technology.
8 events from the most recent confirmed update back to the earliest known activity.
On 2026-04-09, AhnLab ASEC released its Q1 2026 Attack Technique Trends Report, describing AI- and automation-driven threats, identity-centric intrusions, and growing abuse of SaaS, cloud, APIs, and trusted partner relationships. The report also cited specific defense-evasion examples, including Interlock’s use of the Hotta Killer technique with CVE-2025-61155 against FortiEDR and abuse of Carbon Black’s legitimate updater binary to terminate EDR processes.
On March 6, 2026, Cloudflare threat intelligence experts Brian Carter and Chris Pacey discussed the 2026 Threat Report on the 'This Week in NET' podcast. They expanded on AI-driven phishing, botnets, supply-chain risk, token theft, living-off-the-cloud techniques, and state-linked cyber activity.
Alongside the report, Cloudflare recommended moving from judging threats by sophistication to measuring attacker effectiveness and adopting autonomous, real-time defenses. It called for stronger DMARC/DKIM/SPF, tighter SaaS and API controls, and broader Zero Trust protections to counter AI-accelerated attacks.
The report outlined key trends including AI-enabled reconnaissance and exploit development, phishing-as-a-service, session token theft, living off trusted services, email authentication failures, and identity-focused attacks. It also highlighted state-linked activity such as China-linked pre-positioning in North American telecom and government networks and North Korean use of deepfakes and laptop farms.
On March 3, 2026, Cloudflare’s threat intelligence team Cloudforce One released its first annual 2026 Cloudflare Threat Report. The report warned that AI, cloud services, and trusted platforms are enabling faster, more scalable attacker operations.
The threat report said business email compromise attempts surpassed $123 million in 2025, with average targeted amounts around $49,000. The figures were presented as evidence that email-based fraud remained a major threat vector.
Cloudflare reported hyper-volumetric DDoS attacks reaching 31.4 Tbps during 2025, reflecting a major escalation in attack scale. The report also said DDoS volume roughly doubled from 2024 to 2025.
Cloudflare said it disrupted attacker infrastructure by neutralizing more than 400 malicious domains during 2025. The action was cited in later discussion of the company’s threat intelligence and disruption work.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
5 references tracked. Mallory keeps watching after this page renders.
asec.ahnlab.com
Open sourcesecuritysenses.com
Open sourcescworld.com
Open sourcecyberscoop.com
Open sourcecybersecuritynews.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.