Six months ago I wrote that attackers had stopped breaking security controls and started abusing them as designed. Bad news: threat actors didn’t suddenly opt for a more measured and thoughtful approach in the first half of the year. AI continued to compress the time between known risk and successful exploit. Threat actors moved faster and more efficiently, to the detriment of defenders around the world.
We saw this compression everywhere. Voice cloning reached the point where a help desk couldn’t distinguish a CFO from a convincing synthetic voice. AI coding assistants helped groups like The Gentlemen reportedly stand up RaaS infrastructure in days. Credential-harvesting operations such as FortiBleed used AI-assisted tooling to enrich and monetize stolen identities at machine speed. None of these required new exploits. They required attackers to move faster than defenders.
Defenders also lost some of the context that once helped prioritize risk. NIST has stopped enriching most CVEs, so the bulk of new disclosures sit unscored. Researchers are increasingly skipping coordinated disclosure and dumping unpatched flaws straight to the public. The Five Eyes advisory this June put a number on what that means: frontier AI is expected to reshape offensive and defensive cyber capability within months, not years. If your security roadmap is still budgeted in multi-year phases, treat it as already out of date.

ECHO Findings: It’s me, I promise…
Throughout 304 incidents, identity, the edge, and trusted tooling are all resulted in versions of the same failure: security controls working exactly as designed, in the wrong hands.
A stolen credential replayed against Entra ID. An SSL-VPN gateway that lets its own MFA seed reset with nothing but a password. A remote-support session a help desk employee granted willingly, because the caller sounded exactly like their IT team.
8 in 10 host breaches in our docket started with stolen identity. Roughly 1 in 3 came through an SSL-VPN gateway, and it was almost never CVE exploitation on the appliance itself. It was stolen passwords reused against the gateway. Akira rode this pattern into every single one of their cases we worked this half, sometimes hitting full encryption in under an hour.
The Teams vishing playbook deserves its own callout because we watched it work over and over: email bomb the target to manufacture a “help me, my inbox is a disaster” pretext, follow with a Teams call from an external tenant impersonating internal IT, get a Quick Assist or AnyDesk grant, then go hands-on-keyboard. The attacker only needs to win once. We saw campaigns where the same actor hit a dozen employees at one company in a single afternoon.
Et Tu, Quick Assist?
The most effective post-compromise tooling wasn’t malware. It was software defenders already trusted. ScreenConnect, AnyDesk, Quick Assist, Bomgar. PowerShell obfuscated through integer-to-character casting and in-memory AMSI bypass. Bring-Your-Own-Vulnerable-Driver loads to kill EDR before ransomware deployment. None of this is exotic. It’s legitimate software, doing exactly what it was built to do, for someone who shouldn’t have had the keys.
One case still sticks with me: a trojanized open-source media-player installer sat dormant for six weeks after IT deployed it before an external operator activated the ScreenConnect client it had quietly sideloaded. Six weeks of dwell time. That’s the argument for historical detection, not just real-time alerting.
A thriving (and crowded) ransomware marketplace
Qilin led the period with 648 claimed leak-site postings. The Gentlemen posted 467, but backend disclosure from a leak of their own infrastructure suggests the real victim count runs closer to four times what they publicly claimed. LockBit 5.0 is still in the top tier despite the law-enforcement takedown of prior infrastructure. The brand dies, the affiliates migrate.
Where this goes next
I don’t think any of this reverses in the second half of the year. Identity-led intrusion becomes the default, the edge stays a credential and broker problem. The affiliate base keeps outlasting whatever brand is on top of this quarter’s leaderboard, although we expect to see continued fractures and the formation of new collectives due to disagreements on payouts, infighting, and competition with rival groups.
AI continues shrinking the gap between disclosure and exploitation while most organizations still measure remediation in weeks.
If there’s one thing I’d ask every security leader reading this to walk away with, it’s this: phishing-resistant MFA everywhere, help desk verification flows that require an out-of-band callback before any password reset or remote-access grant, and treat your EDR uninstall password like a Tier-0 secret. None of that is exotic either. It’s just the stuff that actually stops what we saw this half.