THREAT OPS › Threat News › H1 2026 Malware Vulnerability Trends
H1 2026 Malware Vulnerability Trends
<h2>Executive Summary</h2> <p>H1 2026 activity showed a continued adversary preference for abusing legitimate tools, trusted platforms, and routine workflows already present in enterprise and consumer environments. Threat actors used exposed software, developer tools, remote access utilities, payment workflows, and third-party services to gain access, steal credentials, move laterally, and
MITRE ATT&CK techniques
- VulnerabilitiesT1588.006
- Social EngineeringT1684
- CredentialsT1589.001
- Generative AIAML.T0016.002
- Local AI AgentAML.T0112.000
Indicators of compromise
- https://www.anthropic.com/research/mythos-preview?curius=1419url
- https://www.anthropic.com/glasswingurl
- https://blog.mozilla.org/en/firefox/privacy-security/ai-security-zero-day-vulnerabilities/url
- https://www.anthropic.com/research/glasswing-initial-updateurl
- https://www.hackerone.com/blog/ai-driven-report-volume-insights-and-actionsurl
- https://openai.com/index/hugging-face-model-evaluation-security-incident/url
- https://www.eset.com/us/about/newsroom/research/eset-research-discovers-promptspy-first-android-threat-using-genai/url
- https://blog.virustotal.com/2026/02/from-automation-to-infection-how.htmlurl
- https://www.malwarebytes.com/blog/news/2026/03/beware-of-fake-openclaw-installers-even-if-bing-points-you-to-githuburl