As ransomware recedes, a new more dangerous digital parasite rises
ID: ba0bf40a-8468-5f81-99db-47abe7d1009c
STIX ID: report--ba0bf40a-8468-5f81-99db-47abe7d1009c
Feed Name: ZDNet Security
Picus Labs' 2026 Red Report, summarized by ZDNET, ranks MITRE ATT&CK techniques from large-scale simulations and finds a shift from ransomware encryption (T1486) toward data theft/extortion enabled by sleeperware that evades detection and increases dwell time; Process Injection (T1055) remains first, followed by Command and Scripting Interpreter (T1059) and Credentials from Password Stores (T1555), with Virtualization/Sandbox Evasion (T1497) surging—all signaling attackers’ preference to inhabit environments using stolen credentials—and the report urges resilient defenses such as immutable, isolated backups.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
