logo

Nowhere, man: The 2026 Active Adversary Report

ID: 25694d70-4b8b-53b7-97db-7e19000f5e06

STIX ID: report--25694d70-4b8b-53b7-97db-7e19000f5e06

Feed Name: Sophos Blogs

Threat Score
75/100

Date Published: 2026-02-24

Date Updated: 2026-04-30

...
...

### Executive summary: The report analyzes 661 incident response and MDR cases (Nov 2024–Oct 2025) and shows identity-related compromises (compromised credentials, brute force, phishing) as the dominant root causes, a significant ransomware presence led by Akira and Qilin, frequent exploitation of known CVEs (notably CVE-2024-40766), and operational gaps — missing/insufficient MFA, absent logs, and end-of-life systems — that enabled intrusion and data exfiltration; recommendations emphasize strong MFA (passwordless/FIDO and bound session tokens), improved logging/retention, patching, and tighter controls on tools like Python/Impacket and AD access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.