2026's Shifting Threat Landscape: What Alert Data Reveals

Critical Start

New data from Critical Start's H1 2026 Cyber Threat Intelligence Report shows the moment of compromise is no longer where the real story is happening.

Security teams have spent years optimizing for one moment: the point where an attacker gets in. New data from Critical Start's H1 2026 Cyber Threat Intelligence Report suggests that moment is no longer where the story is happening.

The Cyber Research Unit at Critical Start analyzed alert investigations across hundreds of organizations from January through June 2026, drawing on first-party telemetry, Security Operations Center (SOC) investigations, and open-source intelligence. The finding that stands out most: Execution, not Initial Access, is now the most common tactic showing up in high- and critical-severity alerts.

Here's what that shift means, and what else the data shows about where attackers are spending their time.

The Big Shift: Execution Overtakes Initial Access

For three straight reporting periods, Initial Access held the top spot among MITRE ATT&CK tactics observed in Critical Start's alert data, peaking at 40.65% of mapped activity in H1 2025. In H1 2026, that changed. Execution became the most frequently observed tactic, accounting for 27.07% of mapped activity, with Initial Access falling to 21.41% and Credential Access close behind at 18.97%.

The report is careful not to overstate what this means. It doesn't necessarily mean attackers are breaking in less often. It could reflect changes in attacker behavior, changes in how activity gets detected, or both. What it does mean is that more of what analysts see now happens after an attacker already has access: command and scripting activity, user execution, and use of built-in tools like Windows Management Instrumentation.

For security leaders, the practical takeaway is that individual alerts matter less than the relationships between them. An Execution alert may look unremarkable on its own. Considered alongside a Credential Access alert from the same environment an hour earlier, it tells a very different story. That correlation work, done at scale and in real time, is where Critical Start sees the clearest current use for AI in the SOC.

Who's Being Targeted, and Why

Critical Start's top five most targeted industries in H1 2026 were Manufacturing, Banking and Finance, Retail, Business Services, and Construction. The lineup is the same as H1 2025, but the order shifted: Manufacturing reclaimed the top position from Banking and Finance, and Retail rose from fifth place to third.

RankIndustry (H1 2026)Change from H1 2025
1ManufacturingUp from #2
2Banking and FinanceDown from #1
3RetailUp from #5
4Business ServicesNo change
5ConstructionNo change

Manufacturing's return to the top spot tracks with factors the report calls out directly: high-availability requirements that make downtime expensive, growing overlap between operational technology and enterprise IT, and long supply-chain dependencies. In March 2026, the Qilin ransomware group listed a French industrial supplier to Airbus and Boeing among its victims, an example of exactly that dynamic.

Retail's climb reflects a similar pattern of interconnected risk: third-party dependencies, e-commerce infrastructure, and valuable payment data all in one place. And organizations outside the top five aren't necessarily in the clear. Attackers routinely gain footholds through payment processors, suppliers, and other partners rather than direct targets, which means industry rank is a poor substitute for understanding your own exposure through the vendors and partners you depend on.

Ransomware: Fewer Groups, More Consolidation

The report tracked the ransomware groups responsible for the largest share of claimed victims in H1 2026:

Ransomware GroupShare of Claimed Victims (H1 2026)
Qilin14.42%
The Gentlemen9.79%
Akira6.19%
DragonForce5.52%
INC Ransom5.19%

Qilin and Akira are the only two groups that have remained among the most active across all three of Critical Start's recent reporting periods. The Gentlemen, by contrast, didn't appear in either 2025 ranking and entered directly into second place in H1 2026.

The common thread across these groups is less about sophisticated malware and more about access. Valid accounts, phishing, and exploitation of internet-facing applications remain the dominant ways in. Once inside, groups like Akira are known to create new admin accounts, move laterally, and disable defenses before deploying ransomware. None of that requires a novel exploit. It requires patience and stolen credentials.

That pattern showed up starkly in a February 2026 breach confirmed by French authorities: roughly 1.2 million bank accounts were exposed after attackers used stolen credentials to access a national account registry. No malware, no custom tooling. Just valid access.

Vulnerabilities Are Being Exploited Faster

The report's new vulnerability landscape section identifies four themes from H1 2026:

  • Exploitation increasingly happens before public disclosure.
  • Management and identity infrastructure, including VPNs, remain frequent entry points.
  • Legacy vulnerabilities, some years old, continue to be actively exploited alongside newer ones.
  • AI-assisted vulnerability discovery is accelerating on both sides of the fight.

The clearest evidence of that acceleration: the average gap between a vulnerability being added to the Known Exploited Vulnerabilities catalog and attackers actively exploiting it narrowed from 120 days to 80 days. Fewer vulnerabilities are involved overall, but the ones attackers do use are moving from disclosure to active exploitation much faster than most organizations can patch.

The report's recommendation here is direct: a high CVSS score doesn't automatically mean a vulnerability is a priority for your environment. Exploitability and business context matter as much as severity.

Where AI Is Actually Helping

Critical Start's report includes a real example of SOC AI in action, its AI capability built to support, not replace, human analysts. In one incident, a ClickFix-style attack against an energy and utilities customer used a steganography loader, malicious code hidden inside image pixel data, to try to deliver a second-stage payload.

The investigating analyst had never seen this specific technique in the wild. SOC AI decoded the obfuscated command chain, identified the steganography technique in plain language, and drafted the initial escalation write-up. The analyst reviewed the findings, applied judgment, and made the final call to isolate the host.

That division of labor, AI accelerating investigation and correlation, humans retaining the decision, is central to how Critical Start approaches AI in the SOC. The report notes a deliberate, deterministic-first design choice: AI agents that behave predictably and stay explainable, rather than fully autonomous systems making unreviewed calls in a domain where mistakes carry real consequences.

What This Means for the Second Half of 2026

A few practical implications follow from the data:

  • Prioritize by exploitability and business context, not CVSS score alone. The gap between disclosure and exploitation is shrinking.
  • Tighten identity and access controls. Valid accounts and stolen credentials, not novel malware, are the common thread across this period's biggest incidents.
  • Don't assume off-hours are safer. Alert activity in H1 2026 clustered heavily between 1400 and 2000 UTC, overlapping U.S. and European business hours, when accounts are actively in use and abnormal activity is easier to blend in.
  • Map your exposure through partners, not just your own industry. Third-party and supply-chain compromise cut across every sector in the top five.

Alert volume has been trending down since H1 2023. That's a sign of better detection tuning, not a sign that risk is declining. The shift toward Execution and away from Initial Access means the alerts that remain carry more information about what's already happening inside an environment, if teams have the visibility and correlation to read them.


This post covers a fraction of the findings in Critical Start's H1 2026 Cyber Threat Intelligence Report, including the full industry breakdowns, ransomware group profiles, and vulnerability data referenced above.

Download the full H1 2026 Cyber Threat Intelligence Report →