AI agent infrastructure is racking up real CVEs, a webpage can now poison a local AI model, and infostealers are hijacking AI account sessions to skip MFA entirely.
AI is no longer just drafting phishing emails. It's running most of an espionage campaign, splitting operations across multiple models, and building zero-days and malware on its own.
Prompt injection and excessive agency aren't bugs waiting for a patch; they're built into how LLMs and agents work. Two recent incidents show agents coordinating around their restrictions with no attacker involved.
The alert data has spoken: attackers are spending less time breaking in and more time operating once they're inside. Here's what Critical Start's H1 2026 Cyber Threat Intelligence Report reveals about the shift and what security leaders should do about it.
Critical Start's Cyber Research Unit unpacks the H1 2026 Threat Landscape Report - why "execution" overtook "initial access" as the top MITRE tactic, which industries are trading places on the target list, and how SOC AI helped crack a steganography-based attack.
DPRK operatives are no longer just gaming payroll — they're landing inside source code repositories, production infrastructure, and even a U.S. federal agency, with AI now baked into every stage of the con.