Attackers Target Trusted Identities and Infrastructure at Record Speed
Darktrace and Microsoft Agent 365 are working together to extend AI security visibility. In the first half of 2026, a Darktrace honeypot was compromised in under two hours after deployment, highlighting the speed of the threat landscape. The shift over the past six months has moved away from traditional malware and vulnerability-centric attacks towards the abuse of trusted identities, platforms, and infrastructure.
Attackers are increasingly operating inside relationships, services, and authenticated channels that defenders rely on. In 2025, identity became the new perimeter as attackers bypassed traditional exploitation in favor of trusted accounts and SaaS platforms. This year, trust has become a supply-chain vulnerability with legitimate services being abused.
The most prevalent threats affecting Darktrace customers were information stealers, which are an identity story. Credentials harvested by infostealers often become the initial access vector for higher-impact intrusions. AI is also becoming an attack multiplier as attackers use Large Language Models (LLMs) to produce working exploit code and deploy it at scale.