Threat Reports

In-depth quarterly reporting from Vega Threat Research — the themes, techniques, and detections that defined the quarter, drawn from what Vega observed across customer environments.

Top threats observed in Q2 2026

Quarterly Threat Report

Q2 2026

Published

Jul 1, 2026

Author

Vega Threat Research

Inside this report

  1. 1.Executive Summary
  2. 2.Threat Landscape
  3. 3.Notes from the Trenches
  4. 4.Detections We Loved This Quarter
  5. 5.Summary

Executive Summary

Over the past quarter, we observed threat actors continuing to favor techniques that are fast to deploy, easy to adapt, and difficult for traditional prevention controls to consistently stop. Rather than relying on sophisticated malware or complex intrusion chains, attackers increasingly combined social engineering, native system utilities, rapid exploitation of one-day vulnerabilities, security control tampering, and evasion infrastructure to gain execution and move quickly after initial access.

A common theme across these observations is the operational efficiency of modern attacks. Many of the techniques we observed were not highly complex, but they were effective because they exploited gaps between user behavior, endpoint visibility, vulnerability exposure, cloud identity controls, and automated analysis. This reflects a threat environment where attackers increasingly advance by abusing what organizations already trust: workflows, credentials, exposed systems, and administrative tools.

Top threats observed

ClickFixVulnerability ExploitationLolBins AbuseSupply-chainIdentity

Threat landscape

Exploitation of newly disclosed vulnerabilitiesUser-assisted initial accessRansomware and data extortionCloud and identity abuseSoftware supply chain compromise

See how Vega detects these techniques across your environment.

Hunt with Vega →