Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Saturday, 13 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Cyber attackers bypass traditional defences as ‘user-driven’ attacks surge, Bridewell warns

by Guru Writer
May 18, 2026
in Featured
Cyber attackers bypass traditional defences as ‘user-driven’ attacks surge, Bridewell warns
Share on FacebookShare on Twitter

Cyber attackers are increasingly sidestepping traditional security tools by exploiting users themselves, according to Bridewell’s newly released Cyber Threat Intelligence Report 2026.  The report highlights a significant shift in attacker behaviour, with threat actors moving away from malware-heavy campaigns towards identity-driven and socially engineered attacks that operate within trusted systems, often leaving little trace for security tools to detect.

Gavin Knapp, Head of Cyber Threat Intelligence at Bridewell, said the findings point to a fundamental evolution in how cyber attacks are executed.

“A key finding in the report is the move away from malware-led attacks toward identity-driven and user-led compromise, leveraging legitimate identities, software and techniques that operate inside trusted systems and bypass conventional defences,” he noted.

Security tools bypassed as attackers target users

At the centre of this shift is the rise of so-called “fix-style” attacks, including ClickFix, FileFix and ConsentFix. These techniques manipulate users into carrying out actions themselves, such as copying malicious commands, approving fraudulent authentication prompts, or completing legitimate login processes that hand control to attackers. Because these attacks rely on user execution, they can bypass endpoint security tools, multi-factor authentication (MFA), and traditional detection mechanisms entirely. In many cases, attacks now take place wholly within browsers or legitimate identity workflows.

Faster, more resilient cyber threats

Rather than reinventing tactics, attackers are refining existing methods to increase speed and resilience. Bridewell’s research shows that widely available offensive tools and command-and-control frameworks remain dominant, while adversary infrastructure is becoming more agile and distributed. This allows threat actors to quickly recover from disruption. When one tool or malware family is taken down, attackers rapidly switch to alternatives, minimising downtime and maintaining operational continuity.

Identity emerges as primary attack surface

The report identifies identity as the central battleground in modern cyber attacks. Credentials, session tokens and OAuth access are now heavily targeted, with information-stealing malware playing a key role in harvesting login data. This enables attackers to operate as legitimate users, significantly reducing the likelihood of detection while enabling follow-on attacks including ransomware and fraud.

Ransomware evolves towards data extortion

Bridewell also highlights a shift in ransomware tactics, with attackers increasingly prioritising data theft over encryption. This “smash-and-grab” approach focuses on rapid data exfiltration, allowing cyber criminals to extort victims without the need for prolonged network access. The result is faster attacks that reduce response times for defenders while increasing pressure on organisations to pay.

Blurring lines between cyber crime and nation-state activity

The report noted a growing convergence between cyber criminal groups and nation-state actors, with both adopting similar tools, techniques and infrastructure. This overlap is driving increased sophistication and unpredictability, particularly in attacks targeting critical national infrastructure and key industries.

What to expect

Looking ahead, Bridewell warns that organisations will face an increasingly adaptive threat landscape shaped by identity abuse, agile infrastructure, and AI-enabled attacks.

Key risks expected to dominate in 2026 include:

  • Increased exploitation of edge devices and identity systems
  • Continued growth in supply chain attacks
  • Rising activity linked to DPRK and other state-aligned actors
  • Ongoing convergence between cyber crime and nation-state operations

Knapp added that organisations must rethink their approach to security in response to these trends.

“As attackers continue to exploit trusted systems and human behaviour, organisations must move beyond traditional security approaches and focus on identity protection, user awareness and threat-informed defence,” he cautioned.

ShareTweet
Previous Post

One in 33 Employees Is Driving Nearly a Fifth of All Workplace AI Activity and Most Companies Are Only Just Waking Up to It

Next Post

Check Point Wants AI Agents to Do What Security Teams Can’t: Manage Networks at Machine Speed

Recent News

Nagomi Control Brings CTEM Into Action

2 in 5 Organisations Experienced Cyber Incidents Tied to Suppliers in Past Year

June 12, 2026
Certes Research Warns Legacy Systems Are Biggest Barrier to Quantum Security Readiness

KnowBe4 Expands Gamified Training Library With Launch of “Spot the Vish” Game

June 12, 2026
Swan Song For Infosec’s Most Gripping Awareness Training Series: The Inside Man Goes Out With A Star-Studded Bang

Swan Song For Infosec’s Most Gripping Awareness Training Series: The Inside Man Goes Out With A Star-Studded Bang

June 12, 2026
artificial-intelligence

The More Confident Organizations Are in Their AI Security, the More Likely They’ve Been Breached, New Research Finds

June 11, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol