All Articles

2026 Threat Landscape: AI Agents, Passkey Phishing & Zero-Days

September 13, 2026 5 min read By The Vici Tech Solutions Team
Threat IntelligenceCyber SecurityAI SecurityVulnerabilities

The Threat Landscape Is Accelerating—And Changing Shape

The cyber threat landscape in late 2026 is defined by three converging forces: autonomous AI agents conducting sophisticated attacks, attackers adapting to next-generation authentication, and an exploit velocity that continues to shrink the window between disclosure and active exploitation. This week's headlines illustrate exactly where the threat landscape is heading—and what organizations must do to prepare.

AI Agents Are Now Offensive Tools, Not Just Theoretical Risks

In May 2026, RubyGems suffered what researchers called a "major malicious attack." This week, we learned the full story: the attack was carried out by a swarm of OpenAI agents that gained remote code execution on RubyDoc servers. This wasn't a researcher's proof-of-concept—it was a real-world supply chain compromise executed by autonomous AI systems.

The implications are profound. AI agents can now:

  • Autonomously discover and exploit vulnerabilities at machine speed
  • Coordinate multi-stage attacks across infrastructure
  • Adapt tactics in real-time based on defender responses
  • Scale attacks beyond human operator limitations

For security operations centers, this creates an entirely new challenge. As one recent analysis noted, alerts triggered by AI tools and agents have become the fastest-growing category in enterprise SOCs over the past year. Organizations are now defending against AI while simultaneously adopting AI tools internally—creating a complex threat surface that requires new detection and response strategies.

What to Do Now

  • Audit AI tool adoption across your organization, including shadow IT and developer tools
  • Implement behavioral monitoring that can detect autonomous agent activity patterns
  • Review supply chain security for all third-party dependencies, especially package repositories
  • Update incident response playbooks to account for machine-speed attacks that may not show traditional human attacker patterns

Authentication Evolution Creates New Attack Vectors

Passkeys were supposed to solve phishing. They're cryptographically secure, resistant to credential stuffing, and eliminate password reuse risks. Yet attackers are now successfully using passkey-themed phishing to hijack Microsoft cloud accounts and exfiltrate data.

The attack leverages social engineering rather than technical bypass. Threat actors abuse third-party email delivery infrastructure to send convincing messages that trick users into approving passkey enrollment on attacker-controlled devices. Once enrolled, the attacker gains legitimate access to cloud resources.

This illustrates a fundamental truth: as authentication technology advances, attackers adapt by targeting the human layer and the enrollment/recovery processes rather than the authentication mechanism itself. We saw similar patterns with multi-factor authentication—attackers shifted to MFA fatigue attacks, SIM swapping, and session hijacking when direct credential theft became harder.

Preparing for Authentication Attacks

  • User education must evolve with authentication technology—passkey security awareness is now essential
  • Monitor authentication enrollment events as closely as login events
  • Implement conditional access policies that flag unusual device enrollment patterns
  • Review account recovery workflows for social engineering vulnerabilities
  • Consider phishing-resistant MFA that requires user verification for new device enrollment

Critical Infrastructure Vulnerabilities Under Immediate Threat

CISA added five actively exploited vulnerabilities to its Known Exploited Vulnerabilities catalog this week, including flaws in JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS. These aren't theoretical risks—they're being exploited in the wild right now.

The Dutch National Cyber Security Centre escalated the urgency further, warning that exploitation of two critical Check Point VPN flaws (CVE-2026-85102 and CVE-2026-85103) is imminent. When a national CSIRT issues imminent exploitation warnings, it typically means they have intelligence indicating active attacker reconnaissance or early exploitation attempts.

Meanwhile, the BlueMoon exploit kit is chaining recent Chrome and Windows zero-days in opportunistic deployments by multiple espionage-motivated threat actors. The rushed adoption of BlueMoon by multiple groups suggests the exploit kit provides a significant capability advantage—likely full remote compromise through common user actions like visiting a website.

Looking at the recent CISA KEV additions, we see exploitation across the entire attack surface:

  • Network perimeter: MikroTik RouterOS (CVE-2026-86060, CVE-2026-67277), Check Point VPN, Citrix NetScaler (CVE-2026-19490), Cisco Firewall Management Center (CVE-2026-20079)
  • Remote access tools: ConnectWise ScreenConnect (CVE-2026-84869), N-able N-central (CVE-2026-86218)
  • Development infrastructure: JFrog Artifactory (CVE-2026-42016, CVE-2026-42018), GitLab (CVE-2026-85706)
  • Client-side: Google Chromium V8 (CVE-2026-87491)
  • Operating systems: Multiple Microsoft Windows vulnerabilities (CVE-2026-81963, CVE-2026-85880)

The Shrinking Patch Window Demands Faster Response

The pattern is clear: critical vulnerabilities are being exploited within days—sometimes hours—of public disclosure. The window for patching before active exploitation has collapsed to the point where traditional monthly patch cycles are no longer adequate for critical infrastructure.

Organizations need to shift their approach:

Build an Adaptive Patching Strategy

  • Monitor CISA KEV catalog daily—it's the authoritative list of actively exploited vulnerabilities requiring immediate action
  • Establish emergency patching procedures that can deploy critical updates within 24-48 hours
  • Prioritize internet-facing systems for immediate patching, especially VPN gateways, remote access tools, and web applications
  • Implement virtual patching through WAF rules or IPS signatures when vendor patches aren't yet available
  • Conduct regular vulnerability assessments to identify exposure before attackers do

Reduce Your Attack Surface

  • Inventory all internet-facing assets—you can't protect what you don't know exists
  • Disable or remove unused services, especially legacy remote access tools
  • Segment networks to contain breaches when perimeter defenses fail
  • Implement zero-trust principles rather than relying on perimeter security alone

Preparing for What's Next

The 2026 threat landscape is characterized by:

  1. Autonomous offensive capabilities that operate at machine speed
  2. Adaptive attackers who target new security controls through social engineering and process exploitation
  3. Rapid weaponization of disclosed vulnerabilities across critical infrastructure
  4. Sophisticated exploit kits that chain multiple zero-days for reliable compromise

Organizations that wait for breaches to drive security investment will find themselves perpetually behind. The preparation window is now—before the next wave of AI-powered attacks, before your VPN becomes the next exploitation target, before a supply chain compromise affects your development pipeline.

Defensive strategies must evolve to match the threat: faster patching, behavioral detection for AI agents, authentication security beyond the technology layer, and continuous assessment of your actual security posture through testing.

If you need help assessing your organization's readiness for the current threat landscape—from penetration testing to security architecture review—contact Vici Tech Solutions to discuss how we can help you prepare for what's coming next.

Worried about the threats you just read about?

Vici Tech Solutions helps businesses across the US find and fix vulnerabilities before attackers do. Explore our penetration testing services or talk to us about your security posture.

Get a Security Assessment