惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

博客园 - Franky
J
Java Code Geeks
腾讯CDC
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Jina AI
Jina AI
博客园 - 司徒正美
Stack Overflow Blog
Stack Overflow Blog
美团技术团队
L
LangChain Blog
WordPress大学
WordPress大学
A
About on SuperTechFans
Martin Fowler
Martin Fowler
月光博客
月光博客
Y
Y Combinator Blog
U
Unit 42
D
Docker
Recent Announcements
Recent Announcements
Hugging Face - Blog
Hugging Face - Blog
B
Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
G
Google Developers Blog
Last Week in AI
Last Week in AI
T
The Blog of Author Tim Ferriss
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com

Latest news

LG G6 vs. LG G5: I compared the latest OLED TV models, and it's a surprisingly tough choice I saw the 'MacBook Pro for Linux users' for the first time, and it's a legit Windows threat I'm putting Motorola above Samsung when it comes to flip phones - and won't think twice I got an early look at ChatGPT Images 2.0, and it's impressive - with one exception I tested Surfshark's new Dausos VPN protocol - here's how it compares to WireGuard How to easily encrypt your files on an Android phone - for free I'm not giving up on DJI cameras yet - not when they can upset my GoPro like this The best website builders for small businesses in 2026: Expert tested and reviewed Why I'm recommending last year's phones over 2026 models - with one exception This powerful Gemini setting made my AI results way more personal and accurate After testing this HP laptop, I get why its 'boring' design is adored by business users The best TV antenna of 2026: Expert tested Your old iPad or Android tablet can be your new smart home panel - here's how Apple's original AirTag still tracks effectively, and you can get a 4-pack for its best price ever T-Mobile will give you an iPad for $99 when you sign up for a new line - here's how How to qualify for Apple's education discount - and get a $499 MacBook Neo for school T-Mobile will give you a Samsung Galaxy Watch 8 for free - how to get yours Prolonged AI use can be hazardous to your health and work: 4 ways to stay safe Verizon will give you a free iPad or Apple Watch with your next iPhone - how the deal works The best laptops of 2026: Expert tested and reviewed I hid 4 Bluetooth trackers (including AirTags) to test their reliability - here's how Android rivals compared I stopped using my iPhone's hotspot after testing this 5G router - and that won't change The best Kindles in 2026: Expert recommended Does Best Buy price match? Everything to know about matching prices online and in-store The best WordPress hosting services of 2026: Expert tested and reviewed The best Apple Watch of 2026: Expert tested and reviewed The best TV screen cleaners of 2026: Expert recommended The best 50-inch TVs of 2026: Expert tested I traded my Sonos Era 300 for Denon's new home speaker - and see no reason to go back AI-powered website builders have come a long way - here's your best option in 2026
5 ways to fortify your network against the new speed of A...
2026-05-19 · via Latest news
image-1.png
Jeffrey Hazelwood/ZDNET; Shutterstock

Follow ZDNET: Add us as a preferred source on Google.


ZDNET's key takeaways

  • Attacks on enterprise networks are becoming more frequent.
  • Cybercriminals are using AI, but humans remain the weakest link.
  • Defending against attacks requires structural changes to the network.

Here's the paradox of modern cyberwarfare: Increasingly, the attackers are using machines that can work orders of magnitude faster than the humans who control them. In response, the targets are increasingly turning to automated systems to detect and repel those intruders.

But in this machine-versus-machine combat, humans remain the center of each battle, and we mere mortals continue to be the weak point. That's the conclusion of this year's survey of the enterprise security landscape from Mandiant, a US cybersecurity firm -- now part of Google Cloud -- that specializes in investigating major global security breaches and advising organizations on how to protect themselves from cyber threats.

Also: Stopping bugs before they ship: The shift to preventative security

Modern enterprise networks are widely distributed and can hand off tasks to partners via software-as-a-service. The bad guys are doing the same thing, according to Mandiant, using a "division of labor" model: one group uses low-impact techniques like malicious advertisements or fake browser updates to gain access to a network, then hands off the compromised target to a secondary group for hands-on access.

And this all happens at a startling pace. In 2022, Mandiant reports, this "time to hand off" was more than eight hours. In 2025, thanks to automation, those hand-offs were happening after an average of just 22 seconds. Likewise, the window to compromise systems with zero-day exploits is also plummeting, with the mean time to exploit vulnerabilities dropping to seven days before vendors have had time to issue a patch.

Identifying the attackers

According to Mandiant, the majority of attackers conducting "hands-on-keyboard operations" in compromised enterprise networks can be divided into two groups with distinctly different tactics and pacing: Cybercriminals pursue financial gain, using tools like ransomware, while espionage groups optimize for long-term, stealthy access.

On one end of the spectrum, cyber criminal groups optimized for immediate impact and deliberate recovery denial. On the other end, sophisticated cyber espionage groups and insider threats optimized for extreme persistence, utilizing unmonitored edge devices and native network functionalities to evade detection.

Those "dwell times" -- that is, the time from intrusion to detection -- average 14 days, but cyber espionage incidents can last much longer, with a median dwell time of 122 days.

Also: The patching treadmill: Why traditional application security is no longer enough

Mandiant identified more than 16 industry verticals that are being targeted, with the high-tech sector (17%) and the financial sector (14.6%) at the top of the list.

Where the intrusions come from

No surprises here: Nearly one-third of detected intrusions come from exploits. The second most commonly observed vector is "highly interactive, voice-based social engineering," with groups targeting IT help desks "to bypass multifactor authentication (MFA) and gain initial access to software-as-a-service (SaaS) environments."

Also unsurprising is the increasing adoption of artificial intelligence tools for reconnaissance, social engineering, and malware development. After gaining access to a network, they report, "attackers are weaponizing AI ... the QUIETVAULT credential stealer was observed checking targeted machines for AI [command-line] tools to execute predefined prompts to search for configuration files and collect GitHub and NPM tokens."

Also: These 4 critical AI vulnerabilities are being exploited faster than defenders can respond

However, AI is still playing a secondary role. "Despite these rapid technological advancements," the report notes, "we do not consider 2025 to be the year where breaches were the direct result of AI. From our view on the frontlines, the vast majority of successful intrusions still stem from fundamental human and systemic failures."

The bad guys are moving faster and breaking things

The entire tech industry has learned from Mark Zuckerberg's infamous imperative for Facebook engineers: "Move fast and break things." That's also true for cybercriminals, who have discovered that ransomware attacks are even more effective when they also target the virtual infrastructure that supports backup tools:

Ransomware groups are no longer just encrypting data; they are actively destroying the ability to recover. ... actively deleting backup objects from cloud storage. ... By targeting the virtualization storage layer directly or encrypting hypervisor datastores, they can render all associated virtual machines inoperable simultaneously.

Also: 1 in 2 security leaders say they're not ready for AI attacks - 4 actions to take now

The good news is that the targets are getting smarter, too. "Organizations are improving their internal visibility. Across all 2025 investigations, 52% of the time organizations first detected evidence of malicious activity internally, an increase from 43% in 2024." The sooner you discover evidence of an intrusion, the sooner you can begin the recovery process.

How to fight back

As attackers get more sophisticated and persistent, IT workers have to step up their game as well. Mandiant's advice includes advanced training for employees and help desk staff on how to recognize modern attack vectors: recognizing social engineering attacks using voice-based tools and messaging apps, as well as unauthorized MFA reset requests.

Here are five other defensive strategies that involve changes in network infrastructure:  

  1. Treat virtualization and management platforms as Tier-0 assets with the strictest access constraints.
  2. To counter the destruction of recovery capabilities, decouple backup environments from the corporate Active Directory domain and utilize immutable storage.
  3. Deploy advanced threat detection across the entire ecosystem and extend log retention policies well beyond standard 90-day windows.
  4. Regularly audit SaaS integrations and route all SaaS applications through a central identity provider (IdP).
  5. Implement behavior-based detection models that flag anomalous activity and deviations from established baselines.

Also: Cloud attacks are getting faster and deadlier - here's your best defense plan

In its conclusion, Mandiant's researchers note that "identity is the new perimeter." Simply rotating passwords and enforcing MFA isn't enough anymore. Focusing on hardening identity controls and shifting to continuous identity verification, especially with third-party vendors, is crucial.