惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Engineering at Meta
Engineering at Meta
D
Docker
IT之家
IT之家
博客园_首页
罗磊的独立博客
V
V2EX
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
美团技术团队
Y
Y Combinator Blog
博客园 - 聂微东
量子位
阮一峰的网络日志
阮一峰的网络日志
GbyAI
GbyAI
Microsoft Security Blog
Microsoft Security Blog
博客园 - Franky
Martin Fowler
Martin Fowler
Jina AI
Jina AI
大猫的无限游戏
大猫的无限游戏
C
Check Point Blog
月光博客
月光博客
G
Google Developers Blog
B
Blog
T
The Blog of Author Tim Ferriss
爱范儿
爱范儿

Featured Blogs - Forrester

Customer Zero Proves AI Works When Humans Change Customer Zero Programs Prove That AI Works When Humans Change Prime Day, June 2026: How Retailers Competed With Amazon Inclusive Design Is Automotive’s Overlooked Growth Opportunity B2B Social Media Influencers Have More Influence Than Ever Comcast Split Puts NBCUniversal In Play What Technology Leaders Should Not Miss At Technology & Innovation Forum Central Why Your AI Strategy Needs A DEXM Solution: Lessons From Nexthink Masters Of Experience The Dawn Of The Accidental Developer The Next Era Of B2B Events: 8 Data-Backed Shifts Defining 2026 The Next Era Of B2B Events: Eight Data-Backed Shifts Defining 2026 Identiverse 2026 Recap: Identity Security for Agentic AI Dominates Announcing The Forrester Wave™ On Extended Detection And Response Platforms: Platformization, AI, And…AI Announcing The Forrester Wave™ On Extended Detection And Response Platforms: Platformization, AI, And … AI Use EO 14409 As A Canary For Enterprise PQC Migration And Procurement Use The New Executive Order As A Canary For Enterprise PQC Migration And Procurement EO 14409 Makes PQC Migration A Multi-Year Operational Program For Federal Security Leaders New Executive Order Makes PQC Migration A Multiyear Operational Program For Federal Security Leaders AI Is Moving Fast, But Trust Is Struggling To Keep Up: Why Security And Risk Leaders Can’t Miss Forrester’s AI Forum Answer Engines Will Select Your Content. Your Digital Experience Has To Do More. Meta Gambles With Its Trust In Prediction Markets The EU’s Digital Markets Act Meets The Mobile OS, Round 2 Don’t Just Hear About The IT Singularity — Work Through It At Our Austin Tech Forum Don’t Just Hear About The IT Singularity — Work Through It At Our NYC Tech Forum The Cost Of AI Productivity Is Less Creativity Dollars And Sense At FinOps X 2026: Is AI Value Management Bigger Than FinOps? Quantum Security Is No Longer Optional: A Practical Blueprint For Successful Implementation The AI Orchestration Layer In Banking Is The New Battleground The Canary in the CDP Mine: Databricks CustomerLake Is The Litmus Test For Agentic Marketing The Canary in the CDP Mine: Databricks CustomerLake Is The Litmus Test For Agentic Marketing AI Forces A Redesign Of How Marketing And Agencies Work
Announcing Forrester’s Top Cybersecurity Threats For 2026
Jitin Shabadu · 2026-06-11 · via Featured Blogs - Forrester

AI innovation is moving at an unprecedented rate, and geopolitical tensions show no signs of easing. Forrester identifies these factors as two primary forces reshaping the threat landscape, placing additional strain on CISOs who are already stretched thin managing increasingly complex security programs.

Anthropic’s Claude Mythos Preview and Project Glasswing are early signals of how radically areas such as vulnerability discovery, remediation, and exploitation are about to change. Simultaneously, the escalating US-Iran conflict has already translated into real world impact, driving a spike in disruptive cyberattacks; from the Stryker incident to Iranian-linked actors targeting PLCs across US critical infrastructure.

AI has been a consistent thread running through the last three editions of Forrester’s top threats report. AI‑driven threats have evolved across the past three years as follows:

  • AI is more than LLMs and ChatGPT. Back in the top threats report for 2023, when ChatGPT was still the public’s first real handshake with large language models, we flagged data integrity as the standout risk. The concern here was the trust placed in these AI systems.
  • AI has been weaponized. In the 2024 edition of the report, the focus shifted from trust to misuse. We called out how genAI was being weaponized for enabling narrative attacks via disinformation, growing concerns around deepfakes, and concerns over AI responses due to prompt engineering, injection attacks, or the increased risk of sensitive data spillage.
  • AI supply chain risk emerged. In 2024, we also flagged the AI software supply chain risk as a threat (Spoiler: This concern hasn’t gone away, and it shows up again in this year’s report with updated findings). This is driven by adoption of open‑source models and frameworks such as those found in Hugging Face and GitHub.
  • Deepfakes are maturing and evading detection. For the 2025 iteration, deepfakes showed up again, not due to novelty but because of how easy they have become to produce as creation capabilities continued to outpace detection. However, the net new threat categories were tech exuberance over genAI as models proliferate and deployment options increase, and the rise of genAI-driven extortion.

To support security leaders as they prepare to defend against new and emerging threats, Forrester has released the report, Top Cybersecurity Threats In 2026. This annual publication outlines the most critical risks organizations need to plan for.

What’s New In This Year’s Report?

This report is based on trends and observations from the market at large and the threat landscape. We expect enterprises to experience one or more of the following in 2026:

  1. Near autonomous attacks from a nation-state. Easy access to AI models enables nation‑state threat actors to automate and scale more sophisticated exploitation at unprecedented speed. Recent cases, such as Anthropic’s report on the China-linked actor using Claude code to conduct a cyber-espionage campaign and, the disclosure by Google’s Threat Intelligence group about cases of attackers misusing Gemini highlight this trend. Hence, defenders must prepare to defend against autonomous attacks and adopt agentic security capabilities anchored in trust, cost, and utility.
  2. Concerns over agent threats. Personal agents “claw” their way into enterprises via browser hooks and inbox access, turning into shadow operators that access data and perform actions at machine speed outside of governance and visibility, leaving CISOs accountable for increased exposure with limited control. Security leaders must inventory agents, enable policies, actions, and tests while governing use through dedicated vendor platforms.
  3. Non-negotiable AI software supply chain. Building on its 2024 inclusion as a threat category, agentic AI turns things such as tools, models, skills into a sprawling and fast‑changing supply chain risk. Organizations must adopt a dedicated AI supply chain playbook that enables aspects such as inventorying all AI components, requiring AI‑BOM transparency, applying supply‑chain controls, and enforcing least‑agency for agents.
  4. Provenance and IAM risks of AI agents. AI agents force a shift from legacy IAM to agent‑specific identity, provenance, and access controls, with standards maturing rapidly and accelerating the adoption of commercial solutions. Organizations must control and govern internal, inbound, and outbound AI agent identities, access, and their activities by implementing agent‑specific IAM. For inbound agents, inspect inbound API requests and check provenance to manage access to MCP servers and tools; for more complex scenarios, use externalized AI agent authorization tools.
  5. Digital sovereignty spans regions and tech stacks. Pushes for digital sovereignty can backfire and introduce nascent and fragmented tech stacks. This leaves security leaders vulnerable, especially in regulatory demands. Treat sovereignty-driven providers as a supply chain risk by performing stress tests, evaluating compensating controls, and mandating CISO sign‑off.

To learn more about these threats and how to respond to them, read the full report.

For any questions about the threat landscape, book an inquiry or guidance session with me or one of my colleagues.

Categories

Blog

Conway’s Law: Your Operating Model Matters More Than The AI Model

I love an axiom, something easy to remember, fast to say, and punchy enough to stick. With my older boys, I’ve often said, “If in doubt, don’t.” With my younger son, who is autistic, I say, “Stay close; stay safe.” These are short phrases with big truths, the kind that helps in the moment when […]

Blog

OpenAI’s Proposed IPO Opens A Trifecta Of Opportunities For It, But Don’t Lock In Just Yet

OpenAI’s IPO move, paired with its latest manifesto, highlights a race to win consumers, automate enterprises, and advance toward AGI. For business and technology leaders, the implication is clear: Accelerate AI adoption, avoid lock-in, and focus on capabilities, not vendors, as the competitive landscape shifts.

Get The Insights At Work Newsletter

Business Email Address*

Yes, I’d like to receive Forrester’s Insights At Work newsletter and receive occasional survey invitations and marketing communications.

Thanks for signing up.

Stay tuned for updates from the Forrester blogs.