Cyber Daily: Fabio, you’ve said that organisations that rely upon malware-driven tools are basically making themselves vulnerable. What do you mean by that?
Fabio Fratucello: So that comes from pretty much checking what the current thread landscape is doing, what modern thread actors are doing.
If we look at the macro – a lot of those stats come from the 2026 Global Threat Report that CrowdStrike published – there are some very strong themes that have emerged. One of those is identity, now a key domain, a mandatory domain. We’re seeing so many adversaries operating and focusing on the identity domain. And it’s no surprise, because if we look at what defenders do as part of detection and response activities, when an attack starts from a pure identity standpoint, the attackers are logging in instead of breaking in.
When you put that into perspective, when you put that into your defensive methodologies, your kill chain, it just becomes more challenging and more difficult for defenders to kickstart their response, their analysis, and all those activities that are required for detection and containment.
Cyber Daily: I’m assuming these threat actors are getting hold of these credentials via other data breaches. Is that the case?
Fabio Fratucello: That is definitely the case.
If we look at the threat landscape and the e-crime composition, we now have adversaries that – some of them, a good amount of them – are highly specialised. You will have, for example, what are called access brokers. These adversaries are specialised – what they do is harvest credentials; they’re not necessarily using those credentials to go ahead.
Cyber Daily: No, they’re selling those credentials.
Fabio Fratucello: We’re just gonna sell it on the dark web, yeah.
Cyber Daily: I’m kind of fascinated by this idea of a cyber criminal who is willing to go this far, but no further, because they know if they break into a network, that’s a level of crime they’re not willing to commit, but they’re willing to sell that on. There’s a whole criminal ecosystem that’s just selling passwords and credentials – I don’t think it’s something that a lot of people are aware of. How widespread is that?
Fabio Fratucello: Part of the reason is what you just mentioned, that there might be a posture about ... what adversaries are willing to do.
Another element to consider is that, unfortunately, when you are great at doing something, there’s an opportunity to focus on that exclusively. And so, if you think of skills and proficiency and effectiveness, what that creates is an ecosystem where adversaries are getting more specialised in a specific part of the attack chain, and they just keep doing what they are extremely successful at doing.
Cyber Daily: It’s no different from what we do as journalists. And you too – we’re specialists. And the criminal ecosystem has its own specialists that do what they do and do what they’re good at.
Fabio Fratucello: That’s correct.
It’s organised, unfortunately; it is an organised business, right? And so, we have the access broker, and we have, for example, others that we call cloud-conscious adversaries.
And you know, they don’t mix with each other. So, cloud-conscious adversaries, for example, there are threat groups that are specialised in targeting cloud environments, and they have outstanding skills in understanding AWS, GCP, Azure, your …
Cyber Daily: Salesforce?
Fabio Fratucello: Salesforce, all those cloud environments … They know what the underlying primitives are that are available uniquely in those environments. What are the likely vulnerabilities? What are the likely misconfigurations? What are the likely overall deficiencies of the system? And how can those be exploited?
Because effectively, they have access to underlying primitives and capabilities without having to bring tools into the environment. Again, a different concept from what we just discussed about identity.
But not too dissimilar.
Cyber Daily: Yeah, but also you’re talking about utilising legitimate tools that already exist in the environment, so what are those guys doing?
Fabio Fratucello: That’s something that we have seen in the last GTR, and in previous iterations. We expect this to continue to be a trend, because – again – it speaks to bringing additional challenges from a defensive standpoint.
If tools are available in the environment, they are likely to generate some level of noise. So, the fidelity of the signal from a detection standpoint, through positive versus false positives, may be a little bit skewed from bringing something that is 100 per cent malicious and is easier to detect with defensive tools.
This is called living off the land. You’ve probably heard this term a few times – it’s not something that just popped up in 2026. But the concept is brilliant to some extent, and I do expect that, as technology progresses, we’re gonna see new iterations of the same concept, with maybe different technical blends as we move forward.
Cyber Daily: In my limited experience, living-off-the-land techniques are often used by state actors. Are we seeing criminal actors using the same techniques?
Fabio Fratucello: Yes. If we look at what is, effectively, the demarcation between nation-state and e-crime, that has become smaller and thinner.
Nation-states continue to be the threat actors and groups that have the highest capabilities. They have the greatest resources at their disposal to carry out attacks. But when we just look at, for example, skill and proficiencies – and particularly with some of the GenAI tools that are now available to everyone, including adversaries – we’re seeing the level of sophistication, the level of skills, sometimes even the persistence, and the volume of some of the e-crime actors is getting up to a nation-state level.
So, yes, absolutely, we’ve seen some of those that have been using living-off-the-land techniques as well.
Cyber Daily: And that brings us to agentic AI. People are worried about AI-powered attacks and the necessity for AI-powered defence. How fundamental is that shift in the landscape?
Fabio Fratucello: It is a fundamental shift.
But, I think it is good to try to – in a time where everyone, in my opinion, is fantasising a little bit about AI and what it means – let’s try to be a bit realistic about it.
So there is a shift. Let’s acknowledge that it’s big, and it’s wide, right? What AI is doing, though, is predominantly giving adversaries the ability to achieve higher volume. We’re talking about scaling. We’re talking about automation and speed. At this point in time, however, we haven’t seen AI discover new attacking methodologies, right?
If we think of the R&D and the evolution from an adversary standpoint, that continues to be human-driven. Particularly with some of these frontier AI models, a great example is in the vulnerability management domain. Those capabilities, they’re actually great, and they’re able to go through a huge amount of lines of code, able to keep context, a pretty large memory window, and understand where deficiencies, where bugs, where vulnerabilities are discovered.
They have the ability – because the context window is so large – to understand if there are multiple deficiencies, how those deficiencies can be tied together, maybe chained together – from an offensive standpoint. And they’re also great at creating patches from a defensive standpoint, but also finding exploits from an adversarial standpoint.
That’s from a frontier AI model. If we go back to what I mentioned, scale and volume, those general AI capabilities are available to everyone. They’ve been available to the world for quite some time. The challenge is – and one of the actions that I always encourage customers, when I speak to them, is that AI is here, it’s been here for quite some time, and adversaries are taking advantage of it: “Are you taking advantage from a defensive standpoint?”
Because if you think about it, in the defensive world, we have regulations, we have governance, we have a number of technical processes and controls. These have a good reason to exist, but also, they may slow down innovation.
Those limits don’t exist in the attacker space, though. They’re not regulated. They’re not waiting for a change management approval to jump on a new AI technology and use it. So we now have this picture where, on one side, we have the attacker that has the ability to innovate without limit, at their own pace, resources, and whatever, but we have constraints on the other side.
The technology’s here, and the technology is great, both from offending and from a defensive standpoint. AI capability is one of the best technologies, for example, to detect and respond to an AI-led attack. It’s just a matter of … Do we have the right pace of change from a defensive standpoint, and are we adopting the right technologies?
Cyber Daily: You mentioned the fact that both threat actors and network defenders have AI, so does that mean we’re kind of … at the same level we were pre-AI? That it’s just different tools being employed to do the same thing at the moment? And that means the fundamentals haven’t really changed?
Fabio Fratucello: That’s an interesting question. I think it would be superficial to put it that way, to some extent.
Cyber Daily: That’s fair.
Fabio Fratucello: We’ll probably need to bring it down into the various domains and different companies … Or maybe different sectors are jumping on those capabilities?
Because again, just because something is available, it doesn’t necessarily mean that, in the first instance, the technology has been adopted, and that it’s been adopted and embedded properly. If you think about, again, the difference between attacking and defending: attacking is complex by nature, and it’s technically difficult, but process-wise, it’s simpler. It requires less organisation; you need to pick a target, and then, from there, you can reverse the kill chain and all of that.
Cyber Daily: Yeah, and an attacker can fail as many times, and it doesn’t ... It has no impact, but a defender fails, and ...
Fabio Fratucello: Correct, correct. And we’ve been trying to reverse that model, which, to some extent, has been reversed, and AI capability can help with that, because what you said has been true, and it’s been a nightmare for me and many other folks who have been in security operations centres for years.
And again, we can then talk about the difference in difficulty in attacking versus defending. But particularly now, if we start employing AI capabilities, from a defensive standpoint, as soon as an attacker makes some noise, we can start analysing, detecting, and responding. What that means in today’s landscape – and we talked about cloud, and we talked about identity – it’s extremely likely that an attack is going to be a cross-domain attack.
This means it’s going to span across multiple logical domains, multiple technolog[ies], maybe it’s going to be a combination of on-prem, cloud environment, and so forth. Now, if we go back to what we were discussing earlier, we now have a signal. And if we’re not using an AI-enabled platform for defence, that signal can be interpreted as something that happens somewhere, but it’s not necessarily something that happened in the cloud. And if we’re not using the right platform, the right AI technology to stitch all the relevant telemetry across multiple environments – that’s just one element, but it’s not the entire picture.
One of the great uses for AI is going through a huge amount of data volumes and making sense of the data. That’s why it’s a great technology to employ from a defensive standpoint.
Cyber Daily: When you have millions of signals coming in that no human can process, having the AI do that for you is a huge advantage. But, again, I feel like security fundamentals are still so important, despite the excellent tools we have on our side.
Fabio Fratucello: Fundamentals are critical. They will continue to be critical.
You can look at it in many ways. One of the ways that I’ve recently talked about it with many customers is in relation to frontier AI models – what do they mean for the vulnerability management domain?
Higher volumes of exploits to deal with, and very likely, the window of time from vulnerability discovery to exploit creation becomes shorter and shorter, because it’s now done by AI instead of a person writing the code. Then from there, you start doing your patching and all of that.
There’s nothing new here, except volume and speed.
Want to see more stories from trusted news sources?Make Cyber Daily a preferred news source on Google.