back to course
Lesson 03 / 427%· free preview
Fundamentals3/6
Threat Landscape 2026
Definition
The threat landscape is the set of attacker techniques, actors and trends that are currently active. It changes every quarter.
1. Top Threats Today
| Threat | What attackers do | What defenders do |
|---|---|---|
| Ransomware-as-a-Service | Encrypt + exfiltrate, double extortion | Offline backups, EDR, segmentation |
| Supply-chain attacks | Compromise vendor (SolarWinds-style) | SBOM, signed builds, vendor audits |
| AI-generated phishing | LLM-crafted spear-phishing, voice deepfakes | FIDO2 keys, link sandbox |
| Cloud mis-config | Public S3, leaky CI tokens | IaC scanning, least-privilege IAM |
| LLM prompt injection | Hijack AI agents, exfiltrate via RAG | Input/output guardrails |
| IoT botnets | Mirai-class for AI training infrastructure | Default-creds ban, firmware signing |
2. Old vs New Threats — Differences
| Dimension | Pre-2020 | 2026 |
|---|---|---|
| Phishing language | Broken English | Native, voice deepfakes |
| Malware | Static binaries | Polymorphic, AI-mutated |
| Targets | Workstations | Cloud, AI pipelines |
| Tooling | Manual | LLM-assisted (red & blue) |
| Time to weaponise a CVE | Weeks | Hours |
3. Why "Quantum" is on the 2026 Risk Register
Quantum computers can break RSA / ECC with Shor's algorithm. While usable quantum is still years away, attackers are already harvesting encrypted traffic to decrypt later. Standards bodies (NIST) have selected CRYSTALS-Kyber as the post-quantum KEM.
Diagram
Decade ┌──────────────┬──────────────┬──────────────┐
2010s │ worms │ ransomware │ APT │
2020s │ cloud mis- │ supply- │ AI-phish │
│ config │ chain │ │
2026+ │ LLM injec- │ voice deep- │ quantum │
│ tion │ fake fraud │ harvest │
└──────────────┴──────────────┴──────────────┘
Common Mistakes
- Treating last year's threat report as today's playbook.
- Ignoring vendor risk because "we don't host that".
- Assuming AI alerts are accurate without human review.
Quick Revision
The 2026 attacker writes better English than yesterday's grad. Spelling is a dead signal — rely on tech, not grammar.
Key Takeaways
- Threats evolve faster than annual budgets — review quarterly.
- Defence must include vendors, AI tooling and identity, not just the perimeter.
- Start tracking quantum-readiness of every long-lived encrypted data store.
Interview Questions
Practice Questions
- Read a recent CISA advisory and summarise it in five bullets.
- Identify one supply-chain dependency in a project you ship.
- Try a defensive prompt-injection demo on a chat app you own.
Pro Tips
- Ransomware now commonly involves data exfiltration and public shaming, known as double extortion, requiring a broader incident response.
- AI and LLMs will increasingly automate and personalize attacks; focus on securing AI interactions and implementing robust guardrails.
- Supply chain attacks remain critical; always rigorously vet third-party software, hardware, and service providers.
- The "Harvest Now, Decrypt Later" quantum threat demands immediate planning for post-quantum cryptography implementation.
- Social engineering will be amplified by AI-generated deepfakes and personalized content, making advanced training crucial.
AI-powered recap
Quick recap quiz?
We'll generate 5 MCQs from this lesson and check your understanding instantly. Takes ~30 seconds.
Ready to move on?
// feedback.matters()
Did this lesson help you?
