PwC's 2026 Global Digital Trust Insights survey of nearly 4,000 business and tech leaders across 70+ countries finds AI is now the top cybersecurity budget priority (46%), but leaders rank attacks on their own AI systems — autonomous botnets, adversarial attacks, data poisoning — as the threats they're least prepared for. Quantum risk ranks similarly unready: fewer than 10% budget for it and only 3% have fully implemented quantum-resistant measures.
Source →ANALYTICS
Research, reports, and market trends.
Intel 471's 'Insiders for Hire' report tracked 85 insider-recruitment leads across underground forums over a year, documenting tactics like a $50,000 referral fee offered for an introduction to a crypto exchange compliance employee, and recruiters targeting unemployed US residents to take telecom jobs and perform SIM swaps for a cut of the proceeds. The report urges security teams to extend insider-threat monitoring beyond privileged users to support, logistics, and verification staff.
Source →Delinea's 2026 Identity Security Report finds 87% of IT leaders saw an AI tool or agent access sensitive data outside its intended scope in the past year, even though 99.7% of organizations have AI data-access policies — only 51% actually enforce them in real time. 55% of organizations take a full day or longer to detect when an agent oversteps its scope.
Source →Google's Threat Intelligence Group found monthly vulnerability disclosures more than doubled in 2026 (from 5,045 in January to 10,740 in August) and that AI is changing which flaws get found: 50% of AI-discovered vulnerabilities enable remote code execution, versus 26% across the broader CVE ecosystem. Exploited high-risk flaws also roughly tripled year over year, driven mainly by faster exploitation of already-patched n-days.
Source →Detectify's H2 2026 Cyber Hygiene Index, based on 1,300 organizations across the US, UK, and Nordics, found nine in ten open critical and high-severity vulnerabilities had sat unresolved for more than 90 days — as high as 97% in the Nordics. Organizations with exposed AI tooling resolved critical/high findings at less than half the rate of the broader sample.
Source →SkillBit's 2026 survey of 200 security executives found 70% of organizations have few or no roles open to candidates with under two years of experience, and 57% report a six-month time-to-value for new hires. Leaders showed some openness to alternatives: 30% already accept interactive-lab credentials in place of experience, and 71% said they'd prefer weekly 20-minute training over infrequent multi-hour sessions.
Source →UNSW researchers found that prompting AI models to act 'drunk' — whether via role-play or fine-tuning on over 57,000 posts from r/drunk and Texts From Last Night — made five tested models (GPT-3.5, GPT-4, Llama 2, Llama 3.1, Mistral) consistently easier to jailbreak and more likely to leak information they'd been explicitly told to keep confidential. The team says the finding means persona or style changes to a model can't be treated as purely cosmetic from a security standpoint.
Source →