Ransomware in 2026: Encryption Is the Last Step. Detect the Four That Come Before It
The encryptor is the terminal event, not the attack. Detection didn't vanish when breakout hit 29 minutes. It relocated to the pre-encryption phases.
9 posts
The encryptor is the terminal event, not the attack. Detection didn't vanish when breakout hit 29 minutes. It relocated to the pre-encryption phases.
The 2011 kill chain trains you to stop malware at the perimeter. Identity-first attackers skip five of its seven links and log in. What to defend instead.
Prompt injection is OWASP's #1 LLM risk and you can't filter it out. Stop detecting the prompt. Detect the lethal trifecta closing in one session.
Cloud hands every workload a privileged identity by default. Unlike other machine identities it's bound to one host. Use from elsewhere is theft.
An AI agent is a non-human identity with an opaque decision layer. You can't detect the prompt injection, so watch what the agent's credential does.
OAuth abuse bypasses MFA by attacking authorization, not authentication. Most SOCs don't collect consent-grant telemetry. Here's what to detect.
92% of identities are over-permissioned and creep leaves no log line. Stop treating the blast radius as cleanup. Instrument it instead.
Most CTI programs measure IOCs ingested and reports published: activity, not effect. Here's what operationalized intelligence actually looks like.
You have ~45 non-human identities per human, and the signals your detection runs on (MFA, impossible travel, login geo) don't exist for any of them.