The Containment Era is here. →Explore

Executive Summary

In 2025, Unit 42 responded to over 750 major cyber incidents across more than 50 countries, revealing a significant acceleration in attack timelines. Threat actors, leveraging AI, reduced the time from initial access to data exfiltration to as little as 72 minutes, a fourfold increase from the previous year. Identity weaknesses were exploited in nearly 90% of cases, with attackers often using stolen credentials to escalate privileges and move laterally across multiple attack surfaces, including endpoints, networks, cloud services, and SaaS applications. (paloaltonetworks.com) This rapid evolution underscores the urgent need for organizations to enhance their cybersecurity posture. The increasing use of AI by adversaries, coupled with complex and fragmented identity systems, has expanded the attack surface, making traditional defenses insufficient. Organizations must adopt comprehensive security strategies that address these multifaceted threats to effectively mitigate risks. (paloaltonetworks.com)

Why This Matters Now

The 2026 Unit 42 Global Incident Response Report highlights a critical shift in the cyber threat landscape, with AI-driven attacks accelerating at unprecedented rates. Organizations must urgently reassess and strengthen their security frameworks to address these rapidly evolving threats and protect sensitive data. (paloaltonetworks.com)

Attack Path Analysis

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The report highlights a fourfold increase in attack speeds due to AI, with data exfiltration occurring in as little as 72 minutes. It also notes that identity weaknesses were exploited in nearly 90% of incidents, and 87% of attacks involved multiple attack surfaces. ([paloaltonetworks.com](https://www.paloaltonetworks.com/blog/2026/02/unit-42-global-ir-report/?utm_source=openai))

Cloud Native Security Fabric Mitigations and ControlsCNSF

Implementing Aviatrix Zero Trust CNSF could have significantly constrained the attacker's ability to escalate privileges, move laterally, and exfiltrate data, thereby reducing the overall impact of the incident.

Initial Compromise

Control: Cloud Native Security Fabric (CNSF)

Mitigation: The attacker's initial access may have been limited by enforcing strict identity-based access controls and continuous verification of credentials.

Privilege Escalation

Control: Zero Trust Segmentation

Mitigation: The attacker's ability to escalate privileges could have been constrained by enforcing least-privilege access and continuous verification of role changes.

Lateral Movement

Control: East-West Traffic Security

Mitigation: The attacker's lateral movement may have been limited by segmenting workloads and enforcing strict east-west traffic controls.

Command & Control

Control: Multicloud Visibility & Control

Mitigation: The attacker's command and control communications could have been constrained by monitoring and controlling DNS traffic across multicloud environments.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: The attacker's data exfiltration efforts may have been limited by enforcing strict egress policies and monitoring outbound traffic.

Impact (Mitigations)

The attacker's ability to deploy ransomware could have been constrained by limiting lateral movement and enforcing strict access controls.

Impact at a Glance

Affected Business Functions

  • Cloud Infrastructure Management
  • Identity and Access Management
  • Network Security Operations
  • Incident Response
Operational Disruption

Estimated downtime: 7 days

Financial Impact

Estimated loss: $500,000

Data Exposure

Potential exposure of sensitive corporate data, including intellectual property and customer information, due to unauthorized access and data exfiltration.

Recommended Actions

  • Implement Zero Trust Segmentation to enforce least privilege access and prevent lateral movement.
  • Utilize East-West Traffic Security to monitor and control internal traffic flows, detecting unauthorized movements.
  • Deploy Egress Security & Policy Enforcement to filter outbound traffic and prevent data exfiltration.
  • Enhance Threat Detection & Anomaly Response capabilities to identify and respond to suspicious activities promptly.
  • Establish Multicloud Visibility & Control to gain comprehensive insights across cloud environments and enforce consistent security policies.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image