Prophet Security investigated every alert across customer environments from May 1 to July 31, 2026, to produce its first quarterly threat report. This methodology aimed to eliminate bias from human analyst decisions on alert prioritization. The analysis revealed that identity was the target in approximately half of all confirmed malicious activity during this period.
The report identified session hijacking as the most successful method for attackers to compromise accounts. Direct attacks on accounts and sessions constituted about 18% of confirmed malicious activity. These included token replay, MFA bypass, credential stuffing, and post-compromise persistence techniques like inbox rules and OAuth consent grants.
A key finding was that attempts using an already-authenticated session consistently succeeded, while password-based attempts were usually blocked. Security measures such as conditional access and phishing-resistant MFA effectively stopped attacks involving passwords or credential capture. However, replayed session cookies bypass initial authentication, preventing conditional access policies from triggering and allowing attackers continuous access to accounts.
The success of session hijacking highlights a gap in current security strategies, where replayed session cookies can circumvent established conditional access checks. This allows attackers to maintain access to compromised accounts for extended periods, as observed with individual accounts experiencing dozens of malicious sign-ins over several weeks. The report suggests a need for re-evaluation of security controls that rely solely on initial authentication checks.
✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →
One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.
▶ Play today's briefNew every morning, and the back catalogue is archived by date.
Prophet Security's Q2 2026 threat report, based on investigations of all customer alerts, found that identity was the target in roughly half of all confirmed malicious activity. Session hijacking, using already-authenticated sessions, was the most successful attack method, bypassing standard security controls that block password-based attempts.