Cyberattacks are moving faster, and automation is making familiar threats easier to carry out. A new cybersecurity report by Comcast Business examines how attackers are using these tools to find vulnerabilities, gain access and move through enterprise systems.
Analyzing 79.3 billion security events recorded between March 2025 and February 2026, the company’s 2026 Cybersecurity Threat Report covers phishing, vulnerability scanning and attempts to steal information.
The findings also identify browsers, business applications and exposed infrastructure as areas attackers are targeting, with AI adding another layer to how these campaigns are developed and carried out.
Why It Matters: Automation is changing how much time organizations have to respond to security threats, putting greater pressure on processes that still depend on manual investigation and coordination. The findings also bring attention to how security responsibilities extend across infrastructure, identity management and enterprise applications. Maintaining visibility across those systems becomes more important when attackers can use legitimate access and familiar tools to move through an organization without immediately triggering an obvious warning.
- Attack Activity Is Reaching Enormous Volumes: Researchers recorded 47.9 billion initial access events and another 5.2 billion associated with attackers preparing resources for potential attacks. These numbers represent observed security activity across monitored customer environments, not successful breaches. Much of this activity comes from automated tools that can operate continuously with little manual involvement, leaving security teams to distinguish meaningful threats from large volumes of unsuccessful attempts and routine background activity.
- Phishing Is Familiar, but the Effort Behind It Is Changing: The report identified 25.4 billion phishing events and 21.9 billion drive-by compromise events, showing how heavily attackers continue to rely on established methods of gaining access. AI is making some of those campaigns easier to develop and adjust, helping attackers generate convincing messages and produce variations of malicious content with less manual effort. Researchers also found evidence of malware written with assistance from large language models, adding another example of how AI is becoming part of the attack process.
- Attackers Are Looking for Weaknesses Before They Can Use Them: Not every scan is tied to an immediate attempt to break into a system. Among the 288.9 million scanning events detected, the report describes activity intended to identify and catalog exposed infrastructure that may become useful when new vulnerabilities are discovered. That preparation can give attackers a head start once an exploit becomes available. The time between vulnerability discovery and exploitation is also getting shorter, leaving organizations less room for delays in identifying affected systems and applying fixes. For companies managing large numbers of internet-facing devices and applications, knowing which systems are exposed can help determine where remediation efforts need to begin.
- The Browser Is Becoming Another Way Into the Business: An estimated 5.8 million attempts to control browsers were detected, including activity involving extensions, synchronization features and active sessions. A stolen session, for example, may provide access to an application without requiring the attacker to enter a password again. With employees regularly moving between SaaS platforms and personal or corporate accounts, browser activity can create exposure across several systems. Extension permissions, account synchronization and centralized browser management are among the areas identified for closer attention.
- Legitimate Tools Can Help Attackers Avoid Detection: Another 1.3 billion blocked events were associated with attempts to move data out of protected environments. Once attackers gain access, they may use administrative tools and permissions already available within the organization, making their actions harder to separate from ordinary activity. An individual command or file transfer may appear routine even when it is part of a larger attack. The report emphasizes monitoring behavior across different stages of an incident, including unusual access patterns and movement between systems. Connecting those activities can provide a clearer picture of what is happening, particularly when the original point of entry does not produce an obvious alert.
Go Deeper -> The 2026 Comcast Business Cybersecurity Threat Report – Comcast Business


