Cybersecurity Watch: Identity Replaces Vulnerabilities as Ransomware’s Top Entry Point

Written by Erwin Castro — Founder & Editor, The CODEW
The CODEW Cybersecurity Watch | August 15, 2026


The CODEW Cybersecurity Watch cover


For the first time in four years, exploited software vulnerabilities are no longer ransomware's leading entry point — stolen identity is. That single reversal, confirmed in this year's largest ransomware survey, reframes almost everything else worth knowing about enterprise security this week: where budgets are going, which regulations are landing, and why AI is reshaping both sides of the fight at once.

The Vulnerability & Exploitation Landscape

VULNERABILITY

The raw volume of vulnerability disclosure keeps climbing without a matching climb in confirmed exploitation — a pattern one veteran researcher at Trend Micro's Zero Day Initiative called the "new normal" for patch density this month. CISA's Known Exploited Vulnerabilities catalog currently tracks more than 1,280 actively exploited CVEs across 275 vendors, with 234 tied directly to ransomware campaigns.


This week's confirmed additions include Progress Kemp LoadMaster (CVE-2026-8037, CVSS 9.6), JetBrains TeamCity (CVE-2026-63077, CVSS 9.8), a Metabase zero-day, and an IBM Langflow code-injection flaw. August's Patch Tuesday added 751 CVEs, with a Windows Ancillary Function Driver flaw (CVE-2026-68820) already under active attack and a critical Microsoft QUIC bug (CVE-2026-62815, CVSS 9.8) requiring no user interaction.

Ransomware: The Identity Pivot

RANSOMWARE

The seventh annual Sophos State of Ransomware report (surveying 2,158 IT leaders) documents a structural shift: compromised identity now drives 79% of all ransomware attacks, overtaking exploited vulnerabilities for the first time in four years. Two-thirds of victims confirmed their ransomware incident and their most significant identity attack were the same event.


Median ransom demands have fallen 65% over two years to $698,000, and 63% refuse to pay. However, data encryption rose to 56% of attacks, and average recovery costs climbed 11% to $1.7 million. Critically, MFA was already deployed in 97% of identity-driven breaches, but push-notification MFA is routinely defeated through fatigue and AiTM phishing. Only phishing-resistant authentication (FIDO2/passkeys) meaningfully closes the gap.

Identity & Access: The New Battleground

IDENTITY

Microsoft reports roughly 600 million identity attack attempts per day, with over 99% still password-based. The overwhelming majority of identity compromise remains credential stuffing, phishing, and password reuse. Industry forecasts describe identity security "eclipsing" perimeter defense as the primary battleground for 2026.


What this means for CISOs: Continuous verification and phishing-resistant authentication need to move from "recommended" to "assumed baseline" for any organization handling sensitive data.

AI-Driven Attacks

AI ATTACKS

AI's role in the threat landscape is now documented. Suspected Chinese state-linked hackers built an autonomous attack tool from open-source AI agents that ran simultaneous reconnaissance and intrusion against Taiwanese government websites. Meanwhile, OpenAI expanded its Daybreak program with GPT-5.6-Cyber for defensive partners, but paused a separate model, Astra, after internal testing found it crossed a "critical cybersecurity threshold." Google's 2026 forecast predicts attackers will use AI across the full attack lifecycle, including prompt-injection and AI-generated phishing.


CrowdStrike and Palo Alto Networks hit record highs this month following Black Hat conference commentary that AI agents have "fundamentally changed the threat landscape."

Enterprise Security Spending

SPENDING

Gartner forecasts global cybersecurity spending at $240 billion in 2026, with IDC projecting $377 billion by 2028. Spending per employee is roughly $2,700, consuming 12–13.2% of IT budgets. Traditional network security spending is the slowest-growing subcategory (9.4%), with budget shifting toward identity, cloud misconfiguration, and AI-generated threats.


PwC data shows 36% of organizations name AI investment as their top cybersecurity budget priority. Consolidation is emerging: Sophos launched Fusion, a unified platform, in response to its own research finding the typical enterprise runs more than 45 separate security products.

Regulatory Developments

REGULATION

The Netherlands' Cyberbeveiligingswet (Cybersecurity Act) enters into force today, August 15, 2026. Germany's CyberGovSecure program has been approved as binding policy across federal departments. At the EU level, the Commission's proposal to amend NIS2 and revise the Cybersecurity Act into "CSA2" is progressing.


The critical near-term deadline is September 11, 2026, when NIS2 reporting duties for actively exploited vulnerabilities and severe incidents formally begin — just under four weeks away.

Cybersecurity Market at a Glance

Metric Value
Global Cybersecurity Spending (2026) $240B
Projected Spending (2028) $377B
Ransomware Attacks Starting with Identity 79%
MFA Deployed in Breaches 97%
Average Ransomware Recovery Cost $1.7M
Security as % of IT Budget 12-13.2%

What Security Leaders Should Watch Next Week

STRATEGIC PRIORITIES
  • OpenAI's Astra model — whether it resumes testing will benchmark how AI labs define internal cybersecurity "stop" thresholds.
  • KEV exploitation activity — particularly Progress LoadMaster and TeamCity, as CISA's 21-day patching deadlines lapse.
  • Netherlands' Cyberbeveiligingswet — early enforcement signals as the first EU member state to activate a NIS2-linked national law.
  • Vendor consolidation — whether other major vendors follow Sophos toward platform consolidation over point-product expansion.
  • Phishing-resistant MFA — adoption data for FIDO2/passkeys specifically, as opposed to push-notification MFA generally.

THE CODEW TAKE

What's changing in enterprise security isn't the threat catalog — ransomware, credential theft, and unpatched software have topped the list for years — it's which of those threats is actually doing the damage, and identity has decisively taken the lead.

That matters to CIOs and CISOs because it changes where budget should go first: the data this week shows perimeter and network security remain necessary but are no longer sufficient, given that MFA was already deployed in 97% of the identity-driven breaches Sophos studied. AI compounds the urgency on both sides at once — autonomous agents are already running real reconnaissance-and-intrusion operations in the wild, while the same labs building defensive AI tooling are quietly admitting their own models occasionally cross safety thresholds internally.

For technology buyers, the practical takeaway is to treat identity architecture, not perimeter hardware, as the primary security investment for the next budget cycle, and to ask AI-security vendors specifically how their tools perform against AiTM and MFA-fatigue techniques — not just whether they detect malware faster.


Source Attribution

  1. Zero Day Initiative — The August 2026 Security Update Review
  2. CrowdStrike — August 2026 Patch Tuesday: Updates and Analysis
  3. Senserva — Known Exploited Vulnerabilities: Live CISA KEV Catalog (August 2026)
  4. Sophos — State of Ransomware 2026
  5. InfotechLead — Sophos Ransomware Report 2026
  6. DeepStrike — Cybersecurity Statistics 2026
  7. CDNetworks — Key Cybersecurity Statistics and Emerging Trends for 2026
  8. StationX — Cybersecurity Spending Statistics 2026
  9. CNBC — CrowdStrike, Palo Alto Hit Records After Black Hat
  10. CNBC / TechCrunch — OpenAI Expands Daybreak Cybersecurity Initiative
  11. Financial Times — Suspected Chinese Hackers Used AI Agents
  12. Skadden — European Commission Announces Potential NIS2 Reform
  13. NISD2.eu — NIS2 Regulatory Timeline
  14. VinciWorks — Cyber Security in 2026: Legislative Shifts



THE CODEW · CYBERSECURITY WATCH

Editorial Note

The CODEW Cybersecurity Watch examines the rapidly evolving enterprise security landscape, focusing on where threats are moving, how defense strategies must adapt, and which companies and technologies are positioned to protect the digital economy. It covers ransomware, identity security, AI-driven attacks, enterprise spending, regulation, and the strategic shifts that matter to security leaders and technology buyers.

Coverage is based on company announcements, public disclosures, industry reporting, and other publicly available information. Analysis reflects the reporting period and should be considered in the context of the sources and developments cited.

Cybersecurity Watch: Identity Replaces Vulnerabilities as Ransomware’s Top Entry Point Cybersecurity Watch: Identity Replaces Vulnerabilities as Ransomware’s Top Entry Point Reviewed by Erwin Castro on Saturday, August 15, 2026 Rating: 5
CRM + marketing automation + payments in one integrated platform. Helps small businesses streamline sales and automate the follow-up work that falls through the cracks. Get Keap