Q3 2026 Attack Techniques Trend Report

Q3 2026 Attack Techniques Trend Report

Overview


In the third quarter of 2026, there was a notable increase in cases where attackers attempted to establish persistence and expand their attacks using paths trusted by the organization following their initial access. Attacks on perimeter devices such as NetScaler and Cisco FMC led to the installation of web shells (server-side scripts for remote command execution) following vulnerability exploitation, while in the supply chain, malicious versions were distributed through official package registries. In identity-based attacks, attack cases were observed where attackers impersonated password reset notifications to obtain sessions and tokens.

Analysis


There were 100 new listings in CISA’s KEV from July to September 2026, a twofold increase compared to the 50 listings during the same period in 2025. Of these, 31 involved web and server applications, and 30 involved network and perimeter devices, accounting for 61.0% Of the total. The list also included 9 development and deployment tools and 6 AI and LLM tools.

Regarding breaches of perimeter devices, exploitation of CVE-2026-88771 and CVE-2026-88772 in NetScaler ADC and Gateway, as well as CVE-2026-20079 in Cisco Secure Firewall Management Center (FMC), CVE-2026-20316 were confirmed. Threat actors deployed web shells on legitimate web paths and disguised them to appear as .Deb file names or CSS resources. In the Cisco FMC cases, attackers placed JSP web shells and JAR command execution executors in Tomcat web paths to harvest authentication credentials. In some instances, they also set the SUID and SGID bits on /bin/sh to elevate the privileges of subsequent commands.

In supply chain attacks, malicious versions of the keyv and cacheable families, as well as the @7nohe/openapi-react-query-codegen and MemTensor npm and PyPI packages, were distributed. Preinstall scripts, binding.Gyp files, module loading phases, and publication workflow triggers were used as Malware Paths. Ten malicious versions of @7nohe/openapi-react-query-codegen were even assigned legitimate npm provenance.

In identity attacks, the report covered attack cases where Okta and Microsoft were exploited through passkey registration, password recovery, and help desk impersonation calls and text messages. Methods were identified where threat actors used AiTM phishing—an attack that intercepts sessions from a middleman position—to steal session tokens or obtain tokens for the threat actor’s client through device code authorization. Subsequent cases involved gaining access to OfficeHome, the identity portal, Microsoft Graph, SharePoint, OneDrive, and Exchange.

Key techniques were classified under MITRE ATT&CK Enterprise as T1190, T1505.003, T1548.001, T1036, T1195, T1566.004, And T1078.004. A common thread is that the privileges and authentication methods obtained after the Initial Intrusion were used for persistence and expansion.

Prevention and Detection Information


For perimeter devices, prioritize applying patches in accordance with KEV and vendor recommendations, and inspect exposed management functions and DTLS settings. Check for new files in /vpn/scripts/linux/ and /var/netscaler/logon/LogonPoint/custom/, changes to web server configurations, changes to /bin/sh permissions, and traces of web shell invocations.

For the supply chain and build pipeline, verify the caller permissions of deployment triggers, input sources, and whether source commits match deployment artifacts. Inspect secrets accessible in developer and CI environments, and if a malicious version is detected, replace tokens and credentials in affected environments.

When responding to identity attacks, passkey registrations and recovery requests must be re-verified through internal validation channels, and unnecessary device code flows must be restricted. All active sessions, registered authentication methods, and approved applications must be inspected together, and conditional access and phishing-resistant authentication must be implemented.

Overall, this quarter demonstrates the importance of IoA (Indicator of Attack)-based detection—which focuses on the sequence of behaviors rather than individual file names or domains.