ブログ
/
AI
/
February 13, 2024

Predicting the Future of Cyber Security and Cyber Threats

Read about cyber security predictions and cyber threats in 2024. Staying up-to-date on cyber attacks and cyber security is vital to all organizations.
Inside the SOC
Darktrace cyber analysts are world-class experts in threat intelligence, threat hunting and incident response, and provide 24/7 SOC support to thousands of Darktrace customers around the globe. Inside the SOC is exclusively authored by these experts, providing analysis of cyber incidents and threat trends, based on real-world experience in the field.
Written by
The Darktrace Threat Research Team
Default blog image
13
Feb 2024

2024 Cyber Threat Predictions

After analyzing the observed threats and trends that have affected customers across the Darktrace fleet in the second half of 2023, the Darktrace Threat Research team have made a series of predictions. These assessments highlight the threats that are expected to impact Darktrace customers and the wider threat landscape in 2024.  

1. Initial access broker malware, especially loader malware, is likely to be a prominent threat.  

Initial access malware such as loaders, information stealers, remote access trojans (RATs), and downloaders, will probably remain some of the most relevant threats to most organizations, especially when noted in the context that many are interoperable, tailorable Malware-as-a-Service (MaaS) tools.  

These types of malware often serve as a gateway for threat actors to compromise a target network before launching subsequent, and often more severe, attacks. Would-be cyber criminals are now able to purchase and deploy these malware without the need for technical expertise.  

2. Infrastructure complexity will increase SaaS attacks and leave cloud environments vulnerable.

The increasing reliance on SaaS solutions and platforms for business operations, coupled with larger attack surfaces than ever before, make it likely that attackers will continue targeting organizations’ cloud environments with account takeovers granting unauthorized access to privileged accounts. These account hijacks can be further exploited to perform a variety of nefarious activities, such as data exfiltration or launching phishing campaigns.  

It is paramount for organizations to not only fortify their SaaS environments with security strategies including multifactor authentication (MFA), regular monitoring of credential usage, and strict access control, but moreover augment SaaS security using anomaly detection.  

3. The prevalence and evolution of ransomware will surge.

The Darktrace Threat Research team anticipates a surge in Ransomware-as-a-Service (RaaS) attacks, marking a shift away from conventional ransomware. The uptick in RaaS observed in 2023 evidences that ransomware itself is becoming increasingly accessible, lowering the barrier to entry for threat actors. This surge also demonstrates how lucrative RaaS is for ransomware operators in the current threat landscape, further reinforcing a rise in RaaS.  

This development is likely to coincide with a pivot away from traditional encryption-centric ransomware tactics towards more sophisticated and advanced extortion methods. Rather than relying solely on encrypting a target’s data for ransom, malicious actors are expected to employ double or even triple extortion strategies, encrypting sensitive data but also threatening to leak or sell stolen data unless their ransom demands are met.  

4. Threat actors will continue to rely on living-off-the-land techniques.

With evolving sophistication of security tools and greater industry adoption of AI techniques, threat actors have focused more and more on living-off-the-land. The extremely high volume of vulnerabilities discovered in 2023 highlights threat actors’ persistent need to compromise trusted organizational mechanisms and infrastructure to gain a foothold in networks. Although inbox intrusions remain prevalent, the exploitation of edge infrastructure has demonstrably expanded compared to previously endpoint-focused attacks.

Given the prevalence of endpoint evasion techniques and the high proportion of tactics utilizing native programs, threat actors will likely progressively live off the land, even utilizing new techniques or vulnerabilities to do so, rather than relying on unidentified malicious programs which evade traditional detection.

5. The “as-a-Service” marketplace will contribute to an increase in multi-phase compromises.

With the increasing “as-a-Service” marketplaces, it is likely that organizations will face more multi-phase compromises, where one strain of malware is observed stealing information and that data is sold to additional threat actors or utilized for second and/or third-stage malware or ransomware.  

This trend builds on the concept of initial access brokers but utilizes basic browser scraping and data harvesting to make as much profit throughout the compromise process as possible. This will likely result in security teams observing multiple malicious tools and strains of malware during incident response and/or multi-functional malware, with attack cycles and kill chains morphing into less linear and more abstract chains of activity. This makes it more essential than ever for security teams to apply an anomaly approach to stay ahead of asymmetric threats.  

6. Generative AI will let attackers phish across language barriers.

Classic phishing scams play a numbers game, targeting as many inboxes as possible and hoping that some users take the bait, even if there are spelling and grammar errors in the email. Now, Generative AI has reduced the barrier for entry, so malicious actors do not have to speak English to produce a convincing phishing email.  

In 2024, we anticipate this to extend to other languages and regions. For example, many countries in Asia have not yet been greatly impacted by phishing. Yet Generative AI continues to develop, with improved data input yielding improved output. More phishing emails will start to be generated in various languages with increasing sophistication.    

7. AI regulation and data privacy rules will stifle AI adoption.

AI regulation, like the European Union’s AI Act, is starting to be implemented around the world. As policies continue to come out about AI and data privacy, practical and pragmatic AI adoption becomes more complex.  

Businesses will likely have to take a second look at AI they are adopting into their tech stacks to consider what may happen if a tool is suddenly deprecated because it is no longer fit for purpose or loses the approvals in place. Many will also have to use completely different supply chain evaluations from their usual ones based on developing compliance registrars. This increased complication may make businesses reticent to adopt innovative AI solutions as legislation scrambles to keep up.  

Learn more about observed threat trends and future predictions in the 2023 End of Year Threat Report

Inside the SOC
Darktrace cyber analysts are world-class experts in threat intelligence, threat hunting and incident response, and provide 24/7 SOC support to thousands of Darktrace customers around the globe. Inside the SOC is exclusively authored by these experts, providing analysis of cyber incidents and threat trends, based on real-world experience in the field.
Written by
The Darktrace Threat Research Team

More in this series

No items found.

Blog

/

Email

/

July 24, 2026

Darktrace / EMAIL Expands Behavioral Defense Across Email and Collaboration Workflows

Default blog imageDefault blog image

Email and collaboration tools do more than carry messages. They are where organizations approve payments, share sensitive data, reset credentials, and make thousands of everyday decisions. Increasingly, they are interfaces through which humans direct AI agents in their daily activity. Email, Slack and Teams are high volume, rich with sensitive data, and an easy place to hide malicious activity.

The opportunity isn’t lost on bad actors. Darktrace / EMAIL detected more than 32 million high-confidence phishing emails globally in 2025, and 70% of those messages passed DMARC authentication.  Phishing is increasingly difficult to detect and familiar trust signals alone are not enough. People and security teams need to understand how a message fits the normal behavior of the sender, recipient, and organization. They also need to correlate activity across platforms to spot threats that span multiple channels.

To effectively secure against today’s evolved threats, security teams need to act at two levels: they need to help each employee make a safer decision ‘in the moment’, and they need to understand the wider patterns that may expose the business to risk.

Darktrace is introducing four new capabilities in Darktrace / EMAIL to address both challenges. The new features explain suspicious content more clearly to end users, strengthen the capabilities of Darktrace / Adaptive Human Defense with richer guidance, let organizations define their own patterns for detecting sensitive data in messages, and give security teams a process-level view of risk across email and collaboration workflows.

Darktrace / EMAIL Inbox Analysis highlights risky content within your emails

A warning is more useful when it explains what the user should look at. To help do that, we’ve expanded Darktrace / EMAIL’s Inbox Analysis Add-In to highlight potentially dangerous content within the body of emails that Darktrace / EMAIL flags as potentially suspicious or high risk.  

The add-in can highlight language designed to create urgency, financial references, requests for payment, suspicious links, and content that is unusual for the sender. Each highlighted element includes a pop up that explains why it may be suspicious. Instead of asking an employee to accept a verdict without context, the analysis helps them examine the message and make a more informed decision.

Enhanced Just-In-Time Training Banners in Darktrace / Adaptive Human Defense

Enhanced Just-In-Time Training Banners build on the same principle. The banners now include a contextual header, actionable advice, and specific detection context. This gives employees more useful guidance at the point of risk without adding unnecessary information or cognitive load.

Together, the capabilities help turn a warning into a short learning moment. Employees can see what looks unusual, understand what action to take, and build their judgment.

Custom Sensitive Data Detection in Darktrace / EMAIL - Data Loss Prevention

Sensitive data is different for every business. Standard categories such as payment card details or government identifiers matter, but organizations also have their own customer codes, project names, research formats, account structures, and internal identifiers.

Custom Sensitive Data Detection in Darktrace / EMAIL - Data Loss Prevention allows administrators to write custom expressions for the data their organization needs to protect. Matched content can trigger existing model actions and data loss prevention (DLP) workflows, extending Darktrace's DLP capabilities.

This extends data loss detection beyond a fixed library of common data types. Security teams can apply controls to information that is sensitive in the context of their own organization and adapt those controls as the business changes.

Introducing Email and Collaboration Workflow Risk Posture Dashboards

Some of the most important risks are not isolated events. They are repeated ways of working that create an opening for error, misuse, or attack. For example, a payment request may be one suspicious message, but a recurring approval workflow that relies on weak verification is a business process risk.

The new Email and Collaboration Workflow Risk Posture Dashboard analyzes email and collaboration data across Email, Microsoft Teams, Slack and Zoom to provide a process-level view of risk in the organization. These may include financial authorization workflows, sensitive data sharing patterns, and activity that could expose credentials.

The dashboard brings these patterns into a view and provides actionable recommendations. This helps security teams determine where to investigate or strengthen controls, where ownership needs to be clarified, and where the business may need to change a risky process. It gives CISOs a clearer view of how human and communication risk is embedded in everyday operations, not only where individual alerts occur.

Behavior connects the individual decision to the wider risk

These capabilities build on Darktrace’s unique behavioral approach to security. We use Adaptive AI to learn how people and AI normally behave within an organization, creating the context needed to recognize when activity changes.

Within the Darktrace Behavioral Defense Platform, Darktrace / EMAIL helps protect people against phishing, account takeover, data exfiltration, and human risk across email and collaboration tools. The new capabilities extend that protection in both directions. They give employees clearer context for the decision in front of them, while giving security leaders a broader view of the workflows and behavior that create risk across the organization.

The result is not simply more alerts. It is a better understanding of why something is risky, what action to take, and where the organization can reduce risk before a familiar process becomes an easy route for an attacker.

[related-resource]

Continue reading
About the author
Carlos Gray
Senior Product Marketing Manager, Email

Blog

/

AI

/

July 23, 2026

When AI Agents Go Off Script: What the OpenAI and Hugging Face Incident Means for Defenders

Default blog imageDefault blog image

The recent security incident disclosed jointly by OpenAI and Hugging Face is quickly becoming one of the most discussed AI security stories of the year; it's one that has generated great discussion amongst our researchers and technical teams here at Darktrace.

During an internal evaluation of advanced OpenAI models, an autonomous agent reportedly escaped its intended testing boundaries, obtained internet access, and compromised Hugging Face infrastructure while attempting to evaluate and benchmark the model's cyber capabilities. OpenAI has described it as an unprecedented cyber incident and is collaborating with Hugging Face to investigate and share its findings publicly to help defenders understand the implications and improve AI safety across the community.

What this means for organizations deploying AI agents

The most important takeaway for security leaders is not that the AI model is capable of complex and effective chained attacks. It's what this tells us about the guardrails and protections that need to be put in place to ensure these increasingly capable models are safely used within our businesses.

According to OpenAI's investigation, the models were not acting with malicious intent. They were attempting to achieve a legitimate assigned objective. In pursuing that objective, they identified a path that involved obtaining information from a third party's environment and followed it to completion. From the model's perspective, that appears to have been an effective solution to the problem it was given.

Many organizations still hold the assumption that giving an AI agent a legitimate goal will naturally result in legitimate behavior. Increasingly, that is not something defenders can safely assume.

A human who encounters a "permission denied" message generally understands the technical restriction as well as the social meaning behind it. An agent may interpret that message only as evidence that one method to achieve its objective has failed. What makes this incident notable is the agent’s ability to keep pursuing the objective, revise its plan, and combine many individually useful actions into an outcome its designers did not intend.

This is not an isolated challenge. Recent research from the UK's AI Security Institute found that frontier models often attempt to "cheat" evaluations by finding unintended shortcuts to success. More interestingly, that behavior is not always reflected in chain-of-thought outputs and is not always admitted when models are questioned about their actions. One lesson for defenders is that understanding what an AI system says it is doing is not always the same as understanding its behavior and what it is actually doing.

Why behavioral security is an essential security foundation

That's the principle behind Darktrace / SECURE AI and our broader approach to behavioral security. Understanding intent or putting in place static guardrails is not enough; security teams need visibility into how agents behave over time, what resources they interact with, how their behavior changes, and whether they begin pursuing objectives in unexpected ways. Research released by NIST earlier this summer reinforced that rules alone are not sufficient to defend against AI threats, with one conclusion being that "there will always be a way to prompt an AI system to disregard its rules - it's just a matter of finding it."

Another interesting lesson is that nothing described in OpenAI's preliminary findings appears fundamentally impossible for a skilled human attacker. But it does highlight the accessibility and scale that could be unlocked for attackers as increasingly capable models become more widely available. Resource constraints that attackers deal with will decrease as frontier models can help execute elements of those attack workflows autonomously, persist through failure, and iterate towards an objective. Capabilities that were once limited to skilled attackers can increasingly be supplemented with these systems, lowering the barrier to entry to conduct complex cyber operations.

It is incredibly positive to see OpenAI and Hugging Face investigating this incident collaboratively and sharing their findings publicly. Transparency and collaboration around incidents like these helps the entire security community better understand how rapidly AI capabilities are evolving and where we need to improve safeguards. It also reinforces why Darktrace is excited to be partnering with OpenAI through the Daybreak Cyber Partner Program: to explore how advanced AI can be used safely and responsibly in support of defenders while developing the visibility, governance, and security controls needed for increasingly autonomous systems.

This incident is an important reminder that capable AI systems will not always behave in the ways we expect. As organizations deploy AI agents across critical workflows, understanding behavior is an even more important foundation for effective security.

[related-resource]

Continue reading
About the author
あなたのデータ × DarktraceのAI
唯一無二のDarktrace AIで、ネットワークセキュリティを次の次元へ