Crystal Ball Series

Published On : 2026-09-24
Share :
Crystal Ball Series

Crystal Ball Series

Q3 2026 CHECK-IN • THE ROAD TO DECEMBER

Attackers will overwhelmingly avoid presistence

PREDICTION TRACKING: VALIDATED — ON TRACK
EХРЕСТED TO CLOSE: VALIDATED — ON TRACK

Then, now and next

WHAT WE SAID (JAN 2026)

  • 90 – 95%  of instructions avoid persistence entirely
  • Attacks become session – based, ephemeral and transactional
  • AI Accelerates attacks from days to hours

WHAT MID-YEAR SHOWED (JUN 2026)

  • 82% of detections are malware—free  a new record high
  • eCrime breakout time down to 29 minutes
  • Attackers log in with valid credentials, not malware

WHAT TO EXPECT BY DECEMBER

  • Breakout keeps compressing sub-20-minute averages in the next threat-hunting data would settle the “hours, not days” call
  • Malware-free shore breaks 85%  on its way to the 90-95% we forecast
  • Persistence becomes the exception H2 incidents showing pure credential and session abuse with no implant at all

Mid-year evidence

  • 82% of 2025 detections were malware – free – a record high
  • 29 min average eCrime breakout time -65% faster than 2024
  • 27 sec fastest observed breakout time  in 2025
  • 67% of incidents start with identity compromise, not malware

“Log in, not break in” is now me norm: identity-driven, malware – free intrusions that detonate in minutes

OUR H2 OUTLOOK

Containment speed now matters more than forensic depth. We expect December to confirm persistence-free, identity-led intrusions as the majority pattern, with breakout time still falling.

DECEMBER CONFIDENCE

Tracking the numbers – January forecast mid- year evidence latest published data

NEXT: END-OF-YEAR VERDICT – DECEMBER 2026

Final verdicts on all 10 predictions, plus the first look at the Crystal Ball Series 2027.

MID-YEAR 2026 UPDATE

Attackers will overwhelmingly avoid presistence

PREDICTION TRACKING : VALIDATED — RUNNING AHEAD OF FORECAST

What we said vs. what 2026 is showing

WE PREDICTED (Jan 2026)

90-95% of intrusions will avoid persistence entirely Attacks become session-based & ephemeral Al accelerates attacks to minutes/hours

WHAT’S HAPPENING NOW
82% of detections are malware-free – a new record high eCrime breakout time down to 29 minutes Attackers log in with valid credentials

Mid-year evidence

  • 82% of 2025 detections were malware-free, up from 79%
  • 29 min average eCrime breakout time 65% faster than 2024
  • 27 Sec fastest observed breakout time in 2025
  • 67% of incidents start with identity compromise, not malware

OUR UPDATED POSITION
Strongly on track. Persistence-free, identity-driven “log-in not break-in” intrusions are now the norm and detonate in minutes, not days. Defenders must pivot from malware hunting to identity and session telemetry and assume attackers are already inside using legitimate tools. Speed of containment now matters more than depth of forensic analysis.

In this Instalment we Explore

Attackers will overwhelmingly avoid presistence

Analyzing past behaviour helps us assess Predictive Threat Intelligence


Preemptive External Threat Landscape Management