Skip to content
← all posts
Security

Auditing My 2026 Security Predictions: Five Months In

idk about you, but this feels like a LOOOOOONG time ago right now...

Back in December I made eight predictions for what 2026 would bring in security. We're four months in, so it's time to grade my own work.

Holding yourself accountable to what you said publicly is one of the few honest things you can do in this industry. Most predictions get fired off, then quietly forgotten when reality goes sideways. So here we go — by my count, eight directionally right, two with caveats, zero outright misses. But two of them came in sharper than I expected, and two need a footnote I should have written in the first place.

1. PLA Centenary Escalation → Correct

I called increased Chinese cyber activity ahead of the August 2027 PLA centenary — more skirmishes, prepositioning, and reconnaissance.

What's actually happened: Salt Typhoon hit Sistemi Informativi (the IBM Italy subsidiary handling Italian critical IT infrastructure) in late April. TechCrunch's March 9 piece walked through Salt Typhoon hits across global telecoms. Volt Typhoon's prepositioning posture remains active per CISA.

The interesting variable is geography. The earlier waves were US-centric. 2026 is showing the European pivot — that's the part I underweighted in December.

2. Shift-Left Success in Modern Code → Partial

I called GenAI letting security succeed in CI/CD-native, cloud-native shops.

The tooling momentum is real. GitHub Copilot is shipping security suggestions, JFrog launched agentic remediation, GitGuardian published an MCP for AI-generated code. The whole industry has shifted vocabulary to "shift smart" or "AI-DevSecOps."

Here's what I missed: Cisco's State of AI Security 2026 report flags that 83% of organizations plan to deploy agentic AI capabilities, and only 29% feel ready to do so securely. The shift-left side is getting more capable, but agentic AI is opening a brand new attack surface faster than defenders can close it.

The right call would have been "shift-left wins for human-written code, but agentic AI creates a new front." I'll mostly take that on the chin, in reality it was already well underway when I wrote this but has finally made it's way out into the Zeitgeist.

3. Legacy Infrastructure Stays Vulnerable → Correct

This one was easy to call — and reality validated it harder than I expected.

Ransomware against industrial and enterprise targets surged 49% YoY in 2025. Twenty-nine percent of known-exploited vulns were weaponized on or before the day their CVE was published — meaning patch windows have effectively closed. The Interlock ransomware crew burned a Cisco FMC zero-day (CVE-2026-20131) starting January 26, 2026. Average end-of-life software image accumulates ~218 new vulnerabilities every six months after support ends.

If you're running aged infra and unpatched systems, the math is no longer on your side.

4. Two Internet Attack Surfaces Diverge → Partial

I called nation-states focusing on legacy and cybercriminals focusing on new platforms.

The pattern is showing — Salt Typhoon → telcos and legacy IT, Vibeware/MalTerminal/PromptLock targeting new SaaS and AI platforms. But the lines are blurrier than I implied. Interlock (criminal) is hitting Cisco FMC (legacy enterprise). Volt Typhoon (state) is hunting modern OT.

The clean two-surface story I told reads more like a probability distribution in practice. Right intuition, neater story than reality.

5. Democratized AI-Enabled Malware → Strongly Correct

This was the "spicy software" line and it aged well.

Arctic Wolf's labs counted 22,000+ distinct AI-generated malware files in a rolling Feb-2025-to-Feb-2026 window. The industry coined a term: vibeware. The Cloud Security Alliance published a technical Vibeware threat model in March. WormGPT and friends — LLMs trained to refuse no request — were available for €60/month.

There's an honest contrarian view (Oliver Rochford on Medium) that LLM-embedded malware is mostly marketing — that the actual operational lift is fragility and detectability, not effectiveness. Fair point. But proliferation is what I called, and proliferation is what we got. (Caveat I'm leaving on the table: if the original December call read as "AI-enabled malware will be a problem" rather than "AI-enabled malware files will exist", the honest grade is Partial, not Strongly Correct. I'll resolve that in the addendum.)

6. Security Research Crowdsourcing Expansion → Correct

Bug bounty market is $2.06B in 2026, projected to $7.74B by 2035 at a 15.94% CAGR. Intigriti is at 150K+ vetted researchers and the fastest-growing platform in the space. Nvidia launching a major program on Intigriti in 2025 was the enterprise validation signal.

The labor supply side held up too. Q1 2026 tech layoffs hit 78,557, with ~48% AI-attributed. Some non-trivial fraction of those folks are showing up on bounty platforms.

I'll declare a conflict of interest here: this is the call where my priors are deepest. Twelve years building Bugcrowd will do that. Take the conviction with a grain of salt; take the data without one.

7. Economic Pressure → Cybercrime → Correct (structurally)

Cybercrime is projected to cost $10.5T globally in 2026. Losses up 34.96% YoY (2023 → 2024). Tech layoffs at 113,863 YTD in 2026 (about 911 per day). Low-friction entry tools at €60/month.

Direct causation in four months is hard to prove. But every structural condition I named is in place, and every measurable indicator is up-and-to-the-right.

8. Defense Triage Crisis → Strongly Correct

This is the one I'm most surprised by — not because it happened, but because it happened exactly the way I described.

I wrote about a "triage trash fire in 2026 across all blue-team disciplines — vulnerability management and beyond."

On April 15, 2026, NIST formally announced it can no longer enrich most CVEs in the National Vulnerability Database. A 263% submission surge — driven explicitly by AI-fueled vulnerability reports — overwhelmed the pipeline. Roughly 29,000 backlogged CVEs got reclassified "Not Scheduled," meaning no enrichment in the foreseeable future. Going forward, only ~15–20% of CVE volume gets full enrichment (CISA KEV, federal software, EO 14028 critical software). The rest ship without CPE / CVSS / CWE.

The headline that ran in industry press: "NIST Stops Scoring Most CVEs — The NVD Is Now a Triage Queue."

I called it a triage trash fire. Reality called it a triage queue. Same thing.

Still watching on these calls

Two of the calls above have unfinished arcs, and they belong with the graded section — not as new predictions, just as signals I'm tracking:

  • Two-surface divergence (#4) is partial. Does the criminal ↔ nation-state cleavage sharpen as elections, conflicts, and PLA centenary pressure compound, or stay blurred?
  • Economic pressure → cybercrime (#7) is structurally validated, but the participation lift is hard to measure. By Q4 we should have numbers that either validate or deflate the call.

My biggest underweighting in December: how fast the AI-generated CVE flood would crush NIST. I called the symptom. I missed the speed.


Updated Predictions for the Rest of 2026

The first half of the year produced one development big enough to deserve its own section: the labs are now openly racing on cyber-AI, and they're publicly disagreeing on the terms. That changes what the back half of 2026 looks like. Here are the calls I want on the record now — separate from the December eight, dated May 15.

The Mythos/Daybreak split is the 2026 cyber-AI story

This is the one I'd retroactively bolt onto prediction #5 if I could. The malware-proliferation call was right; what I underweighted was how fast the frontier-lab side would split on the access question.

Anthropic's Mythos. Existence outed by an accidental CMS leak on March 26. Formalized in April under Project Glasswing. Limited preview — about a dozen launch partners (AWS, Apple, Microsoft, Google, JPMorgan, Palo Alto Networks, others) plus ~40 critical-infrastructure orgs, $100M in usage credits, no general availability. The numbers behind the decision: 83.1% on the CyberGym vulnerability-reproduction benchmark versus Claude Opus 4.6 at 66.6%. Found thousands of high-severity bugs across major OSes and browsers, including a 27-year-old OpenBSD flaw and a 16-year-old FFmpeg bug that five million automated tests had missed. Helped Mozilla close 270+ Firefox vulnerabilities. First time in roughly seven years a frontier lab has publicly held a model back over cyber-misuse risk.

OpenAI's Daybreak. Announced May 12, powered by GPT-5.5 plus a specialist GPT-5.5-Cyber tier. End-to-end automation — threat modeling, vuln triage, audit-ready patch generation. Pitched explicitly as the answer to Mythos. The access model is inverted: any organization can request access via contact form; higher tiers are verification-gated. Launch partners are the security industry itself — Cisco, Oracle, CrowdStrike, Palo Alto Networks, Cloudflare, Fortinet, Akamai, Zscaler. Altman's framing: "AI is already good and about to get super good at cybersecurity."

So one lab says this is too dangerous to ship, and six weeks later the other lab ships the same kind of capability to anyone with an email address. EU regulators are already pushing on Anthropic over the European access asymmetry.

The call: lab-level access governance — who gets cyber-grade AI and on what terms — becomes the dominant 2026 cyber-AI policy fight. Bigger than another vibeware count, bigger than the next AI-DevSecOps acquisition. By year-end the question "do you have a Glasswing-style access policy or a Daybreak-style one" will be a serious procurement question.

Agentic AI is the dominant attack-surface story by Q4

Already partway justified in prediction #2 above, but I'm putting a stake in the ground: by end of Q4, the agentic-AI side of the shift-left/agentic-AI split will be where the actual incidents are, where the budget is moving, and where the headlines live. The Cisco 83/29 gap is the leading indicator. Mythos and Daybreak are accelerants — both raise the ceiling on what AI agents can do, and both create new attack surfaces of their own (model abuse, prompt-level vulnerabilities, supply-chain compromise of cyber-AI tooling).

If you're a buyer, the question shifts from "is my CI/CD AI-secure" to "what is my exposure when my employees, my suppliers, and my attackers all have agents running."

Falsifiable test I'm committing to: by Q4, agentic AI is named the primary or co-primary vector in at least two of {Verizon DBIR, Mandiant M-Trends, CrowdStrike Threat Report}, OR ≥15% of Q4 public breach disclosures cite agent compromise as a contributing factor. Miss both and this prediction is wrong, full stop.

CVE enrichment splits, and CISA KEV becomes the canonical list

Prediction #8 graded correct on the triage crisis. The follow-on call: by year-end, NIST's retreat creates a market for distributed CVE enrichment. CISA KEV is already the highest-signal list — under-the-hood it's becoming the spec that vulnerability management tools build around. Expect at least one vendor (probably more than one) to launch a "what NIST stopped doing" service. Expect the conversation about CVE numbering authority itself to get noisier.

A serious Mythos-or-Daybreak-attributable incident before year-end

The lower-confidence call, written down so I have to grade it. Either a Glasswing partner gets caught misusing access, a Daybreak access-controlled tier gets phished or social-engineered open, or a downstream attacker uses one of these systems' outputs in a way that produces a public attribution chain. The dual-use math doesn't allow for clean records once the capability is in the field at scale. Watching this with low confidence and full expectation that the specifics will surprise me.

Falsifiability constraint (working version): "serious" means publicly disclosed by the vendor, the partner org, or a credible journalist, with named attribution to Mythos or Daybreak. Generic "an AI was used" coverage does not count. I'll tighten this further before I score it.


Eight months left. We'll see.

Casey Ellis
Casey Ellis
Hacker, founder, advisor, and pioneer of crowdsourced security. Founder of Bugcrowd, co-founder of disclose.io, principal of Tall Poppy Group. Board member at SRLDF.
bio →

Comments ·

members only