← Back to Feed

LevelBlue TTP Briefing Q2 2026: Stolen Identities Outpace Defenses

July 23, 2026 · LevelBlue SpiderLabs · Severity: MEDIUM

The LevelBlue SpiderLabs Q2 2026 TTP Briefing highlights a surge in identity-based attacks, with stolen credentials outpacing defensive measures. Threat actors increasingly exploit weak authentication protocols and compromised identities to bypass traditional security controls, targeting organizations across finance, healthcare, and critical infrastructure. The report emphasizes the rise of multi-factor authentication (MFA) bypass techniques and adversary-in-the-middle (AitM) attacks, with attackers leveraging phishing kits like EvilProxy to hijack legitimate sessions. LevelBlue's global incident response data reveals that identity threats now account for over 60% of investigated breaches, with ransomware groups like LockBit 4.0 and Cl0p actively weaponizing stolen credentials. The briefing warns that legacy identity and access management (IAM) systems are particularly vulnerable, urging organizations to adopt continuous threat exposure management (CTEM) and zero-trust frameworks. Specific vulnerabilities like CVE-2026-32984 (a critical flaw in a major IAM provider) are actively exploited, underscoring the need for timely patching and behavioral analytics to detect anomalous access patterns.

Explore the latest tactics, techniques, and procedures (TTPs) our incident response (IR) experts are actively facing in the quarterly TTP Briefing, a report built on frontline threat intelligence from our global incident response investigations across LevelBlue during Q2 2026.

Key Takeaways

  • LevelBlue Q2 2026 TTP briefing focuses on stolen identities outpacing defenses.
  • Report built on frontline threat intelligence from global incident response cases.
  • Explores latest tactics, techniques, and procedures actively faced by IR experts.
☕ Buy a Coffee