
2026 Threat Landscape Reality Check: Turning Threat Intelligence Into Analytic Advantage
The SANS "Threat Analysis Rundown" live stream highlighted a pivotal shift in 2026: identity‑based intrusions have become the primary attack vector, eclipsing traditional malware. Host Sean O'Connor, joined by veterans Rebecca Brown and John Doyle, referenced recent reports—CrowdStrike, Unit 42, Microsoft—showing 80‑90% of detections now involve credential misuse. Key insights included the rise of credential theft and information‑stealing as defenders harden perimeter defenses, pushing adversaries toward legitimate logins. The panel stressed that AI can streamline data collection but cannot substitute human judgment, warning against over‑reliance on automated summaries. Community evolution was also noted, with the STAR series moving from scripted webcasts to authentic, unscripted live discussions. Notable moments featured Katie Nichols reflecting on past over‑complication of threat intel and John Doyle emphasizing how defensive actions unintentionally create new attack surfaces. Rebecca highlighted the pandemic‑driven remote‑work boom as a catalyst for identity exploitation, while participants underscored the growing overlap of geopolitical conflict and cyber operations. Implications are clear: CTI teams must prioritize credential‑focused detection, integrate AI as an assistive tool, and maintain skilled analysts to interpret nuanced threats. Organizations that adapt to the “identity is the new perimeter” paradigm will better safeguard assets amid an increasingly politicized cyber landscape.

Stay Ahead of Ransomware Livestream: May 2026
The May 2026 SANS Stay Ahead of Ransomware livestream, hosted by Ryan Chapman and Mary Degrazia, dissected the latest ransomware and cyber‑extortion trends using the Mandian M‑Trends 2026 report, which analyzes over 500,000 incident hours from 2025. Key findings show ransomware...

Stay Ahead of Ransomware - Initial Access via Evolving Social Engineering
The April 2026 SANS "Stay Ahead of Ransomware" livestream focused on evolving social‑engineering techniques that grant attackers initial access. Hosts Ryan Chapman and Mary Degrazia examined two prominent vectors: the ClickFix scheme, which lures users to a fake capture page that...

From Gut to Gold Standard: The Admiralty System in CTI
The presentation introduces the Admiralty Scale, a century‑old British Navy framework, as a rigorous method for evaluating source credibility and information reliability in cyber threat intelligence (CTI). Freddy argues that modern CTI suffers from opaque reporting, unverified claims, and bias,...

Hunting North Korea’s Contagious Interview Operation
The presentation by senior threat analyst Kir Boyenko details North Korea’s state‑sponsored “contagious interview” campaign, which masquerades as recruiter outreach, test assignments, or take‑home exams to trick developers into executing malicious code. By targeting open‑source ecosystems—primarily npm, but also Python,...

Can We Forecast CTI’s Future? Mapping with SATs
The presentation uses a World‑War‑era forecasting analogy to argue that cyber‑threat‑intelligence (CTI) practitioners can—and should—apply structured analytic techniques (SATs) to anticipate industry shifts. By reviewing how British officials forecast aerial bombings and then evacuated 1.5 million civilians, the speaker illustrates how...