Intelligent CISO Issue 101 | Page 9

ESET report highlights AI-driven threats and growth in QR code phishing
Sophos AI Security 2026 report finds attackers are operationalising AI for attacks

CISO news

ESET report highlights AI-driven threats and growth in QR code phishing

SET Research has released its H1 2026 Threat Report, outlining threat landscape trends observed between

E

December 2025 and May 2026. The report found attackers are continuing to adapt established techniques to new platforms and technologies, while Artificial Intelligence is playing an increasing role in cyberattacks.
ESET analysed nearly 900,000 AI skills and identified tens of thousands of suspicious instances, including thousands classified as malicious. The company also identified PromptSpy, which it describes as the first known Android malware to use Generative AI as part of its execution process.
“ Rather than relying on entirely new methods and tools, attackers are quickly adapting established techniques to new platforms, technologies and user behaviours. The number of AI skills within this new ecosystem is growing rapidly as we speak, further expanding the attack surface,” said ESET Director of Threat Prevention Labs, Jiří Kropáč.
QR code phishing or quishing, also increased during the reporting period. Approximately 11 % of phishing emails detected by ESET in H1 2026 contained QR codes, with the highest levels recorded in the US, Spain and Mexico.
The report also found that ClickFix attacks have expanded beyond fake CAPTCHA prompts into AI-themed websites, browser extensions and cloud authentication scenarios. ESET said detections of ConsentFix attacks more than doubled between H2 2025 and H1 2026.
The report also found ransomware activity continued to increase during H1 2026, while the proportion of victims paying ransoms fell. ESET said it has documented more than 100 different endpoint detection and response( EDR) killers used in attacks.

Sophos AI Security 2026 report finds attackers are operationalising AI for attacks

S ophos has released its AI Security 2026 Report, finding that attackers are operationalising AI to collapse attack workflows from weeks to days.

The report finds that AI’ s most immediate impact on cybercrime is speed, as well as a rise in attacks using identity as the primary initial access vector( IAV), rather than inventing new attack types at this stage.
Key findings from the Sophos 2026 AI Security Report include:
• AI is compressing attack timelines and accelerating operational readiness.
• Enterprise AI identities, OAuth tokens, agents, APIs, and development tools are becoming high-value targets.
• AI-assisted social engineering and deepfakes are now operational tools.
• Threat actors are incorporating AI into underground markets, recruitment, prompt engineering, jailbreaking, malware development workflows and criminal services.
• AI development infrastructure and supply chains are being targeted.
“ Attackers still need initial access, still move laterally and still exfiltrate through observable channels. What has changed is the clock,” said John Peterson, Chief Technology Officer, Sophos.“ For the first time we have observed AI being actively used as an operational force multiplier. While the tools and techniques were familiar, the speed of development, testing and iteration was materially different. That is the AI threat that security teams need to prepare against. It means faster cycles and shorter windows to respond, with greater pressure on defenders to detect and contain activity before impact.”
WWW. INTELLIGENTCISO. COM 9