New research from the SentinelLABS and Wayfinder teams illustrates how attackers exploit the misalignment between security and operations
SentinelOne (NYSE: S), a global leader in AI-powered cybersecurity, released its Annual Threat Report, highlighting a critical shift in the cyber threat landscape: Malicious actors are no longer simply gaining initial access, but are aiming to exploit the identity systems, infrastructure and automation mechanisms that power businesses.
In an age of industrialized attacks, security teams are inundated with massive amounts of telemetry data, and often lack the context to distinguish a real intrusion from a simple anomaly. While organizations today have access to an unprecedented amount of threat intelligence, the real challenge is translating this knowledge into concrete, contextualized actions for managing their local environments.
Designed to help companies ensure operational continuity in the face of large-scale attacks, the report offers a true "Defender's Playbook", which connects global threat intelligence to practical evidence based on observed behaviors. By analyzing the eight strategic phases of modern breaches, the document helps security teams move from a reactive approach to a proactive and resilient, context-based posture.
The main findings of the SentinelLABS Annual Threat Report:
- Defuse the paradox of identities
Identities today span across SaaS, cloud infrastructures, and autonomous agents. A single account can access dozens of systems. Organizations are collecting more identity data than ever, but identity-based intrusions remain among the most difficult to detect. Attackers leverage stolen tokens, phishing, and compromised accounts to operate with valid credentials. Defenders must, therefore, shift their focus from authentication alone to continuously monitoring post-login behavior. - Attacks along the development pipeline
Attackers are increasingly targeting CI/CD pipelines and development pipelines rather than production environments. By compromising build systems, they can introduce malicious code and extract secrets before the software is deployed, thus operating inside trusted processes and bypassing runtime defenses. Tracking requires visibility into the entire software development lifecycle and the ability to correlate events over time. - Protecting an increasingly blurred perimeter
Edge devices have become primary attack surfaces: nearly 46% of recent zero-day exploits target them. They often represent unmanaged blind spots and are the first step to broader compromises. It is necessary to go back to the basics: retire obsolete hardware, centralize logs in a SIEM, implement network segmentation for critical levels and adopt multi-factor authentication on all remote access points, treating the edge as a high-risk area.
- Countering the automation multiplier
The real "multiplier" is not only agentic AI, but also advanced automation, which represents the operational backbone for transforming analyzes into defensive actions. After years of attempts, these technologies are overtaking the techniques of attackers, who use automated workflows to accelerate tasks such as vulnerability scans, credential harvesting, and lateral movement, often within milliseconds. Defense requires automated response policies that prioritize blocking high-confidence threats, rather than simply generating alerts.
“The threat environment is constantly evolving, but the fundamentals remain,” said Steve Stone, Chief Customer Officer. "Attackers rely less and less on individual exploits or clusters of malware and more on gaps between security and operations, blind spots in trusted systems, and defenders' slowness to adopt the same technology multipliers. Closing the gap isn't about chasing every new technique, it's about constantly testing whether controls can withstand the pressures of modern attacks."






