Threat Brief — 2026-08-08 — Identity is the New Perimeter
Executive summary. Unit 42 published a deep-dive on identity-based attacks as the dominant SOC challenge, attributing roughly 90% of incidents to identity compromise. The piece frames identity as the modern "front door" for attackers and offers operational guidance for SOC leaders. This reinforces a pattern visible across this week's intelligence: M365 AitM phishing, Windows Hello for Business key abuse, and Entra ID persistence all point to identity as the primary battleground.
Top items
- Unit 42: Identity-based attacks drive 90% of SOC incidents. New article from Palo Alto's Unit 42 details how modern attackers exploit credentials, tokens, and identity-provider trust to compromise organisations. The report provides SOC-centric guidance on detection and response priorities for identity threats. Relevant to ongoing identity-attack trends including the M365 AitM phishing campaign and Windows Hello for Business key-abuse techniques reported earlier this week. (src: Unit 42)
Themes
Identity as the primary attack surface. This week's intelligence has consistently shown identity-layer compromise as the critical path: active M365 AitM phishing targeting payroll and finance, malware abusing Windows Hello for Business keys for Entra ID persistence, and now Unit 42 quantifying identity-based attacks at 90% of incidents. Defenders should prioritise identity threat detection, conditional-access hardening, and token/credential monitoring over traditional network-perimeter controls.
