A new ranking shows which cyber threats deserve your time first

Huntress has released its Tragic Quadrant, a ranking of cyber tactics based on how common they are and how close they sit to real business damage

Yajush Gupta
Yajush Gupta
News · 4 Oct 2026 · 2 min read
Above A new ranking shows which cyber threats deserve your time first. Dynamic Business

Huntress, a cybersecurity firm, recently shared its list of the most problematic cyber tactics affecting businesses - and surprisingly, most of them aren't related to AI.

The Tragic Quadrant scores each tactic on two things: how often Huntress sees it, and how close it puts a business to serious damage. The company says the data covers more than 5 million endpoints and 15 million identities across nearly 300,000 organisations it protects. It also draws on 2026 detections, its 2026 Cyber Threat Report and incidents handled by its security operations team.

The tactics in the top-right corner, the ones that are both common and dangerous, share one trait. They lean on tools and habits businesses already trust.

Tools you already trust

Remote monitoring and management (RMM) software lets IT teams manage computers from anywhere. Attackers like it for the same reason. Huntress says 45% of the endpoint incidents it investigated in the first quarter of 2026 involved RMM abuse, making it the most common threat category it sees on endpoints. One rogue install can give an attacker lasting access that looks like normal admin work.

Huntress also says attackers are using AI to build convincing fake document shares and service agreements that trick staff into installing these tools.

The inbox problem

Mailbox manipulation made up 24.6% of the identity threat signals Huntress saw so far in 2026. Once someone is inside a mailbox, they can quietly change inbox rules. Replies from suppliers can end up in folders nobody checks, and invoice details can be altered. That is how many business email compromise scams get paid out.

Logins that skip MFA

Huntress also flags adversary-in-the-middle attacks, which made up 18.9% of identity-based threats it tracked in 2025. The attacker sits between the user and a real Microsoft 365 login page and steals the session token as it passes through. While that session stays valid, they can get into the account without a password or a fresh MFA prompt.

Huntress also said roughly 70% of the active intrusions its security team caught started with attackers logging in through VPN access.

Newer threats to watch

Some tactics sit in other corners of the quadrant. ClickFix uses a fake CAPTCHA to get someone to paste a command into their own computer. It makes up about 2.2% of Huntress's managed endpoint detection signals, but nearly 99% of those are high severity. Device code phishing and abuse of AI platforms are rarer for now, though Huntress says they are evolving fast. It lists AI platform abuse and deepfakes among the threats it considers overhyped, for now.

Jai Minton, Senior Manager, Detection Engineering and Threat Hunting at Huntress, says AI has not changed the picture as much as the headlines suggest.

"AI is making some attacks faster and more convincing, but it hasn't fundamentally changed the techniques that attackers use," he said.

Minton said the ranking is meant to help local businesses sort real risk from noise. "The Huntress Tragic Quadrant gives ANZ businesses a way to separate hype from reality," he said.

For owners who aren't sure where to start, Huntress suggests asking a few plain questions. Which tools are approved on our systems? How do we monitor mailbox rules? How would we spot strange session behaviour early?

Minton put the broader aim this way: "We hope it helps businesses spend less time chasing the threat of the week and more time asking which trusted tools, identities and access paths would let an attacker move through their organisation today, so that they can close those gaps before they're exploited."

YG
Yajush Gupta
From the floor
Closer to this story than we are?
If you're building in this space — or watching it reshape your market — pitch us. We edit it; you get the byline.
More from the desk

Keep reading.

News ◆

A liquidator's warning for businesses eyeing AI to cut costs

Redundancies, software costs and lost clients can arrive before any AI savings do.

Yajush Gupta · 2 min
News ◆

The ATO is dropping credit cards. Does your tax bill change?

The ATO says most taxpayers don't use credit cards, but business groups say small business will feel it.

Yajush Gupta · 2 min
News ◆

What Google and OpenAI say about getting your business mentioned by AI

Does a bigger budget get you recommended by AI? Here's what Google and OpenAI tell site owners about appearing in AI answers.

Yajush Gupta · 2 min
0 people like this

Comments

Loading comments…