Analysis · August 15, 2026

What the 2026 threat data says about the defense industrial base.

Huntress analysed hacker activity across more than 4.6 million endpoints and 9.4 million identities during 2025. Three of its findings land squarely on small defense suppliers, and all three describe attacks that look like normal administrative work.

On sourcing. Every figure below is from the Huntress 2026 Cyber Threat Report and is Huntress’s measurement, not ours. Cyberneza is an authorized Huntress reseller. We have added the interpretation for defense contractors; the data is theirs.

Finding one

Attacks on manufacturing rose 88%.

That is the largest sector movement in the report, and manufacturing is where a great deal of the defense industrial base actually sits — machine shops, fabricators, engineering firms and component suppliers holding CUI under a DFARS flow-down.

It is worth being precise about what this does and does not show. It is a rise in observed attacks against a sector, not a statement that defense suppliers specifically were targeted, and Huntress’s visibility is into its own customer base rather than the whole economy. What it does establish is direction: the population of organizations that look like a mid-sized supplier saw substantially more hostile activity in 2025 than in 2024.

The operational read is that a small manufacturer can no longer treat itself as too small to be interesting. The attacks in this report are not targeted campaigns against named victims; they are a standardised playbook run at scale against whoever is reachable.

Finding two

Abuse of remote monitoring and management tooling rose 277%.

This is the finding that should worry a small supplier most, because RMM software is how nearly every organization under a few hundred people receives IT support. Attackers are not exploiting a vulnerability in it. They are using it the way an administrator would.

Huntress’s own framing is worth quoting: adversaries are “increasingly aligning their operations with legitimate administrative behavior… blurring the lines between malicious activity and authorized activity.”

A control that checks whether approved software is installed will not catch this, because the software is approved. Detecting it means noticing that an approved tool did something unusual — at an unusual hour, from an unusual place, against an unusual set of hosts. That is a behavioural judgement made over time, which is a different capability from an inventory.

Finding three

Adversary-in-the-middle accounted for 18.9% of identity threats.

AiTM phishing does not break multi-factor authentication. It waits for the user to complete it and steals the resulting session, which means the attacker inherits an authenticated session without ever holding the second factor.

This matters for anyone whose 800-171 programme treats IA.L2-3.5.3 as closed because MFA is enforced. MFA remains necessary and it remains the right control. It is simply not, on its own, sufficient against this technique — and the practice is scored as implemented either way, which is exactly how a control can be genuinely in place and still leave the risk open.

Related figures from the same report: over 35% of identity threats came from suspicious logins — risky locations, malicious networks, anonymising VPNs — and 19% from mailbox manipulation and persistence, which Huntress describes as a signature of business email compromise.

The common thread

All three are detected by behaviour, not by configuration.

RMM abuse, AiTM session theft and mailbox persistence share a property: at the moment they occur they are indistinguishable from authorized activity. No configuration setting blocks them, because there is nothing malformed to block. They are identified by someone or something observing that authorized-looking activity does not fit the pattern.

That is the practical reason several NIST SP 800-171 families — audit and accountability, system and information integrity, incident response — describe continuous activity rather than a state. They are written the way they are because the threats they address only become visible over time.

It is also why a self-assessment can be honestly completed and still overstate. A supplier can have monitoring tooling deployed, logging enabled and an incident response plan written, and have none of it reviewed by anyone between one assessment and the next. The controls exist. The activity the controls describe does not happen.

What to do about it

Three checks worth running this month.

Find out who can reach your RMM

List every remote access and management tool in the environment, who can authenticate to each, and whether anyone would notice an out-of-hours session. Include tools belonging to your IT provider, which are frequently outside your own inventory.

Test whether anyone reads the logs

Pick a security-relevant event from last month and trace who reviewed it and when. If the answer is nobody, your audit and accountability practices are documented rather than operating, and that is a finding waiting to happen.

Look past MFA on identity

Check whether you would detect a successful sign-in from an anomalous location on a valid session, a new mailbox forwarding rule, or a newly consented OAuth application. These are the AiTM and BEC indicators, and none of them trip an MFA control.

Want to know which of your practices are documented but not running?

We scope the CUI boundary, assess the current state, and are explicit about which requirements need something operating continuously rather than written down.

Figures throughout are from the Huntress 2026 Cyber Threat Report and are Huntress’s measurements. Cyberneza is an authorized Huntress reseller.