The first half of 2026 saw a sharp rise in supply-chain attacks, marking the most disruptive trend in Wiz's latest threat report. The TeamPCP group exploited trusted developer packages by injecting malicious code, leading to widespread credential theft across multiple organizations. This method capitalizes on the built-in trust in software dependencies, a blind spot for many existing security systems. The more-than-doubling of such attacks in H1 2026 reveals a fundamental shift in how attackers use software supply chains to exploit common tools and components for large-scale infiltration.
Once a malicious package enters a software development pipeline, its impact quickly spreads. The poisoned software doesn't just affect the initial target but can infect all systems that rely on it, increasing the damage significantly. Despite 70% of organizations implementing key security tools by the end of 2025, these defenses proved ineffective against the attacks. This highlights the need to go beyond basic measures and adopt more thorough strategies. The fact that even widely deployed solutions failed to stop the breaches suggests the issue lies in the lack of comprehensive and real-time monitoring of software dependencies.
Mitigation Strategies
Wiz recommends cooldown policies for package downloads as a starting point for defense. However, these are just initial steps and not sufficient to fully mitigate the risks. The report stresses the importance of continuous audits of dependencies and runtime behavioral monitoring to detect threats more efficiently. This strategic shift is crucial for preventing future breaches and protecting software pipelines from being exploited. Incorporating proactive methods like runtime analysis and anomaly detection becomes essential to identify suspicious behavior before it spreads across interconnected systems.
The report also identifies AI infrastructure as a particularly vulnerable and underprotected area. As companies rapidly deploy AI tools, model endpoints, and inference workloads into cloud environments, the necessary security infrastructure has lagged behind. Cybercriminals are quick to notice and exploit this gap. For example, the financially motivated JINX-0163 group targets cloud service accounts to conduct extortion campaigns. These actors recognize that AI workloads often operate with elevated access to sensitive data and external services, making such accounts especially valuable to attackers.
AI Infrastructure Vulnerabilities
AI workloads are frequently set up with broader permissions to access data stores, APIs, and other services. This means a breach in a cloud service account linked to an AI pipeline can be extremely damaging. The report also points to Cloud Security Posture Management (CSPM) as a growing and contested area in enterprise cybersecurity. Vendors that offer visibility into AI-related cloud configurations are well-positioned to meet the rising demand for enhanced protection. Organizations that neglect to secure their AI infrastructure risk exposing valuable data and allowing attackers to disrupt essential AI operations.
The cybersecurity market is expected to grow significantly, projected to reach $242.4 billion in value by 2026, with an 11.6% compound annual growth rate through 2029. This growth is fueled by an increase in sophisticated threats and the need for advanced security solutions. For enterprise decision-makers, Wiz's threat intelligence offers both a clear warning and a strategic guide. The company's proactive defense recommendations align with its capabilities, and by embedding threat intelligence into its detection platform, Wiz enables a more integrated and effective response to modern cloud threats.
With threats evolving rapidly, proactive cloud defense is no longer just a best practice—it is essential for maintaining competitive advantage. Organizations that fail to modernize their security measures risk substantial financial and reputational harm as cybercriminals increasingly focus on cloud-native and AI infrastructure. Wiz's Cyber Incident Response Team has shown that the most resilient organizations treat cloud security as an ongoing operational priority rather than a one-time compliance task.

