The report prepared by Fortinet’s FortiCNAPP intelligence analyzes how cybercriminals are increasingly using the cloud to carry out their attacks and perpetrate intrusions; the entry routes they use and how they have been industrialized, and are accelerating with the use of AI

The results highlight the global scale of intrusion attempts: 150 million reconnaissance events, 2.3 billion brute force attempts, and 1.7 billion cloud intrusion and exploitation attempts.

The Cloud-Native Threat Landscape Report 2026 shows that threat actors are currently using automated attack flows to identify vulnerable deployments, compromise them, and quickly convert that access into economic benefits.

One of the key findings of the report is that adversaries are turning cloud intrusions into a continuous, automated process. Attackers continually map environments, probe credentials, exploit exposed services, and move quickly toward their targets.

What can organizations do to avoid it?

Ensure that cloud security does the same: dynamically reduce risk, close security gaps that facilitate attacks, monitor potential misuse of resources, and leverage broad context to act quickly on the most relevant threats. These are the main threats and the measures that organizations should take to reduce them:

AI and automation have accelerated the cloud attack chain: Threat actors use AI and automation to exploit vulnerabilities at unprecedented speed and scale, reducing exploitation time from weeks to hours and dramatically shortening the ability to respond. Given this scenario, security teams must adopt automated and AI-driven processes throughout the application lifecycle to prevent, detect and respond to attacks at machine speed.

Identity compromise is already the main route of intrusion: attackers use stolen or exposed credentials to access through legitimate means, making detection difficult. To combat this, in addition to strong authentication, organizations need continuous visibility into permissions, privileges, and anomalous behavior to prevent access to critical data and resources.

The absence of security controls accelerates the advance of attackers: the speed in the deployment of AI applications and services can lead to incorrect configurations, excessive permissions and exposed services, making it easier for attackers to advance. To reduce risk, organizations should apply security controls throughout the lifecycle and continually prioritize the most critical and exploitable vulnerabilities.

Attackers are increasingly using cloud resources to obtain financial benefits by abusing email services, crypto mining or AI platforms. An unexpected increase in the use of cloud resources or services can be a sign that an attacker has gained access to the environment, so anomaly detection using AI is key to identifying and containing these threats in time.

Gap between speed of cloud intrusions and response capacity

The report points out three key priorities to reduce the growing gap between the speed of cloud intrusions and the response capacity of defense teams:

1. Continually identify and prioritize exploitable risks

Continuous threat exposure management provides signals from cloud accounts, development pipelines, data warehouses, repositories, identities, and runtime activity. FortiCNAPP integrates signals from across the cloud environment and applies AI models to identify and prioritize the most relevant risks and threats.

2. Apply native AI security from code to execution to response

Prevention, protection, detection and response must span the entire application lifecycle. Fortinet AI-Native Security Fabric protects the entire application lifecycle, from code to execution, integrating prevention, protection, detection and response using AI and automation.

3. Validate resilience through active testing

Static checks do not reveal all vulnerabilities present during execution. Dynamic testing and red teaming with AI allow vulnerabilities to be identified before attackers. FortiDAST and FortiAIGate extend these capabilities to generative AI applications and systems.

It is possible to consult the Cloud Native Threat Outlook Report 2026 on the Fortinet website.