AhnLab ASEC’s Q3 2026 attack-techniques review points to a pattern defenders should take seriously: attackers are not just breaking in through one exposed service and stopping there. They are using trusted paths — perimeter appliances, web application directories, software registries, CI/CD workflows, identity recovery flows, and cloud collaboration portals — to persist and expand after the first access.
That matters for small businesses, managed service providers, and government contractors because these are exactly the environments where a single “trusted” system often connects too many parts of the organization. A VPN appliance can touch the internal network. A build pipeline can reach secrets. An identity portal can grant access to email, files, and downstream SaaS applications. Once an attacker lands on one of those trust paths, the incident becomes more than a patching problem.
What ASEC reported
ASEC observed increased attacker use of organization-trusted paths during Q3 2026. The report highlights perimeter-device exploitation that led to web shell deployment, malicious software packages pushed through official package registries, and identity attacks built around password reset impersonation, passkey registration abuse, device-code authorization, and adversary-in-the-middle phishing.
The report also notes that CISA’s Known Exploited Vulnerabilities catalog added 100 entries from July through September 2026, roughly double the same period in 2025. Web/server applications and network/perimeter devices accounted for the majority of those additions, with development, deployment, AI, and LLM tooling also appearing in the mix.
Source: AhnLab ASEC — Q3 2026 Attack Techniques Trend Report.
The common thread: trusted access becomes attacker infrastructure
The technical details vary, but the defender takeaway is consistent. Attackers want paths that already look legitimate:
- Perimeter appliances give attackers a route from the internet into trusted network zones.
- Web shells in legitimate web paths blend command execution into normal server locations.
- Package registries and CI/CD triggers can turn software delivery into credential theft or malware execution.
- Passkey, password recovery, and device-code flows let attackers bypass the mental model of “MFA means safe.”
- Cloud productivity platforms provide lateral movement through email, files, Graph APIs, SharePoint, OneDrive, and Exchange once sessions or tokens are stolen.
This is why incident response has to look beyond the original exploit. If a NetScaler, firewall manager, CI job, or identity workflow was abused, defenders should assume the attacker tried to convert that foothold into durable access.
Defensive moves worth prioritizing
- Patch by exposure, not just severity. Internet-facing appliances, identity systems, source-control platforms, and build tools deserve faster handling than isolated internal assets with the same CVSS score.
- Inspect appliance file systems and web paths. Look for unexpected files, web shell indicators, altered web server configuration, unusual script locations, and permission changes on system binaries.
- Treat CI/CD secrets as incident-response scope. If a malicious package or poisoned build path is found, rotate accessible tokens and review what the pipeline could deploy or read.
- Lock down identity recovery paths. Re-verify passkey registration, password recovery, and help-desk reset requests through known internal channels. Do not rely on the inbound requester identity alone.
- Restrict device-code flows where possible. Device-code authorization is useful, but unmanaged use creates a clean path for token theft and cloud access.
- Hunt by behavior sequence. ASEC’s emphasis on indicators of attack is right: single filenames and domains age quickly, but the chain of exploit, persistence, credential access, and expansion is harder for attackers to hide.
Bulwark Black assessment
The strongest lesson from the report is that “trusted” does not mean “safe.” Trusted paths need the most scrutiny because they are the paths defenders are least likely to question during normal operations.
For SMBs and government contractors, the practical starting point is a short list of systems that can turn one compromise into many: perimeter appliances, identity providers, remote access tools, admin portals, source-control systems, CI/CD runners, documentation platforms, and cloud email/file storage. For each one, identify who owns it, how it is patched, what logs exist, what secrets it can reach, and how quickly access can be revoked during an incident.
The organizations that handle this best will not be the ones with the longest vulnerability spreadsheet. They will be the ones that understand their trust paths, monitor them, and rehearse what happens when one of those paths becomes hostile.

