35 Actionable Password Statistics for Businesses in 2026 | Huntress
Huntress compiles 2026 password statistics showing 94% of 19 billion leaked passwords were reused and 37% of identity threats used stolen credentials.
Huntress published a compilation of password security statistics drawing on sources including Cybernews, Verizon's 2026 DBIR, IBM, and Bitwarden. Cybernews found 19 billion exposed passwords from roughly 200 incidents between April 2024 and April 2025, with only 6% unique and 94% reused across accounts. Huntress telemetry reports 37% of identity-based threats in 2026 involved stolen or suspicious credentials, while Verizon cites credential abuse in 39% of breaches. The piece argues weak and reused passwords remain a top entry point and recommends improved password hygiene.
July 2026 Cyber Attacks Statistics Infographic
Hackmageddon's infographic condenses July 2026's 188 confirmed cyber attacks into a visual breakdown of actors, entry vectors, targets, and geography.
Hackmageddon published a one-page infographic summarizing 188 confirmed cyber attacks observed in July 2026. It visually maps attacker motivation, infection and entry vectors, targeted sectors, and geographic distribution for the month. It is a companion piece to the site's detailed monthly statistics report.
July 2026 Cyber Attacks Statistics
July 2026 saw 188 confirmed cyber attacks across 69 countries, with financially motivated cyber crime behind roughly three in four incidents.
Hackmageddon's monthly statistics report tallied 188 confirmed cyber attacks in 69 countries during July 2026. Cyber Crime accounted for about 75% of incidents, malware was the attackers' most-used weapon, and exposed public-facing applications were the most common way in. Information and communication infrastructure absorbed the heaviest share of targeting, with the full breakdown covering actors, vectors, and geography.
Hacker Conversations: Vinnie Liu, Performer Turned Ringmaster
SecurityWeek interviews Bishop Fox CEO Vinnie Liu, recruited by the NSA at 17 in 1999, on hacker ethics, intent, and his career.
SecurityWeek's Hacker Conversations series profiles Vinnie Liu, who was recruited by the NSA in 1999 at age 17 via an IRC contact and later became CEO of security consulting firm Bishop Fox. The interview covers his white-hat philosophy that hacking for fun differs from hacking to harm, the moral development he attributes to parents and educators, and the industry's shift from the NSA to commercial firms like @stake after its 2000 acquisition of L0pht Heavy Industries. The piece is biographical and opinion-oriented with no incident, vulnerability, or research content.
Why judgment is emerging as cybersecurity’s defining skill
CyberScoop op-ed argues CISOs should grant AI autonomy based on reversibility and blast radius rather than model confidence, and measure analyst overrides of AI recommendations.
A CyberScoop op-ed contends that as AI takes over analysis and recommendations in security operations, human judgment about context, reversibility and blast radius becomes the defining skill. The author argues autonomy decisions should rest on how reversible and impactful an action is rather than model confidence, citing examples such as patching vendor-certified medical devices and a service account whose 3 a.m. login spikes were normal quarterly-close activity. It also urges leaders to measure analyst approvals, edits and rejections of AI recommendations, and review latency, instead of automation rates or mean time to resolution.
Supply Chain Attacks in 2026: Why Threat Intelligence Is the Only Early Warning System That Works
Cyble argues supply chain attacks are a primary breach vector, citing Verizon DBIR third-party figures and CISA SBOM guidance to pitch its TPRM platform.
Cyble's vendor blog frames third-party compromise as a first-order breach risk, citing Verizon's 2026 DBIR finding that third parties were involved in 48% of breaches, up 60% year over year. It recounts the Cl0p campaigns against Progress MOVEit Transfer (CVE-2023-34362), which affected over 2,700 organizations and 93 million people, and Fortra GoAnywhere (CVE-2023-0669) with roughly 130 claimed victims. It also highlights CISA and NSA's 2026 Minimum Elements for a Software Bill of Materials covering open-source, AI, and SaaS components. The piece concludes by promoting Cyble's Third-Party Risk Management platform.