Modern Attacks Don't Stay in One Place, So Your Defences Shouldn't Either
New research from Unit 42's 2026 Global Incident Response Report reveals that modern cyberattacks rarely stay confined to a single system. In fact, 43% of investigated attacks involved activity spanning four or more different environments, such as cloud platforms, endpoints, networks, identity systems and SaaS applications, with some cases touching as many as eight.
This cross-environment movement makes attacks harder to spot. An intrusion might begin with something that looks minor, an unusual endpoint alert, a cloud resource set up outside normal patterns, or an app requesting extra permissions. On their own, these events may seem unremarkable. But as the attack progresses, related signs can appear elsewhere: changed permissions in a SaaS tool, reconfigured cloud resources, data being prepared for theft, or new connections between systems that don't normally talk to each other.
The danger is that if security teams look at these signals in isolation, they can miss the bigger picture entirely. Unit 42 notes that connecting activity across these different domains, often with the help of AI-driven correlation, is what allows defenders to see the full attack path: how access was gained, where the attacker moved, and what they were trying to achieve.