Trends and Challenges in Cybersecurity for 2025-2026
The cybersecurity landscape in 2025 saw significant evolution, with a marked increase in supply chain attacks targeting CI/CD pipelines, open source packages, and developer tooling. Organizations like StepSecurity reported detecting and responding to some of the most consequential supply chain compromises before they became public, highlighting the need for real-time visibility and enforcement across software supply chains. The year also witnessed rapid growth in the adoption of security solutions, as enterprises sought to protect their development environments and open-source repositories from increasingly sophisticated threats.
Simultaneously, the industry experienced major shifts in technology and risk management. Startups drove innovation in browser security, application security for AI-generated code, and SOC automation, reflecting the growing importance of cloud-based workspaces and AI-driven applications. On the risk management front, CISOs faced a tightening cyber insurance market, with insurers demanding more rigorous proof of security controls and warning that major supply chain or AI-related incidents could quickly harden underwriting standards. These developments underscore the need for organizations to adapt their security strategies to address both emerging technical threats and evolving risk management requirements.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
4 events from the most recent confirmed update back to the earliest known activity.
StepSecurity expands defenses after 2025 supply chain incidents
In response to the 2025 attacks, StepSecurity expanded its product capabilities with real-time enforcement, secure action replacements, and rapid detection tools, and said it planned broader protections for 2026.
Gartner names 'AI SOC Agents' in its Hype Cycle
In June 2025, Gartner's Hype Cycle identified the category 'AI SOC Agents,' marking a notable recognition point for AI-driven SOC automation offerings.
Google rolls out Manifest V3 browser extensions
In June 2025, Google rolled out Manifest V3 (MV3) extensions, which the commentary says enabled a new control plane for browser observability and enforcement and helped spur emerging browser security startups.
Major software supply chain attacks hit CI/CD and open source ecosystems
During 2025, several major supply chain incidents highlighted growing attacks on developer tooling and pipelines, including the tj-actions/changed-files compromise, Shai Hulud npm package compromises, and the Nx (s1ngularity) compromise.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
3 references tracked. Mallory keeps watching after this page renders.
2025 in Review: The Evolution of Supply Chain Security & What's Next
stepsecurity.io
Open sourceStartup Trends Shaking Up Browsers, SOC Automation, AppSec
darkreading.com
Open sourceCISOs Face A Tighter Insurance Market in 2026
darkreading.com
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.

