Take a Product Tour Request a Demo Cybersecurity Assessment Contact Us

Blogs

The latest cybersecurity trends, best practices, security vulnerabilities, and more

Trellix SecondSight Threat Hunting Report: How AI and Human Intelligence Expose 2026 Cyber Threats

Threat hunting is changing. As adversaries adopt new technologies, techniques, and increasingly AI-enabled ways of operating, defenders have access to more telemetry, intelligence, and automation than ever before. But more data does not automatically translate into better security. The challenge is knowing where to look, what matters, and when a weak signal deserves a closer look.

This is the thinking behind Trellix SecondSight, and the focus of our new Trellix SecondSight Threat Hunting Report.

Analyzing five major H1 2026 cyber campaigns 

The latest report looks at five significant campaigns we observed during the first half of 2026:

  • A stealthy multistage campaign associated with APT28
  • Bitter APT spear-phishing using the FIFA World Cup as a lure
  • A Russian DarkSword iOS exploit kit aimed at NATO-aligned officials
  • JSCeal activity targeting organizations in Southeast Asia
  • The broad Axios npm software supply chain attack

But the report is about more than the campaigns themselves. It provides a look at how our threat hunters take emerging intelligence, attacker behaviors, indicators, and subtle signals and turn them into proactive hunts across real-world telemetry.

Each hunt progresses through clear decision points:

  • Validating threat intel relevance
  • Confirming behavioral alignment with known techniques
  • Assessing environmental exposure
  • Determining whether proactive customer notification is warranted

The result is a disciplined, repeatable approach that prioritizes early disruption over retrospective investigation.

The Axios npm compromise provides a good example. As intelligence about the attack emerged, Trellix SecondSight hunters translated the known infrastructure and attacker behaviors into IOC- and TTP-based hunts across Trellix telemetry—helping identify potentially affected environments, reconstruct activity, and notify customers.

That ability to compress the time between intelligence → hunt → evidence → action is increasingly important.

The human element: Why AI tools cannot replace threat hunters

AI and automation can process enormous amounts of data, correlate signals, and execute hunting logic at a scale no human team could replicate manually.

But that does not remove the hunter from the equation. It changes the hunter's role.

Human expertise is still required to determine what is worth hunting, understand why a signal matters, develop the analytical logic behind a hunt, and follow unexpected evidence when an investigation takes a different direction. Automation provides the reach; human curiosity provides the direction.

This combination sits at the heart of Trellix SecondSight. It brings together Trellix threat intelligence, telemetry from endpoint, network, and email security, and expert human threat hunters to investigate the gray space between routine activity and a confirmed attack.

Trellix SecondSight is designed to provide that additional set of eyes—the ability to investigate signals that automated systems may surface but cannot always fully interpret.

Turning telemetry into proactive incident response

For us, threat hunting doesn’t end with the hunt. What we learn about adversaries feeds back into our intelligence, detections, products, and ultimately the protection we provide customers.

That is one of the ideas we hope comes through clearly in this report. Effective threat hunting is not about how many queries we run or alerts we generate. It is about how effectively we combine intelligence, technology, analytical discipline, and human curiosity to uncover what an adversary hoped would remain unseen—and turn that knowledge into protection.

We invite you to dig into the five investigations and learn more about how Trellix SecondSight is helping organizations move from reactive detection toward proactive defense by exploring the new Trellix SecondSight Threat Hunting Report.

Discover the latest cybersecurity research from the Trellix Advanced Research Center.

This document and the information contained herein describes computer security research for educational purposes only and the convenience of Trellix customers.

Get the latest

Stay up to date with the latest cybersecurity trends, best practices, security vulnerabilities, and so much more.
Please enter a valid email address.

Zero spam. Unsubscribe at any time.