Blogs
The latest cybersecurity trends, best practices, security vulnerabilities, and more
Trellix SecondSight Threat Hunting Report: How AI and Human Intelligence Expose 2026 Cyber Threats
By John Fokker and Adam Rocker · September 8, 2026
Threat hunting is changing. As adversaries adopt new technologies, techniques, and increasingly AI-enabled ways of operating, defenders have access to more telemetry, intelligence, and automation than ever before. But more data does not automatically translate into better security. The challenge is knowing where to look, what matters, and when a weak signal deserves a closer look.
This is the thinking behind Trellix SecondSight, and the focus of our new Trellix SecondSight Threat Hunting Report.
Analyzing five major H1 2026 cyber campaigns
The latest report looks at five significant campaigns we observed during the first half of 2026:
- A stealthy multistage campaign associated with APT28
- Bitter APT spear-phishing using the FIFA World Cup as a lure
- A Russian DarkSword iOS exploit kit aimed at NATO-aligned officials
- JSCeal activity targeting organizations in Southeast Asia
- The broad Axios npm software supply chain attack
But the report is about more than the campaigns themselves. It provides a look at how our threat hunters take emerging intelligence, attacker behaviors, indicators, and subtle signals and turn them into proactive hunts across real-world telemetry.
Each hunt progresses through clear decision points:
- Validating threat intel relevance
- Confirming behavioral alignment with known techniques
- Assessing environmental exposure
- Determining whether proactive customer notification is warranted
The result is a disciplined, repeatable approach that prioritizes early disruption over retrospective investigation.
The Axios npm compromise provides a good example. As intelligence about the attack emerged, Trellix SecondSight hunters translated the known infrastructure and attacker behaviors into IOC- and TTP-based hunts across Trellix telemetry—helping identify potentially affected environments, reconstruct activity, and notify customers.
That ability to compress the time between intelligence → hunt → evidence → action is increasingly important.
The human element: Why AI tools cannot replace threat hunters
AI and automation can process enormous amounts of data, correlate signals, and execute hunting logic at a scale no human team could replicate manually.
But that does not remove the hunter from the equation. It changes the hunter's role.
Human expertise is still required to determine what is worth hunting, understand why a signal matters, develop the analytical logic behind a hunt, and follow unexpected evidence when an investigation takes a different direction. Automation provides the reach; human curiosity provides the direction.
This combination sits at the heart of Trellix SecondSight. It brings together Trellix threat intelligence, telemetry from endpoint, network, and email security, and expert human threat hunters to investigate the gray space between routine activity and a confirmed attack.
Trellix SecondSight is designed to provide that additional set of eyes—the ability to investigate signals that automated systems may surface but cannot always fully interpret.
Turning telemetry into proactive incident response
For us, threat hunting doesn’t end with the hunt. What we learn about adversaries feeds back into our intelligence, detections, products, and ultimately the protection we provide customers.
That is one of the ideas we hope comes through clearly in this report. Effective threat hunting is not about how many queries we run or alerts we generate. It is about how effectively we combine intelligence, technology, analytical discipline, and human curiosity to uncover what an adversary hoped would remain unseen—and turn that knowledge into protection.
We invite you to dig into the five investigations and learn more about how Trellix SecondSight is helping organizations move from reactive detection toward proactive defense by exploring the new Trellix SecondSight Threat Hunting Report.
Discover the latest cybersecurity research from the Trellix Advanced Research Center.
RECENT NEWS
-
Aug 24, 2026
Trellix Expands Leadership Team to Accelerate Growth and Cyber Resilience
-
May 19, 2026
Trellix Appoints Joe Chen as Chief Technology Officer
-
Apr 08, 2026
Trellix prevents enterprise data exposure in sanctioned and shadow AI
-
Mar 02, 2026
Trellix strengthens executive leadership team to accelerate cyber resilience vision
-
Feb 10, 2026
Trellix SecondSight actionable threat hunting strengthens cyber resilience
RECENT STORIES
Latest from our newsroom
Get the latest
Stay up to date with the latest cybersecurity trends, best practices, security vulnerabilities, and so much more.
Zero spam. Unsubscribe at any time.