According to Kaspersky’s telemetry, online threats exploiting
vulnerabilities in websites, emails and web services continued to affect
millions of users across the META region during the first half of 2026
JOHANNESBURG, South Africa, July 30, 2026/ — Kaspersky’s
(www.Kaspersky.co.za) Global Research & Analysis Team (GReAT)
reveals key cyber threat trends for the first half of 2026 at the recent
Cyber Security Weekend for the Middle East, Turkiye and Africa region
(META).
As the cybersecurity landscape continues to evolve, cyberthreats are
becoming increasingly diverse and sophisticated. The rapid adoption of
artificial intelligence (AI), coupled with ongoing geopolitical and
economic instability, is contributing to the rise of cybercrime and the
growing complexity of cyberattacks.
According to Kaspersky’s telemetry, online threats exploiting
vulnerabilities in websites, emails and web services continued to affect
millions of users across the META region during the first half of 2026.
Specifically, Kaspersky detection systems stopped 5,7M attacks from
various online resources in South Africa, 4,5M in Kenya and 1,6M in
Nigeria.
Turkiye recorded the highest percentage of users affected by web-based
threats at 22.8%, followed by Kenya (21.2%), Qatar (19.3%), Nigeria
(18.4%) and South Africa (17.2%). In contrast, Saudi Arabia, Jordan and
Pakistan registered the lowest share of users targeted by web-borne
attacks in the region.
AI is transforming attacker operations
Kaspersky experts report that threat actors are increasingly integrating
AI into different stages of their operations. Large language models are
already being used to generate phishing emails, malicious code and
supporting operational content.
AI is also beginning to play a larger role in malware development.
Modern language models are capable of generating substantial portions of
malicious software, from initial code scaffolding to functional modules.
Researchers have already observed AI-assisted malware development in
campaigns linked to the FunkSec group, which deployed Rust-based malware
capable of data theft, encryption and process manipulation. Similarly,
during the RevengeHotels campaign in 2025, threat actors used large
language models to generate portions of the infector and downloader
code.
“We expect AI to remain one of the key factors shaping the threat
landscape in 2026, as we already see how it is reshaping attacker
workflows and accelerating their operations,” said Sergey Lozhkin, Head
of Global Research and Analysis Team in APAC and META regions at
Kaspersky. “By lowering the time and cost required to develop and adapt
malicious tools, AI allows threat actors to iterate faster and scale
their efforts. Defenders should be prepared for quicker shifts in
tactics.”
Emerging trends shaping the cyber threat landscape
In addition to the growing use of AI by cybercriminals, Kaspersky
experts identified several trends that organisations should monitor
closely:
- AI-driven malware evolution: generative models can rewrite malware
in different languages or architectures, making malicious code harder to
detect, and faster to deploy at scale. - Cloud-based data exfiltration: attackers increasingly route stolen
data through legitimate cloud and file-sharing services to blend in with
normal traffic. - Ransomware targeting operations: some groups disrupt production and
business processes, not just encrypt data, to increase pressure for
payment. - AI agents as persistence mechanisms: some AI agent solutions are
granted broad or even full system access. If compromised, attackers
could modify the system prompt or the agent’s configuration, for
example, causing it to download a payload on every startup. - Malicious AI skills become a new attack vector: as AI agents gain
broader access to enterprise systems, attackers start to exploit
compromised skills to manipulate agent behaviour, steal sensitive data,
execute unauthorised actions, and establish persistent access. This
creates a new layer of risk where trusted AI tools can be turned into
powerful mechanisms for cyberattacks.
As cyberthreats continue to evolve alongside emerging technologies,
Kaspersky recommends that organisations strengthen their cybersecurity
posture through continuous vulnerability management, timely patching,
employee awareness training, threat intelligence, and advanced security
solutions like Kaspersky Next (https://apo-opa.co/4xbceIX), capable
of detecting sophisticated and AI-assisted attacks.


Comments
Start the conversation about this story.