Announcing Forrester’s Top Cybersecurity Threats For 2026 AI innovation is moving at an unprecedented rate, and geopolitical tensions show no signs of easing. Forrester identifies these factors as two primary forces reshaping the threat landscape, placing additional strain on CISOs who are already stretched thin managing increasingly complex security programs. Anthropic’s Claude Mythos Preview and Project Glasswing are early signals of how radically areas such as vulnerability discovery, remediation, and exploitation are about to change. Simultaneously, the escalating US-Iran conflict has already translated into real world impact, driving a spike in disruptive cyberattacks; from the Stryker incident to Iranian-linked actors targeting PLCs across US critical infrastructure. AI has been a consistent thread running through the last three editions of Forrester’s top threats report. AI‑driven threats have evolved across the past three years as follows: - AI is more than LLMs and ChatGPT. Back in the top threats report for 2023, when ChatGPT was still the public’s first real handshake with large language models, we flagged data integrity as the standout risk. The concern here was the trust placed in these AI systems. - AI has been weaponized. In the 2024 edition of the report, the focus shifted from trust to misuse. We called out how genAI was being weaponized for enabling narrative attacks via disinformation, growing concerns around deepfakes, and concerns over AI responses due to prompt engineering, injection attacks, or the increased risk of sensitive data spillage. - AI supply chain risk emerged. In 2024, we also flagged the AI software supply chain risk as a threat (Spoiler: This concern hasn’t gone away, and it shows up again in this year’s report with updated findings). This is driven by adoption of open‑source models and frameworks such as those found in Hugging Face and GitHub. - Deepfakes are maturing and