"The total means an average of roughly 2,514 cybersecurity events every second," the Comcast Business 2026 Cybersecurity Threat Report found.
Comcast Business 2026 Cybersecurity Threat Report: scope and headline
The report analyzed 79.3 billion cybersecurity events detected across Comcast Business cybersecurity customers between March 1, 2025, and February 28, 2026. From that dataset the authors calculated the headline figure — an average of roughly 2,514 cybersecurity events occurring every second over the 12‑month window.
Phishing, drive-by compromise, initial access, and resource development volumes
The report says phishing and drive‑by compromise attacks "still lead by volume," even as attackers accelerate how quickly they can exploit vulnerabilities. In one breakdown the report lists 47.9 billion initial access events and 5.2 billion resource development events, "showing the volume of automated attacks probing the perimeter and the infrastructure attackers built to run them." Elsewhere the report enumerates 25.4 billion phishing events and 21.9 billion resource development events, repeating the characterization of those totals as evidence of automated, high‑volume probing and infrastructure build‑out.
Researchers attribute part of the acceleration to tooling: "AI coding tools let attackers develop new exploits before patches are available, while the underlying techniques stay familiar." The net effect reported is not a novel technique set but faster, cheaper execution at scale.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleActive scans, DDoS, and browser covert-access attempts
The Comcast Business report also catalogs persistent, automated reconnaissance and blunt force interruption attempts. It records 288.9 million active scans — described as "evidence of adversaries constantly hunting vulnerable devices" — and 57,000 distributed denial‑of‑service (DDoS) events driven by botnets seeking to interrupt digital business services with hyper‑volumetric traffic. The authors also identified 5.8 million attempts to gain covert access to employee browsers through malicious extensions, browser sync, and session theft.
Identity, AI agents, and APIs as the focal point of defense
The report places identity at the center of defense. It says stolen credentials, hijacked sessions, and "an explosion of non‑human identities have made identity the focal point of defense." It adds that "AI agents and APIs open new inroads into the enterprise, each one carrying permissions no employee would be granted." The recommended defensive posture, as stated in the report, moves beyond one‑time verification: "Defending against this requires identity management paired with ongoing behavioral analysis rather than a one‑time verification."
Compromised residential devices and residential proxy networks
Another theme in the report is the rise of attacker infrastructure built from devices organizations do not own or monitor. Researchers describe a growing share of the corporate attack surface consisting of routers, cameras, streaming devices, and point‑of‑sale terminals in employees' homes and businesses that attackers compromise and conscript into residential proxy networks. Those infected devices are then rented as ordinary‑looking traffic for buyers; researchers "traced this infrastructure and identified large groupings of infected devices forwarding traffic for outsiders." The report notes a practical gap: perimeter controls "do not account for these devices, because no one has mapped them."
What security, resilience & travel risk leaders, enterprises, and end users face
- Security, resilience & travel risk leaders: The report warns these leaders "face a fast‑moving threat environment that extends well beyond the stadiums" as the Americas plan the world’s biggest football tournament in 2026, signaling that major events add context where unmanaged surfaces and high‑volume attacks matter.
- Enterprises and technologists: The report ties the changing threat to tooling and identity, saying defenses will require identity management paired with ongoing behavioral analysis rather than a one‑time verification, and suggests organizations must reconsider controls that assume the enterprise owns or monitors every device on the perimeter.
- End users and physical‑security procurement leaders: The report highlights that "security and compliance reviews of physical security devices tend to fail for the same reasons" and that an expanding set of consumer and point‑of‑sale devices can be co‑opted into attacker infrastructure, creating risk beyond traditional IT assets.
The Comcast Business 2026 Cybersecurity Threat Report lays out a simple, stark arithmetic: billions of automated probes, millions of covert browser intrusions, tens of thousands of DDoS events, and the repurposing of unmanaged devices all add up to roughly 2,514 events every second. The report's prescription — stronger identity management, continuous behavioral analysis, and attention to devices outside formal inventories — is presented as the operational response to that scale. Whether organizations map and neutralize those invisible device clusters or adjust controls for AI agents and API permissions is the concrete question the data leaves on the table.




