Your security tools stopped the obvious attack. They missed the sneaky one.

Picus Security's Blue Report 2026 finds defenses catch famous techniques reliably but let quieter variants walk straight through.

ThreatVectr NewsdeskUpdated · Editor: Lee Brown· 3 min read
A security operations center with multiple detection screens showing successful blocks of known attack patterns highlighted in green, while subtle, unusual netw
Share

Key points

  • Picus Security's Blue Report 2026 tested how well corporate security tools block real attack behaviours, not just known malware samples.
  • Prevention rates swing sharply between techniques, with some blocked over 90% of the time and near-identical variants missed almost entirely.
  • The gap is worst when attackers abuse built-in operating system tools instead of custom malware, an approach known as "living off the land".
  • Companies should test their defenses against attacker behaviour continuously, not once a year in a formal audit.
  • Passing a compliance checklist isn't the same as being safe.

Security software is good at spotting attacks it has seen before. It's much worse at spotting the same attack wearing a slightly different hat.

That's the uncomfortable finding in the Blue Report 2026 from Picus Security, a company that tests corporate defenses by safely simulating real attacks. First reported by BleepingComputer, the study looked at how often widely deployed security tools actually stop attacker behaviour, rather than just flagging known bad files. We first covered the report on 12 August, when it showed that companies blocking more attacks at the front door than ever still left intruders free to roam once inside.

What did the report actually find?

Companies block famous attack techniques well but miss quieter versions of the same thing. Picus ran millions of simulated attacks against real customer environments and found prevention rates that varied sharply from one technique to the next, even when the end goal was identical.

A company can show an auditor it blocks a well-known hacking tool while a different tool doing the same job slips past unnoticed. The failure mode is pattern matching. Security products learn what bad looks like, and attackers just change what it looks like.

Why do the same defenses catch one attack and miss another?

Because most defenses were built to spot signatures, not behaviour. A signature is a fingerprint of a specific piece of malicious software. Change the fingerprint and the alarm goes quiet.

Attackers know this. Increasingly they abuse tools already built into Windows or Linux, things like PowerShell or scheduled tasks, instead of dropping their own malware. Nothing looks obviously wrong because nothing foreign is running. Picus found this category especially poorly defended. The post-mortem will say, again, that the intruder never needed custom code.

What does this mean for regular businesses?

Buying the security product isn't the same as being protected by it. Configuration matters. Testing matters more.

The report advocates what the industry calls continuous validation: running fake attacks quietly against your own network to see what your tools actually catch, then fixing the gaps. Think of it as a fire drill for the security stack, not a one-off inspection. The same argument was made from a different angle in our 14 July story on Pentera, where the vendor pushed proof-based validation into AI security workflows.

For anyone relying on a bank, an employer, or a health provider to keep their data safe, the read is straightforward. Ask whether that organisation tests its defenses regularly. A yearly penetration test is a snapshot. Attackers don't keep office hours.

Attack style How defenses tend to do
Known malware families Blocked reliably
Slight variants of the same malware Often missed
Built-in OS tools abused by attackers Poorly detected
Data theft over normal web traffic Frequently missed

The operational read

If your security programme can't tell you what it blocked yesterday against live attacker behaviour, it's measuring paperwork, not risk. Continuous validation isn't a premium add-on anymore. It's the minimum honest answer to the question of whether your controls actually work.

© 2026 Threat Vectr