RNeZpDoCrAtB

R$eTpGoIrHt#

RUeKp6oZrMtY

Beyond the Human Horizon: Cogent Q4 2026 Threat Report

Cogent Research analyzed 43 million assets across 50+ Fortune 1000 companies to measure the attack paths humans and AI agents can exploit. The findings show AI-only paths forming three times as fast as human-viable ones and outlasting them, as policies rank their findings too low.

Key findings

  • Machine-viable attack paths surged 386% in a year and now outnumber human-viable ones three to one

  • 26% of machine-viable attack paths contain no finding that the organization's own remediation policy ever requires fixing

  • 83% of machine-viable attack paths persist for more than 30 days, compared with 55% of human-viable paths

  • Machine-viable paths run twice as deep as human-viable ones, with a median of 8 asset hops versus 4

  • 64% of attack paths cross domains no single security tool observes, and the median critical path needs data from five tools


What's covered

The full analysis includes depth and per-hop yield comparisons for both path types, why severity-based remediation leaves machine-viable paths standing, and a methodology section detailing data sources and thresholds.



When it takes five or six days for a vulnerability to show up in your scanner, you're giving attackers a week-long head start. This should be a wake-up call for any security organization still treating scanner output as their first line of visibility.”

Scott Howitt

Former CISO (JCPenney, UKG, MGM)

“

When it takes five or six days for a vulnerability to show up in your scanner, you're giving attackers a week-long head start. This should be a wake-up call for any security organization still treating scanner output as their first line of visibility.”

Scott Howitt

Former CISO (JCPenney, UKG, MGM)

“