Why Insider Threats and Zero-Days Are Rising in 2026 [Prime Cyber Insights]

This briefing analyzes a fundamental shift in the cybersecurity landscape as of March 2026. A new Mimecast report reveals that malicious insider threats have reached parity with negligent incidents, with both categories seeing a 42% year-on-year increase and costing organizations an average of $13.1 million per incident. Simultaneously, the Google Threat Intelligence Group (GTIG) reports 90 zero-day vulnerabilities exploited in 2025, noting a strategic pivot where attackers are now targeting enterprise systems and security appliances over traditional browser-based exploits. Finally, we examine Cisco Talos research into UAT-9244, a China-linked threat actor targeting South American telecommunications infrastructure using sophisticated new implants like TernDoor and the peer-to-peer Linux backdoor PeerTime. These developments underscore the need for adaptive security controls and agentic defenses as AI continues to accelerate both attack and discovery cycles.

In this episode of Prime Cyber Insights, we break down the latest data on internal and external risk factors facing the modern enterprise. We examine the Mimecast research highlighting the $13.1 million average cost of insider incidents and the alarming rise of intentional betrayal alongside employee negligence. The briefing then shifts to the Google Threat Intelligence Group's analysis of 2025 zero-day trends, which shows nearly half of all exploits now targeting enterprise technology rather than consumer browsers. We conclude with a deep dive into the tactical overlaps of China-linked espionage groups targeting critical infrastructure in South America with custom-built backdoors like TernDoor and PeerTime. These reports collectively signal a move toward more targeted, industrialized cyber threats that exploit both human and architectural vulnerabilities.

Topics Covered

  • ⚠️ The Parity of Risk: Why malicious and negligent insider incidents now each account for 42% of internal threats.
  • 📊 The Financial Impact: Analyzing the $13.1 million average cost per insider incident and the frequency of six events per month.
  • 🔒 Zero-Day Stabilization: Google's findings on the 90 vulnerabilities patched in 2025 and the shift toward enterprise-focused exploitation.
  • 🌐 Regional Espionage: Examining UAT-9244's targeting of South American telecoms with TernDoor, PeerTime, and BruteEntry implants.
  • 🛡️ Defense Evolution: The move toward adaptive controls and agentic solutions to counter AI-accelerated vulnerability discovery.

Disclaimer: This briefing is for informational purposes only and does not constitute professional security or legal advice.

Neural Newscast is AI-assisted, human reviewed. View our AI Transparency Policy at NeuralNewscast.com.

  • (00:12) - Introduction
  • (00:23) - The $13M Insider Threat Parity
  • (01:08) - Google's Zero-Day Enterprise Shift
  • (01:08) - South American Telecom APT Activity
  • (03:42) - Conclusion
Why Insider Threats and Zero-Days Are Rising in 2026 [Prime Cyber Insights]
Broadcast by