At FDC Summit 2026, Kaspersky turns threat intelligence into a frontline business weapon
Cyberattacks are getting faster, harder to predict and increasingly shaped by artificial intelligence, but the biggest challenge facing companies may no longer be detecting an attack after it starts.
It is knowing which threat matters before it becomes an incident.
That shift is pushing threat intelligence from a specialist cybersecurity function into a broader business tool, and it is also shaping the technology Kaspersky is likely to put under the spotlight during FDC Summit 2026 in Cairo.
The scale of the problem is already visible across the region.
During the first half of 2026, Kaspersky’s detection systems stopped 75.8 million attacks originating from online resources across the Middle East, as attackers increasingly adopted artificial intelligence to accelerate phishing, malware development and other parts of their operations.
For a company that has spent decades tracking cybercriminal groups, Advanced Persistent Threats and emerging attack techniques, this changing environment is putting one of Kaspersky’s traditional strengths back at the center of the cybersecurity discussion: understanding the attacker.
AI is making cybercrime cheaper and faster
Artificial intelligence is changing the economics of cybercrime.
Large language models can now help attackers generate convincing phishing emails, build parts of malicious software and modify code faster than before, reducing the time and technical expertise needed to launch certain attacks.
Kaspersky researchers have already observed AI-assisted malware development in real-world campaigns, while warning that generative models can help malicious actors rewrite malware for different architectures and scale their operations more rapidly.
The same enthusiasm surrounding AI adoption is also creating opportunities for criminals.
Between January and April 2026, Kaspersky detected more than 33,300 attacks targeting small and medium-sized businesses using malware or unwanted software disguised as popular AI services, nearly five times the level recorded during the comparable period a year earlier.
A separate global analysis found more than 92,000 malware and potentially unwanted application attacks disguised as AI services and agents between January and early May, including fake versions of some of the fastest-growing AI platforms.
The message is clear: attackers are not only using AI, they are also exploiting the demand for AI itself.
The problem with having too much security data
Modern enterprises already generate huge volumes of security information from endpoints, networks, cloud platforms, applications and identities.
But more information does not automatically mean better security.
Kaspersky said its systems discovered an average of around 500,000 malicious files every day during 2025, illustrating the scale of the signals security teams may need to interpret.
The challenge is determining which of those signals represents a genuine risk to a specific organization.
A vulnerability affecting one company may be irrelevant to another, while an attacker targeting financial institutions in one region may pose little immediate risk to an industrial organization elsewhere.
This is where threat intelligence is becoming increasingly valuable.
Instead of asking only whether malicious activity exists, companies can ask more useful questions: Who is behind it? Which industries are being targeted? What techniques are they using? And does the organization have infrastructure that could be exposed?
Kaspersky turns threat reports into a working intelligence platform
One of Kaspersky’s most significant moves this year has been the expansion of its Threat Intelligence Portal.
In May, the company transformed its Threat Intelligence Reporting service into a more interactive content environment, giving security teams direct access to intelligence covering Advanced Persistent Threats, cybercrime and threats targeting Industrial Control Systems.
The platform adds geographic filtering, visual analysis and contextual information intended to help security teams connect threat research with real operational decisions.
Kaspersky produces more than 200 in-depth threat intelligence reports annually, but the direction of the platform shows how the company wants that research to be used.
Threat intelligence is moving away from being something analysts simply read and toward becoming something they actively interrogate.
A bank could focus on campaigns targeting financial institutions in its region, while an energy company could examine threats affecting industrial environments and operational technology.
That makes intelligence more relevant to business priorities rather than simply adding another stream of cybersecurity information.
Hunt Hub moves analysts closer to the attacker
Kaspersky has also expanded the investigation side of its intelligence platform through Hunt Hub, introduced earlier this year.
The new capability centralizes threat hunting expertise and detection knowledge, while expanding MITRE ATT&CK mapping and vulnerability information to help analysts understand how suspicious activity relates to known attacker behavior.
That may sound like a technical improvement, but it reflects a broader change inside Security Operations Centers.
Traditional cybersecurity teams often wait for an alert and then begin investigating.
Threat hunting reverses that process.
Analysts actively search for evidence that an attacker may already be operating inside the environment, even before conventional security systems generate a clear warning.
As attacks become faster and more automated, the ability to hunt proactively could become increasingly important.
AI agents could become attackers from inside the network
The rise of agentic AI is also creating a new category of risk.
AI agents are being designed to perform tasks autonomously, access corporate systems, retrieve information and interact with applications without requiring human approval at every stage.
Those capabilities make them useful, but they also make them attractive targets.
Kaspersky researchers have warned that compromised AI agents could become persistence mechanisms inside organizations, particularly where agents are given extensive system privileges.
Attackers could potentially manipulate an agent’s configuration, system prompt or skills, turning a trusted corporate tool into a mechanism for stealing information, executing unauthorized actions or maintaining access to the environment.
That changes the cybersecurity conversation around AI.
Companies are no longer dealing only with employees accidentally sharing sensitive data with generative AI services.
They may soon have to defend autonomous software entities that can make decisions and take actions on their own.
Even trusted cloud services can hide an attack
Another trend identified by Kaspersky shows why traditional security indicators are becoming less reliable.
Attackers are increasingly using legitimate cloud storage and file-sharing platforms to move stolen data, allowing malicious traffic to blend into normal business activity.
Blocking an unknown server is relatively simple.
Blocking a trusted cloud platform used every day by employees is not.
Security teams therefore need context rather than simple lists of malicious addresses.
They need to understand behavior, relationships and attacker techniques.
That is precisely where threat intelligence becomes valuable.
Cyber intelligence moves into the boardroom
The growing importance of threat intelligence also means cybersecurity is becoming less isolated from wider business decisions.
An organization deciding where to invest, which suppliers to trust or how quickly to deploy a new technology increasingly needs to understand the cyber risks surrounding those decisions.
For critical infrastructure operators, the consequences extend even further.
Cyberattacks against energy, manufacturing or transport environments can affect physical operations and business continuity rather than simply exposing information.
Kaspersky’s experience in Industrial Control Systems security gives the company a particularly relevant role in that discussion, especially at FDC Summit, where governments, financial institutions, telecom operators and major enterprises will be represented.
What to watch from Kaspersky at FDC Summit 2026
Kaspersky’s presence at FDC Summit is therefore likely to be less about introducing another standalone cybersecurity product and more about showing how threat intelligence, AI-assisted defense, threat hunting and managed security can work together.
The timing matters.
As organizations accelerate AI adoption, attackers are gaining many of the same advantages: automation, speed and lower operating costs.
That means security teams will increasingly be judged not only on whether they can respond to an attack, but on whether they can recognize the threat early enough to prevent it from becoming a crisis.
In that environment, information about an attacker is no longer just intelligence.
It is becoming a competitive advantage.
