The Online Security Trends I'm Actually Keeping an Eye On

Sep 02, 2026By Jay Kells
Jay Kells

People ask me a lot which security trend I think matters most right now, and my honest answer changes depending on the week. I read about new attack techniques and new protections pretty much every day, and most of it turns out to be noise dressed up as urgency. But a handful of things keep showing up in my own accounts, in messages from clients, and in conversations with other people who work in this space, and those are the ones I'm actually paying attention to. This isn't a forecast or a list of buzzwords, it's what I'm genuinely watching right now and why.

Passkeys Are Finally Showing Up Everywhere I Log In

For years passkeys felt like something I'd read about but never actually use. That's changed a lot over the past year. I'm now being offered a passkey option on my email account, my banking app, and a couple of the shopping sites I use regularly. What I like about them is that there's no password to steal in the first place, so the usual phishing tricks that rely on tricking me into typing a password into a fake page simply don't work the same way. I've started setting them up wherever they're offered, partly because they're genuinely more convenient once you're used to them, and partly because I want to be comfortable with the technology before it becomes the default rather than the option.

MFA Fatigue and the Push Notifications I've Learned to Question

I used to think multi-factor authentication was close to bulletproof. Then I started reading about push bombing, sometimes called MFA fatigue, where someone who already has your password sends approval requests to your phone over and over until you get annoyed or confused enough to tap approve. It's a simple trick and it works often enough that I've changed how I treat every single approval notification. If I get a push request I wasn't expecting, even just one, I don't approve it automatically anymore. I check what device and location it's coming from first, and if anything looks off I change my password straight away rather than assuming it was a fluke. The NCSC has written about this pattern too, and it's worth reading if you've never seen it explained before.

The AI Voice Cloning That's Made Me Rethink Phone Calls Completely

This is the one that unsettles me most. I've written before about the voice clone call that almost had me fooled, and since then I've tested a few of the free voice cloning tools out of curiosity. It genuinely doesn't take much source audio to produce something convincing over a phone line. My response to this hasn't been to panic, it's been to lean harder on the verification habits I already rely on whenever something feels slightly off. If someone calls asking for money or urgent help, I hang up and call them back on a number I already have saved, every single time, no exceptions.

Professional condenser microphone mounted on shock mount with pop filter and acoustic foam treatment in background

My Browser Catching More Fake Login Pages Than It Used To

On a more positive note, I've noticed the built in phishing and malicious site warnings in my browser catching things earlier than they used to. I get the occasional warning page now that stops me before I land on a lookalike login screen, and when I've checked the URLs afterward they've usually been close copies of real banking or delivery company pages. I still don't rely on this as my only line of defence, because these filters are reactive by nature and new fake sites slip through before they're flagged. But it's a noticeable improvement, and it's part of why I keep my browser and operating system updated automatically rather than putting it off.

Credential Stuffing Attacks Happening at a Scale I Didn't Expect

Credential stuffing isn't new, but the scale of it caught me off guard when I looked into it properly. Attackers take huge lists of email and password combinations leaked from old breaches and simply try them against other websites automatically, hoping people reused the same password somewhere else. I checked my own old email addresses against a breach lookup and found combinations from accounts I'd forgotten even existed. That's what finally pushed me to move everything into a password manager with unique, randomly generated passwords for every account, rather than relying on memory or a handful of variations I could actually remember.

Why I Still Think the Basics Matter More Than Any Trend

With all of that said, I try not to lose sight of the fact that most of what protects me day to day isn't cutting edge at all. It's unique passwords, multi-factor authentication set up properly, software that updates itself, and a habit of pausing before I click on anything urgent sounding. The trends I've mentioned here are worth knowing about because they show where attackers and defenders are both heading next, but they build on top of fundamentals rather than replacing them. If I had to recommend one thing to someone who hasn't touched their security setup in years, it still wouldn't be passkeys or AI detection tools, it would be a password manager and a few minutes spent turning on multi-factor authentication on the accounts that matter most. If you want a simple starting point, my free Safety Toolkit walks through exactly that.