Those lines belong to Polonius, the meddling old counselor in Hamlet, sending his son off to France with a satchel of fatherly advice: buy the best clothes you can afford, because people will judge you by what you wear. For most of history that worked in both directions. A uniform, a badge, a logo on the side of a van told you who you were dealing with before anyone said a word. Our industry was built on the same assumption. We learned what malicious code looked like, wrote its appearance down as a signature, and turned away anything wearing the wrong clothes.
In the first half of 2026, the apparel stopped proclaiming anything. In Q2, 95.72% of the malware we blocked on endpoints appeared on exactly one machine. One victim, one payload, one costume, never worn again. That is not a spray campaign; it is a tailor’s shop. Malware-as-a-service builders and large language models have made a hand-stitched disguise cheaper to produce than an off-the-rack one, and threat actors are ordering one per victim.
Here is the twist, though. All that craftsmanship went into the disguise, not the break-in. The median vulnerability among our 50 most voluminous IPS signatures was first disclosed in 2014, and not one of them targets a flaw from 2025 or 2026. So picture our adversary: a figure in a bespoke suit no one has ever seen before, walking up to your building and trying a key that was cut twelve years ago. Distressingly often, the key still turns.

