Key Findings
- Key trends included increasingly sophisticated supply-chain attacks, threat actors abusing of AI, and the continued exploitation of specialized network, IoT, OT, and IoMT devices.
- Published vulnerabilities rose 51%:
- AI-assisted vulnerability research may be contributing to the acceleration in vulnerability discovery and disclosure, although the available data does not establish how much of the increase is attributable to AI.
- 55% of new vulnerabilities were rated high or critical.
- 54 vulnerabilities were exploited as zero days.
- CISA added 146 CVEs to its KEV catalog, an 11% increase from 132 in 2025H1.
- 46% of the additions involved CVEs published before 2026, demonstrating that older vulnerabilities continue to represent active risk.
- We recorded activity updates for 107 threat actors:
- China-, Russia-, and Iran-linked actors collectively accounted for 32% of the threat actors with activity updates.
- The United States, United Kingdom, Germany, France, and India are the countries most frequently targeted.
- Government, technology, financial services, education, and healthcare were the most frequently targeted sectors.
- Claimed ransomware attacks rose by 25%:
- The 4,544 recorded attacks averaged 757 attacks per month, or 25 per day.
- The number of active ransomware groups rose by 16% from 89 to 103, nearly twice the 8.5% growth recorded between 2024H1 and 2025H1
- 70% of attacks hit the top 10 targeted countries: the U.S. accounted for 44%, followed by Canada (4%), U.K. (4%), Germany (4%), and Italy (3%).
- Top targeted industries are professional/business services, manufacturing, technology, retail and healthcare.
- We tracked more than 5,700 hacktivist attack claims tracked across 98 Telegram channels.
- The most commonly claimed attack types were DDoS, system compromise or disruption, data breaches, and defacement.
- Israel, the United States, Ukraine, Indonesia, and Iran were the most frequently targeted countries.
- Government, technology, manufacturing, education, transport and logistics were the most frequently targeted sectors.
Mitigation Recommendations
- We strongly recommend reviewing the full Mitigation Recommendations section.
- Reduce exposure of management interfaces.
- Increase monitoring for exploitation and credential misuse.
- Prioritize patching and mitigations for internet-facing infrastructure and high-consequence devices.
- Ensure service resilience and investigate disruptive activity as a potential precursor.
- Validate segmentation and control at IT/OT/facilities boundaries.
- Confirm readiness for containment and recovery, including destructive scenarios.
- Control Ethereum / blockchain and Telegram usage.
- Harden CI/CD pipelines.
Our mid-year threat review analyzes the threat landscape from January 1 to June 30, 2026 (2026H1) comparing it with the same period in 2025.
It’s impossible to discuss the current threat landscape without referring to two things: geopolitics and artificial intelligence (AI).
First, geopolitical conflict rarely stays kinetic nowadays. Rising tensions in the Middle East since last year have increased uncertainty for security teams globally and led to a renewed spike in cyber activity. This activity tends to follow a familiar shape:
- An early spike in noise: claims, defacements, low-grade DDoS.
- Then, a smaller number of higher-impact operations: credential-driven intrusion, selective disruption, occasional destructive outcomes.
- Followed by opportunistic crime riding the wave.
While not every organization is directly targeted, periods of escalation bring a rise in opportunistic attacks and politically motivated disruption. These attacks can come from a variety of threat actors, including state-sponsored, hacktivists and cyber criminals.
Secondly, rapid advancements in AI capabilities allow threat actors to more easily find and exploit vulnerabilities, automate parts of campaigns, and scale their operations to target an increasing number of organizations worldwide. We are already seeing signs of traditional vulnerability management programs struggling with the increased pace and volume of vulnerability disclosure. Organizations need support to understand what to prioritize now and in the future.
To help organizations prepare for the increased activity driven by geopolitics and AI, this new report presents statistics and distills key trends about the current threat landscape. Within the larger report, we also delve into the Iranian threat actor ecosystem, highlighting their recent evolution in terms of threat actors, capabilities, and infrastructure in the first half of 2026.
Beyond the Numbers: Supply Chain Attacks, AI Abuse, and Specialized Devices
The full report goes deeper than raw metrics, offering analysis of how threat actor behavior continues to evolve, particularly in relation to supply chain attacks, AI abuse, and compromise of specialized devices.
Supply Chain Attacks
Since September 2025, there has been a wave of supply chain compromise operations primarily executed by TeamPCP and rival actor PCPJack, including the Trivy security scanner, Checkmarx KICS, LiteLLM on PyPI, the Telnyx Python SDK, the TanStack CI/CD pipeline and the Nx Console VS Code extension.
Other significant supply-chain incidents during the period included:
- Vercel OAuth. Attackers reportedly infected a Context.ai employee with Lumma Stealer and stole Google Workspace OAuth tokens. They then abused the trusted third-party OAuth integration to access Vercel systems and harvest unencrypted environment variables containing API, cloud access, and OpenAI credentials.
- Axios npm. A North Korea-linked actor tracked as Sapphire Sleet or UNC1069 reportedly compromised a legitimate maintainer account and published malicious Axios versions that received approximately 600,000 downloads within hours. The packages loaded a concealed plain-crypto-js dependency that deployed a cross-platform remote-access Trojan (RAT).
- node-ipc. Attackers registered an expired domain associated with a dormant maintainer’s account-recovery email and used it to reset the maintainer’s npm password. The malicious package collected environment variables, configuration files and other local data and exfiltrated the resulting archive through fragmented DNS queries.
- Laravel-Lang packages. Attackers rewrote every Git tag across multiple Laravel-Lang PHP packages to load a PHP backdoor and credential stealer targeting cloud, CI/CD, developer, browser, password-manager, VPN and cryptocurrency data.
AI Abuse
Frontier AI models, such as Mythos and GPT-5.5-Cyber, are now finding vulnerabilities at an unprecedented scale. Anthropic’s Mythos identified more than 23,000 potential vulnerabilities across over 1,000 open-source projects, while evaluations by the U.K. AI Security Institute found the generally available GPT-5.5 comparable to Mythos in vulnerability discovery. This made the security implications of AI impossible to ignore during 2026H1. We studied the evolution of AI for vulnerability research and exploit development between 2025 and 2026 and showed that even smaller generally available models can find and exploit real vulnerabilities when supported by effective prompting and tooling. Our research included the discovery of four zero-days on an open-source captive portal software. In May, Google reported what it assessed to be the first known instance of a threat actor using an AI-generated exploit for a zero-day in a real attack.
Attackers are not only using AI to exploit vulnerabilities. They are also exploiting vulnerabilities in AI applications. In 2025, we saw an AI framework vulnerability appear among the most exploited vulnerabilities for the first time: CVE-2025-3248 in Langflow. During 2026H1:
- CISA added four vulnerabilities affecting AI frameworks to its KEV catalog: CVE-2025-34291 and CVE-2026-33017 affecting Langflow, and CVE-2026-42208 and CVE-2026-42271 affecting BerriAI LiteLLM.
- We added two additional vulnerabilities to the Vedere Labs KEV (VL-KEV): CVE-2025-0868 in DocsGPT and CVE-2025-26319 in FlowiseAI.
- CVE-2026-26144 could cause Microsoft Rxcel’s Copilot Agent mode to exfiltrate data through unintended network requests, creating a zero-click information-disclosure pathway.
The growing adoption of AI applications is creating an expanded attack surface that many organizations do not yet fully understand. The risk is not limited to OpenClaw and Langflow. Organizations are increasingly installing local AI models, frameworks, and supporting tools on their own servers, including:
- Local LLM runtimes, such as Ollama, GPT4All, and LocalAI
- Chat / Model management UI, such as AnythingLLM, LM Studio, and Open WebUI
- Image-generation and processing workflows such as ComfyUI
- No-code workflow and agent builders, such as Flowise and n8n
- Autonomous-agent frameworks, such as OpenClaw, AstrBot, Observer AI, and LocalAGI
- Retrieval-augmented generation (RAG) and vector search services, such as Chroma and Qdrant.
A Shodan query identified more than 940,000 exposed AI services at the end of May, distributed as shown below.
Compromise of Specialized Devices and Other Emerging Attack Patterns
Our 2025 Threat Roundup documented growing exploitation of specialized devices, especially network infrastructure, IoT and OT. As expected, this trend continued in 2026H1. Examples of exploited specialized devices targeted in this period include Human Machine Interfaces (HMIs), Programmable Logic Controllers (PLCs), Automatic Tank Gauges (ATGs), Automated Teller Machines (ATMs), serial-to-IP converters, and others exploited by hacktivists and botnets.
Relevant emerging attack patterns discussed in the full report include browser-native ConsentFix, single sign-on (SSO) hijacking via voice phishing, and phishing campaigns using phishing-as-a-service (PhaaS) kits.
Mitigation Recommendations
In a world where geopolitics drives increased threat actor activity and AI enables them to act faster than ever before, organizations should prioritize extending visibility, risk assessment and proactive controls across the increasingly exploited attack surface including network perimeter assets, operational technology, healthcare systems and IoT assets.
For defenders, the practical point is simple: the greatest risk usually comes from known weaknesses and exposed access paths, not novel techniques. In periods of heightened activity, attackers move quickly against internet-facing infrastructure and weak identity controls. Therefore, we recommend the following risk mitigation actions:
- Reduce exposure of management interfaces. Identify internet-reachable management services and device administration interfaces (VPN portals, RDP/SSH, web UIs on edge devices, remote access jump points). Close what can be removed; harden what must remain (source IP allowlists, MFA where supported, dedicated admin paths, and logging).
- Increase monitoring for exploitation and credential misuse. Assume both will occur in parallel: scanning/exploitation of internet-facing infrastructure and credential-based access attempts. Prioritize detection for password spraying, anomalous administrator logins and behavior, new device registrations, VPN authentication anomalies (including unusual geolocation), and configuration changes on edge devices.
- Prioritize patching and mitigations for internet-facing infrastructure and high-consequence devices. Focus first on edge devices, remote management components, and externally exposed services, especially those that provide broad internal reach. Where patching is constrained, apply mitigations including segmentation, admin-plane isolation, access restriction, virtual patching/IPS rules where available, and increased logging and monitoring.
- Ensure service resilience and investigate disruptive activity as a potential precursor. Prepare for DDoS and other disruptive events by validating upstream protections and internal response processes. Treat disruptive activity as an operational trigger to review logs and access changes around internet-facing systems. Do not assume DDoS activity is isolated.
- Validate segmentation and control at IT/OT/facilities boundaries. Review routing and trust paths between corporate IT and OT/building/medical networks and processes. Identify bridge devices (serial-to-IP, BACnet gateways/routers, access control controllers, remote maintenance paths) and verify they are inventoried, restricted, monitored, and properly segmented.
- Confirm readiness for containment and recovery, including destructive scenarios. Ensure you can rapidly scope impact and potential blast radius (what is affected, where it is, what has changed), and isolate compromised segments or device classes. Validate backup integrity and restore procedures and rehearse response steps for disruptive or destructive outcomes (beyond ransomware).
Residual risk associated with novel techniques such as use of blockchain, Telegram and cloud APIs for C2, as well as targeting supply chain and development ecosystems drive the need for additional mitigation actions:
- Control Ethereum / blockchain usage. Detect and block Ethereum RPC and other blockchain communication, especially if originating from non-crypto applications.
- Control Telegram usage. Detect and block Telegram communications, unless there is a documented business need. Focus on the Telegram Bot API pattern (e.g. api.telegram.org/bot/sendMessage), plus related endpoints (file uploads, getUpdates). Where business use is allowed, allowlist sanctioned bots and destinations, log all access, and alert on token exposure in page source.
- Harden CI/CD pipelines
- Enforce least privilege principles by ensuring that CI runners do not have global access to cloud infrastructure or secrets management services.
- Implement strict approval processes for modifications to GitHub actions and pipeline configuration files.
- Use minimal container images without risky tools, such as curl, that can be used to exfiltrate secrets.
- Treat any CI/CD runner, container, or developer machine that installed a poisoned package as fully compromised.
- Rotate all credentials, such as API keys, SSH keys, Kubernetes secrets, and cloud tokens present on those machines.
- Fully isolate affected hosts and re-deploy from known clean states.