2026H1 Threat Review

Vulnerabilities, Threat Actors, and Ransomware

Once again, Forescout Research – Vedere Labs widens its mid-year lens with a macro look at the most pressing cybersecurity risks to date. From 4,544 ransomware attacks to a resurgent Iranian threat actor ecosystem to AI reshaping how vulnerabilities are found and exploited, here are the new threat patterns and cyber attack behavior you need to know right now.

Get the research get the newsletter

2026H1 By the Numbers

51%↑

YoY in new vulnerabilities

11%↑

YoY in CISA KEV additions

25%↑

Ransomware attacks

25/day

Avg. ransomware attacks

AI Now In Play: Published Vulnerabilities Increase in Number and Rate

In the first half of 2026, 37,137 vulnerabilities were published, averaging 205 new CVEs per day or 6,189 per month. This represents a 51% increase compared to the same period in 2025. Although the number of CVEs has been constantly growing for the past few years, the rate has accelerated in 2026H1. This is clear in the chart, especially after March. This acceleration is likely connected to new vulnerabilities being found and disclosed with the help of AI.

Key Trends: AI Is Now a Vulnerability Researcher — and a Target

Frontier models are finding vulnerabilities at a pace traditional vulnerability management programs weren’t built for — a trend Forescout linked directly to this year’s 51% jump in published CVEs. At the same time, threat actors are exploiting the AI applications themselves: exposed AI services more than doubled since February to over 940,000, and attackers used a Microsoft Copilot Agent flaw to trigger a zero-click data leak straight out of Excel.

107 Threat Actor Updates, Origins, and Countries Targeted

We track 1,033 threat actors, and 107 had notable activity updates in 2026H1. China, Russia, and Iran continue to have the highest number of threat actors, accounting for 32% combined. The U.S., U.K., Germany, France, and India are the countries most targeted by threat actors.

Key Trends: A Supply Chain Worm Goes Global

TeamPCP spent 2026H1 evolving from stolen access tokens to forged SLSA provenance, hijacking CI/CD pipelines at Aqua Security, TanStack, and Nx Console. A rival worm, PCPJack, emerged to hunt and delete TeamPCP’s own infrastructure. Supply chain compromise is no longer a package-registry problem — it’s a developer-ecosystem problem, now reaching Docker, Kubernetes, IDE extensions, and AI coding assistants.

Deep Dive: Is It Hacktivism or a State-Sponsored Attack?

In today’s geopolitical landscape, this line is increasingly blurred, often by design. Iran’s “Electronic Operations Room” now coordinates more than 60 hacktivist proxy groups aligned with Russian actors like NoName057(16) — while state agencies MOIS and IRGC run parallel espionage, OT sabotage, and ransomware operations under their own subgroups. Identity-shifting threat actors use this ambiguity to confuse attribution and complicate response.

Attacks Targeting Industries

Government, technology, financial services, education, and healthcare are the industries most targeted by threat actors. Education, healthcare, and retail rose in the rankings this period, while telecommunications, energy, and media dropped.

Ransomware Attacks Per Industry

Professional/business services, manufacturing, technology, retail, and healthcare were the most targeted industries by ransomware in 2026H1. Qilin climbed to the top spot from third place last year, while DragonForce jumped from 11th to fourth and LockBit returned to the top 10 on the strength of its new LockBit 5.0 variant.

Dive Into the Research

Stay on top of this year’s trends, so you can know where to focus your cybersecurity and OT defenses. Get all the data and analysis, including:

  • The full Iranian threat actor ecosystem — agencies, groups, capabilities, and infrastructure behind the 2026 Iran War cyber campaign
  • How TeamPCP and rival worm PCPJack are battling for control of the open-source software supply chain
  • New attack patterns like ConsentFix phishing, SSO vishing, and OAuth device-code abuse that bypass MFA entirely
  • Mitigation recommendations for reducing exposure, hardening CI/CD pipelines, and preparing for destructive scenarios

See the Research, Share the Presentation

Vedere Labs shares an overview of the research in a presentation format for you and your security team to use and share. Get all the details of this mid-year threat report, key findings, and our recommendations for mitigating risk.

How Forescout Helps

Discover. Assess. Control. Govern.

Your journey to Universal Zero Trust Network Access starts with the Forescout Vistaro platform™: the only platform for UZTNA powered by agentic AI. Continuously identify, protect, and ensure the compliance of all assets – IT, IoT, IoMT and OT – regardless of location, automatically. Deliver cloud-native network security intelligence boosted by agentic workflows from the pioneer of traditional NAC.

Shift from reactive firefighting to proactive risk management. Get continuous visibility into what’s actually exposed across every connected asset — managed or not, physical or virtual. The result? Priorities managed. Peace of mind.

See the Platform
Demo RequestForescout PlatformTop of Page