2026H1 Threat Review
Vulnerabilities, Threat Actors, and Ransomware
Once again, Forescout Research – Vedere Labs widens its mid-year lens with a macro look at the most pressing cybersecurity risks to date. From 4,544 ransomware attacks to a resurgent Iranian threat actor ecosystem to AI reshaping how vulnerabilities are found and exploited, here are the new threat patterns and cyber attack behavior you need to know right now.
2026H1 By the Numbers
51%↑
YoY in new vulnerabilities
11%↑
YoY in CISA KEV additions
25%↑
Ransomware attacks
25/day
Avg. ransomware attacks
AI Now In Play: Published Vulnerabilities Increase in Number and Rate
In the first half of 2026, 37,137 vulnerabilities were published, averaging 205 new CVEs per day or 6,189 per month. This represents a 51% increase compared to the same period in 2025. Although the number of CVEs has been constantly growing for the past few years, the rate has accelerated in 2026H1. This is clear in the chart, especially after March. This acceleration is likely connected to new vulnerabilities being found and disclosed with the help of AI.
Key Trends: AI Is Now a Vulnerability Researcher — and a Target
Frontier models are finding vulnerabilities at a pace traditional vulnerability management programs weren’t built for — a trend Forescout linked directly to this year’s 51% jump in published CVEs. At the same time, threat actors are exploiting the AI applications themselves: exposed AI services more than doubled since February to over 940,000, and attackers used a Microsoft Copilot Agent flaw to trigger a zero-click data leak straight out of Excel.
107 Threat Actor Updates, Origins, and Countries Targeted
We track 1,033 threat actors, and 107 had notable activity updates in 2026H1. China, Russia, and Iran continue to have the highest number of threat actors, accounting for 32% combined. The U.S., U.K., Germany, France, and India are the countries most targeted by threat actors.
Key Trends: A Supply Chain Worm Goes Global
TeamPCP spent 2026H1 evolving from stolen access tokens to forged SLSA provenance, hijacking CI/CD pipelines at Aqua Security, TanStack, and Nx Console. A rival worm, PCPJack, emerged to hunt and delete TeamPCP’s own infrastructure. Supply chain compromise is no longer a package-registry problem — it’s a developer-ecosystem problem, now reaching Docker, Kubernetes, IDE extensions, and AI coding assistants.
Deep Dive: Is It Hacktivism or a State-Sponsored Attack?
In today’s geopolitical landscape, this line is increasingly blurred, often by design. Iran’s “Electronic Operations Room” now coordinates more than 60 hacktivist proxy groups aligned with Russian actors like NoName057(16) — while state agencies MOIS and IRGC run parallel espionage, OT sabotage, and ransomware operations under their own subgroups. Identity-shifting threat actors use this ambiguity to confuse attribution and complicate response.
Attacks Targeting Industries
Government, technology, financial services, education, and healthcare are the industries most targeted by threat actors. Education, healthcare, and retail rose in the rankings this period, while telecommunications, energy, and media dropped.
Ransomware Attacks Per Industry
Professional/business services, manufacturing, technology, retail, and healthcare were the most targeted industries by ransomware in 2026H1. Qilin climbed to the top spot from third place last year, while DragonForce jumped from 11th to fourth and LockBit returned to the top 10 on the strength of its new LockBit 5.0 variant.
Dive Into the Research
Stay on top of this year’s trends, so you can know where to focus your cybersecurity and OT defenses. Get all the data and analysis, including:
- The full Iranian threat actor ecosystem — agencies, groups, capabilities, and infrastructure behind the 2026 Iran War cyber campaign
- How TeamPCP and rival worm PCPJack are battling for control of the open-source software supply chain
- New attack patterns like ConsentFix phishing, SSO vishing, and OAuth device-code abuse that bypass MFA entirely
- Mitigation recommendations for reducing exposure, hardening CI/CD pipelines, and preparing for destructive scenarios
How Forescout Helps
Discover. Assess. Control. Govern.
Your journey to Universal Zero Trust Network Access starts with the Forescout Vistaro platform™: the only platform for UZTNA powered by agentic AI. Continuously identify, protect, and ensure the compliance of all assets – IT, IoT, IoMT and OT – regardless of location, automatically. Deliver cloud-native network security intelligence boosted by agentic workflows from the pioneer of traditional NAC.
Shift from reactive firefighting to proactive risk management. Get continuous visibility into what’s actually exposed across every connected asset — managed or not, physical or virtual. The result? Priorities managed. Peace of mind.