Forescout’s 2026 H1 Threat Review reveals surge in vulnerability discovery amid AI advances and ransomware activity

Forescout’s 2026 H1 Threat Review reveals surge in vulnerability discovery amid AI advances and ransomware activity

Forescout Technologies has released its 2026 H1 Threat Review Report, analysing global cyberthreat trends during the first half of 2026. The report, produced by Forescout Research – Vedere Labs, examines more than 37,000 newly published vulnerabilities, 1,033 tracked threat actors and thousands of cyberattacks observed between January and June 2026.

The report highlights increased vulnerability discovery, ransomware activity and the growing use of Artificial Intelligence by threat actors. Published vulnerabilities increased by 51% year-over-year to 37,137, while ransomware attack claims rose by 25% to 4,544 incidents during the first half of 2026.

Key findings from the report include:

  • Published vulnerabilities increased by 51% year-over-year to 37,137, with more than half rated high or critical severity
  • Forty-six percent of additions to CISA’s Known Exploited Vulnerabilities (KEV) catalogue were CVEs published before 2026, highlighting the continued risk from older vulnerabilities
  • Ransomware attack claims increased by 25% to 4,544 incidents, averaging 25 attacks per day
  • The number of active ransomware groups increased by 16% to 103
  • Threat actors associated with China, Russia and Iran accounted for 32% of threat actors with notable activity updates during 2026 H1
  • Vedere Labs tracked more than 5,700 hacktivist attack claims across 98 Telegram channels

The report also highlights software supply chain compromises, AI-enabled attacks and continued targeting of operational technology (OT), Internet of Things (IoT) and Internet of Medical Things (IoMT) devices.

“AI is dramatically increasing the speed and scale of cyberattacks,” said Daniel dos Santos, VP of Research at Forescout. “In observing attack patterns and threat actor activity, we can see that AI is helping threat actors discover and exploit vulnerabilities faster than security teams can realistically remediate them. At the same time, geopolitical conflicts are fuelling waves of opportunistic and state-aligned cyber activity, with organisations in critical infrastructure sectors increasingly at risk.

In the first half of 2026, the industries targeted by the largest number of tracked threat actors were government, technology, financial services, education and healthcare. Organisations need to understand what is connected to their networks, identify the assets that pose the greatest risk and contain threats before attackers can move laterally into critical systems.”

AI and supply chain attacks reshape the threat landscape

Vedere Labs researchers observed threat actors using AI to accelerate attacks and campaigns, while connected devices including programmable logic controllers (PLCs), human-machine interfaces (HMIs), automatic tank gauges (ATGs), medical devices, routers and firewalls remained targets.

Iranian cyber operations evolve amid ongoing conflict

The report examines changes in the Iranian cybethreat landscape, including activity from state-sponsored actors, hacktivist groups and cybercriminal organisations targeting operational technology and critical infrastructure.

Visibility and segmentation remain defensive priorities

“As attack surfaces continue to expand, security teams can no longer focus exclusively on traditional endpoints,” said Barry Mainz, CEO of Forescout. “Many organisations still have significant blind spots across unmanaged assets and IoT, OT and IoMT devices. Threat actors understand this and are increasingly exploiting those gaps. Security leaders should focus on finding and assessing these devices and using segmentation and automated controls to contain east-west movement, limit blast radius and prevent a single compromise from spreading to more critical systems.”

The findings highlight the importance of identifying vulnerable assets, prioritising risk, strengthening network segmentation and accelerating response across complex environments.

Browse our latest issue

Intelligent CISO

View Magazine Archive