Key Takeaways
- Disclosed vulnerabilities jumped 36 % in Q2 2026, while confirmed exploitations rose only 10 %, widening the gap between volume and real‑world risk.
- Agentic AI is the primary driver of the surge in vulnerability discovery, overwhelming traditional disclosure pipelines (NIST, HackerOne, Pwn2Own, Cisco).
- Despite AI‑enhanced research, attackers still rely overwhelmingly on compromised credentials, which accounted for 67 % of ransomware intrusions investigated by Beazley Security.
- High‑profile AI‑assisted attacks (e.g., TeamPCP’s supply‑chain worm, JADEPUFFER ransomware) demonstrate that threat actors are experimenting with large‑language models, but these remain the exception rather than the norm.
- Law‑enforcement takedowns of infostealer families yield short‑lived gains; malware authors quickly re‑release updated versions.
- Identity‑focused tactics are evolving past MFA, with attackers abusing legitimate device‑code flows to harvest session tokens in BEC campaigns.
- Beazley Security urges organizations to maintain cybersecurity fundamentals, conduct AI‑capability assessments, and adapt controls as enterprise AI adoption grows.
Overview of Q2 2026 Threat Landscape
Beazley Security’s Q2 2026 Quarterly Threat Report reveals a stark divergence between the speed at which new weaknesses are being uncovered and the pace at which attackers are actually exploiting them. The report, compiled from global threat intelligence, incident‑response data, and MDR telemetry, shows a 36 % quarter‑over‑quarter increase in disclosed vulnerabilities, while only a 10 % rise was observed in confirmed exploits added to CISA’s Known Exploited Vulnerabilities catalog. This widening gap underscores the growing difficulty security teams face in prioritizing remediation efforts amid an avalanche of alerts.
Agentic AI Driving Surge in Vulnerability Disclosures
The primary catalyst for the disclosure explosion is the rapid operationalization of agentic AI across vulnerability‑research programs. Historically, vulnerability counts have fluctuated within a narrow ±10 % band quarter to quarter; however, Q1 2026 already saw an 18.5 % increase, followed by the 36 % jump in Q2. Beazley Security Labs attributes this trend to AI agents that autonomously scan codebases, generate proof‑of‑concept exploits, and submit findings at scale. The strain is evident industry‑wide: NIST no longer enriches every new CVE, HackerOne’s Internet Bug Bounty paused submissions citing AI‑assisted research, Pwn2Own issued applicant rejections for the first time, and Cisco overhauled its disclosure model to cope with the influx.
Disparity Between Disclosed Vulnerabilities and Exploited Ones
Although the volume of disclosed weaknesses is soaring, the proportion that moves from theory to active exploitation remains modest. Only a 10 % increase in exploited vulnerabilities was recorded, suggesting that many newly identified flaws are either low‑impact, require complex chaining, or are quickly patched before threat actors can weaponize them. This disparity amplifies the prioritization challenge for security operations centers, which must sift through a growing backlog of alerts while focusing limited resources on the subset that truly poses imminent risk.
Continued Dominance of Credential‑Based Attacks
Even as AI reshapes discovery, the mechanics of initial compromise have remained stubbornly consistent. Compromised credentials used against internet‑facing VPN and remote‑desktop services accounted for 67 % of ransomware intrusions investigated by Beazley Security in Q2 2026—down slightly from 74 % in Q1 but still the leading vector by a wide margin. This statistic reinforces the enduring effectiveness of credential theft, password spraying, and brute‑force tactics, highlighting that foundational controls such as multi‑factor authentication (MFA), credential hygiene, and privileged‑access management remain critical.
AI‑Assisted Attack Demonstrations
The quarter also featured several headline‑grabbing examples of AI‑enhanced offensives. Threat group TeamPCP compromised the TanStack developer package suite, distributing over 500 million infected downloads within hours and then publishing the worm’s “vibe‑coded” source code on a criminal forum alongside a cash‑prize competition for the most damaging supply‑chain compromise. Separately, Sysdig identified JADEPUFFER, assessed as the first ransomware campaign driven end‑to‑end by a large language model. While these incidents illustrate attackers’ experimentation with generative AI, they remain outliers; the majority of intrusions still rely on traditional tactics.
Law‑Enforcement Response and Infostealer Resilience
Law‑enforcement efforts to disrupt infostealer families have achieved measurable success, yet the gains prove fleeting. Within four days of an Operation ENDGAME takedown, the authors of StealC malware released a new version and offered the previous source code for $60,000 on underground markets. Public ransomware leak‑site postings dipped slightly to 2,268 but remained nearly 60 % above Q2 2025 levels, indicating that the overall extortion ecosystem continues to expand despite intermittent disruptions.
Evolution of Identity Attacks Beyond MFA
Identity‑focused attacks are adapting to circumvent even robust MFA implementations. Business email compromise (BEC) remained among the most common incident types, with attackers increasingly exploiting Microsoft’s device‑code authentication flow to capture session tokens. Because the victim completes a legitimate sign‑in and satisfies any organizational MFA requirement, the attacker never needs to intercept a code, effectively bypassing the second factor. This trend underscores the need for continuous monitoring of authentication logs, conditional‑access policies, and user‑behavior analytics to detect anomalous token usage.
Leadership Insight and Recommendations
Alton Kizziah, CEO of Beazley Security, summed up the quarter’s dynamics: “The headline this quarter is that AI made the security industry’s job noisier without making the attacker’s job fundamentally different. But AI assisted attacks are gaining in both frequency and effectiveness, and we seem to be watching the attackers learn in real time. As AI adoption in the enterprise increases, and as attackers continue to evolve tactics, clients need to remain vigilant and attend to cybersecurity basics. We also recommend organizations consider AI assessments to monitor what AI capabilities are in use across the organization, how these tools are being used, and what is needed to improve management and control frameworks.” His advice highlights the dual imperative of strengthening foundational defenses while gaining visibility into emerging AI‑related risks.
About Beazley Security Labs and Company Overview
Beazley Security Labs synthesizes global threat intelligence, incident‑response data, and MDR telemetry to identify trends shaping the cyber risk landscape. The Q2 2026 Threat Report covers ransomware operators, extortion models, high‑profile zero‑day exploitation, and MDR detection trends, offering actionable insights for security leaders. Beazley Security itself is a global cybersecurity services firm providing managed detection and response, incident response, exposure management, and advisory services to organizations of all sizes. Leveraging decades of protection, detection, response, and recovery expertise alongside the actuarial precision and risk‑mitigation capabilities of its parent company, Beazley, the firm helps clients navigate an increasingly complex threat environment. The full Q2 2026 Quarterly Threat Report is available at https://beazley.security/insights/quarterly-threat-report-second-quarter-2026.

