AI drives rise in vulnerability disclosures

Widespread adoption of agentic AI in vulnerability research drove a 36% quarter-on-quarter increase in newly disclosed vulnerabilities in Q2 2026, according to a report published today by Beazley Security. Yet the methods used to gain access to organisations changed little.

Vulnerabilities confirmed as actively exploited and added to the Cybersecurity and Infrastructure Security Agency's Known Exploited Vulnerabilities catalogue rose by just 10%. Disclosure volumes had historically remained within a 10% quarter-on-quarter range, but increased 18.5% in Q1 before rising again in Q2.

Beazley Security Labs attributes the surge to the rapid operationalisation of agentic AI across research programmes.

Beazley Security Labs' Q2 2026 report draws on threat intelligence, incident response data and managed detection and response telemetry. It also covers ransomware operators, extortion models, zero-day exploitation and detection trends.

Compromised credentials remained the main route into organisations. They were used against internet-facing VPN and remote desktop services in 67% of ransomware intrusions investigated by Beazley Security, down from 74% in Q1. Law enforcement disruption of infostealer malware has also proved short-lived. Within four days of an Operation ENDGAME takedown, StealC operators released a new version and offered the previous source code for US$60,000. Public ransomware leak-site postings fell slightly to 2,268 but remained almost 60% above Q2 2025. Business email compromise remained common, with attackers increasingly exploiting Microsoft's device code authentication flow to obtain session tokens. Victims complete a legitimate sign-in and satisfy their organisation's MFA requirements, meaning attackers do not need to intercept an authentication code.

Alton Kizziah, CEO of Beazley Security, said: “The headline this quarter is that AI made the security industry's job noisier without making the attacker's job fundamentally different. But AI assisted attacks are gaining in both frequency and effectiveness, and we seem to be watching the attackers learn in real time. As AI adoption in the enterprise increases, and as attackers continue to evolve tactics, clients need to remain vigilant and attend to cyber security basics.

"We also recommend organisations consider AI assessments to monitor what AI capabilities are in use across the organisation, how these tools are being used, and what is needed to improve management and control frameworks.”



Share Story:

YOU MIGHT ALSO LIKE


Resilience Rooted in Reality
In this podcast, CIR speaks to CLDigital’s Tejas Katwala about why organisations must move beyond checklist compliance to build living, data driven resilience. He explains how rethinking governance, risk and compliance, breaking down silos and focusing on value streams can create sustainable, real time resilience that is rooted in the way businesses actually operate today.

Building cyber resilience in a complex threat landscape
Cyber threats are evolving faster than ever. This episode explores how organisations can strengthen defences, embed resilience, and navigate regulatory and human challenges in an increasingly complex digital environment.