Forescout’ s 2026 H1 Threat Review reveals surge in vulnerability discovery amid AI advances and ransomware activity
SANS report highlights growing AI governance gap in cybersecurity
CISO news
Forescout’ s 2026 H1 Threat Review reveals surge in vulnerability discovery amid AI advances and ransomware activity
F orescout Technologies has released its 2026 H1 Threat Review Report, analysing global cyberthreat trends during the first half of 2026.
Published vulnerabilities increased by 51 % year-over-year to 37,137, while ransomware attack claims rose by 25 % to 4,544 incidents during the first half of 2026.
The report, produced by Forescout Research – Vedere Labs, examines more than 37,000 newly published vulnerabilities, 1,033 tracked threat actors and thousands of cyberattacks observed between January and June 2026.
The report highlights increased vulnerability discovery, ransomware activity and the growing use of Artificial Intelligence by threat actors.
Key findings from the report include:
• Published vulnerabilities increased by 51 % year-over-year to 37,137, with more than half rated high or critical severity
• Forty-six percent of additions to CISA’ s Known Exploited Vulnerabilities( KEV) catalogue were CVEs published before 2026
• Ransomware attack claims increased by 25 % to 4,544 incidents, averaging 25 attacks per day
• The number of active ransomware groups increased by 16 % to 103
• Threat actors associated with China, Russia and Iran accounted for 32 % of threat actors with notable activity updates during 2026 H1
“ AI is dramatically increasing the speed and scale of cyberattacks,” said Daniel dos Santos, VP of Research at Forescout.“ In observing attack patterns and threat actor activity, we can see that AI is helping threat actors discover and exploit vulnerabilities faster than security teams can realistically remediate them.”
SANS report highlights growing AI governance gap in cybersecurity
ANS Institute has released its 2026 SANS AI Survey Insights report, highlighting rapid growth in the use of Artificial
S
Intelligence by cybersecurity teams alongside increasing concerns over governance, skills and operational readiness. confirmed or suspected AI-enabled cyberattacks during the past 12 months. In addition, 95 % of respondents believe threat actors are using AI as part of their operations.
Based on responses from 536 cybersecurity and IT practitioners and 57 senior security leaders, including CISOs, the report found that 78 % of organisations now use AI in cybersecurity, up from 50 % in 2025. However, only 27 % of respondents described their AI deployments as mature production environments.
The research also found that 76 % of security teams now have responsibility for governing enterprise AI, yet more than half said they lack formal audit frameworks to support those responsibilities. At the same time, 63 % reported significant shortcomings in AI-driven threat detection and response, compared with 45 % a year earlier.
“ For two years now, we’ ve asked security teams where they actually stand with AI,” said Matt Bromiley, SANS Certified Instructor and author of the report.“ Both years, the honest answer has been some version of moving fast and working it out as we go. What’ s changed in 2026 is how much weight is now sitting behind that answer.”
The report also found that AI use in red teaming increased from 33 % in 2025 to 61 % this year, while 78 % of organisations reported
Matt Bromiley, SANS Certified Instructor
12 WWW. INTELLIGENTCISO. COM