Intelligent CISO Issue 102 | Page 10

SonicWall finds education faces highest per-device cyberattack intensity of any sector
AI drives 36 % rise in disclosed vulnerabilities as credential attacks remain dominant

CISO news

SonicWall finds education faces highest per-device cyberattack intensity of any sector

ducation experienced the highest per-device cyberattack intensity of any industry tracked by SonicWall during the

E first half of 2026, according to new research highlighting the security challenges facing schools and universities.

The 2026 Education Protect Brief found that education environments recorded 81,879 intrusion prevention system( IPS) hits per device during the six-month period.
“ Education endpoints endure the heaviest per-device attack pressure in our entire dataset. Unlocked network doors remain the operating reality, and threat actors are actively taking advantage.”
One of the biggest sources of activity involved Voice over Internet Protocol( VoIP) infrastructure. SIPVicious exploitation generated 90 million combined hits and accounted for 50.5 % of all IPS events recorded across the education sector.
SonicWall attributed much of the exposure to the structure of education networks, which frequently need to accommodate studentowned devices, faculty research systems, public-facing services, third-party learning platforms and administrative databases.
Michael Crean, SVP of Managed Services at SonicWall, said:“ Education has the most exposed attack surface of any industry we track, and the data shows attackers know it.
Malware also remained a significant concern, with education recording 16,242 malware hits per device – nearly 3.5 times the rate observed in retail.
Researchers also identified evidence of attacks targeting older vulnerabilities. A command injection vulnerability affecting Hikvision IP cameras, first disclosed in 2021, was detected on 605 devices across 28 % of education networks in SonicWall’ s dataset.

AI drives 36 % rise in disclosed vulnerabilities as credential attacks remain dominant

he number of newly disclosed cybersecurity vulnerabilities increased by 36 % during the second quarter of 2026 as

T agentic AI increasingly reshapes vulnerability research, according to Beazley Security.

The company’ s Q2 2026 Quarterly Threat Report found the increase followed an 18.5 % rise during the first quarter, breaking with a historical pattern in which disclosure volumes typically fluctuated within 10 % from one quarter to the next.
However, the increase in disclosed vulnerabilities has not been matched by exploitation. Vulnerabilities confirmed as actively exploited and added to the US Cybersecurity and Infrastructure Security Agency’ s Known Exploited Vulnerabilities catalogue increased by 10 % during Q2.
Beazley Security Labs also issued 40 % more critical zero-day advisories to clients than during the previous quarter. Researchers attributed the broader increase in vulnerability discoveries to the rapid adoption of agentic AI within security research programmes.
Despite increased experimentation with AI by threat actors, more traditional techniques remain responsible for most successful ransomware intrusions investigated by Beazley Security.
Alton Kizziah, CEO of Beazley Security, said:“ The headline this quarter is that AI made the security industry’ s job noisier without making the attacker’ s job fundamentally different. But AI assisted attacks are gaining in both frequency and effectiveness, and we seem to be watching the attackers learn in real time.”
10 WWW. INTELLIGENTCISO. COM