Quarterly Threat Report: Second Quarter, 2026

While more than 20,700 new vulnerabilities were disclosed, confirmed exploitation in the wild grew by just 10%. The population of vulnerabilities disclosed grew by a third, but the methods attackers are using to gain initial access barely moved.

Executive Summary

Reported vulnerabilities grew 36% in Q2, but almost none of it changed how attackers got in.

While more than 20,700 new vulnerabilities were disclosed, confirmed exploitation in the wild grew by just 10%. The population of vulnerabilities disclosed grew by a third, but the methods attackers are using to gain initial access barely moved.

That gap is straining the systems built to track vulnerabilities. In response:

  • NIST has stopped enriching every CVE it receives.
  • HackerOne paused new submissions to its Internet Bug Bounty program.
  • Pwn2Own rejected contestant applications for the first time ever.
  • Cisco rebuilt its entire disclosure model, including bundling multiple flaws under a single CVE, a departure from how CVE IDs are supposed to work.

Even Anthropic's Mythos model got swept in, briefly restricted from foreign access by a US export order in June before the restriction was lifted later that same month.

Filtering that volume down to what matters is the point of this report. Beazley Security Labs continually monitors the vulnerability landscape to identify the threats most likely to result in real world compromise, supporting our Exposure Management platform. Of the roughly 5,600 high-risk CVEs disclosed this quarter, Beazley Security Labs issued 21 advisories, up 40% from Q1.

TeamPCP's continued run through the developer supply chain turned noise into impact. In May, the group hijacked TanStack's CI/CD pipeline and pushed malicious packages to NPM. The compromise lasted only a few hours but produced more than 500 million infected downloads before it was caught. TeamPCP also breached GitHub's own internal systems, exposing 3,800 repositories belonging to organizations that had nothing to do with the original compromise. TeamPCP further amplified the threat by publishing the worm's source code and build instructions on BreachForums and launching a cash-prize competition challenging others to cause the most damage with it.

While TeamPCP's own activity slowed by July, supply chain risk in Q2 wasn't limited to one actor. In June, competitive intelligence platform Klue was compromised, once again exposing client Salesforce instances, this time at large enterprises, with some cybersecurity firms among the victims.

Threat actors kept experimenting with AI beyond the supply chain, with uneven results. Sysdig documented JADEPUFFER, which it assessed as the first ransomware campaign run end to end by a large language model. At the other extreme, researchers analyzing Iranian-linked ICS malware found code riddled with logic errors, likely hallucinated by the model that wrote it.

Once again, law enforcement had a real (but temporary) effect on the infostealer market. Operation ENDGAME actions against First VPN, SocGholish, Amadey, and StealC produced a measurable drop in activity starting in May, though no arrests were announced. The StealC operator was back with a new build within four days and put the old source code up for sale at $60,000. LummaStealer, hit hard by ENDGAME last year, is attempting a quiet return under the name Remus.

None of that changed how ransomware gets in: 67% of intrusions started with compromised credentials against exposed VPN and RDP. Malware via SEO-poisoned installers accounted for another 14%.

What did change is what happens after. A growing share of affiliates skipped encryption entirely this quarter, opting for pure data theft and extortion. We saw the pattern emerge from Inc Ransomware, Brain Cipher, and Pear affiliates.

To bypass MFA in BEC cases, attackers increasingly abused Microsoft's device code sign-in flow, a mechanism built for devices like smart TVs where a second device completes the login. The attacker generates a device code and lures the victim into entering it on a real Microsoft sign-in page. Because the login and MFA are genuine, nothing looks wrong to the victim, and the attacker collects the resulting session token.

The front door has not changed. The noise around it has. Read the full report below.

Observations in the Threat Landscape

Agentic AI Leads to Tidal Wave of Reported Vulnerabilities

As discussed in our last Quarterly Threat Report, the sudden arrival of Anthropic’s Mythos model and its cybersecurity capabilities prompted organizations across the vulnerability management ecosystem to reassess how vulnerabilities are discovered, triaged, and reported. Responses to the Mythos’ capabilities escalated throughout Q2, including an order from the US government in June to restrict all foreign access to Mythos due to national security concerns. Anthropic’s efforts to address concerns and widen access resulted in the release of a public version of Mythos named Fable, and in late June the U.S. Department of Commerce lifted restrictions for both models. Fable was made publicly accessible on July 1st.

While Anthropic was able to slowly address concerns and provide access to more organizations and governments, third party researchers did not wait for the dust to settle or invites to Anthropic’s Project Glasswing, and instead matured their usage of AI in security testing programs, using other available models.

Figure 1 – Multiple research organizations leveraging proprietary offensive agentic AI tooling

The initial hype around Mythos may have subsided, but wide-spread adoption of agentic AI enhanced processes by vulnerability researchers and exploit developers is now a fact. We see this tidal wave of newly reported CVE vulnerabilities in Q2 and the resulting stress put on industry systems made to track and manage those vulnerabilities.

With the drastic increase in reported vulnerabilities, vendors are starting to change how they track and report flaws within their products and manage historical bug bounty programs, and even traditional vulnerability discovery contests are scaling back operations. NIST is changing how they process new CVEs because of the huge increase in discovered bugs by research teams empowered with AI. We discuss the nearly 36% increase in disclosed vulnerabilities quarter over quarter below

Threat Actors Leveraging Agentic AI in Cyberattack Chains

While the cybersecurity industry rapidly operationalized the use of agentic AI in vulnerability discovery, threat actors also experimented with ways to incorporate agentic AI into their attack chains.

The main story regarding threat actor usage of AI in Q2 were the continuing ramifications of TeamPCP’s developer supply chain attacks we reported on in Q1. Widespread incidents included compromises of Checkmarx KICS and AST solutions, the release of their “mini shai-hulud” worm variant, and a breach of internal GitHub systems, which further exposed 3.8k code repositories for other organizations. They also briefly partnered with Vect ransomware group, though the arrangement was short-lived as Vect quickly disbanded under other internal community conflicts.

In another notable escalation, TeamPCP publicly released source code for their Shai-Hulud worm on BreachForums and announced a supply chain hacking competition with a cash prize for the most damaging compromise. They released the project with build instructions and configurable settings, allowing other threat actors to adapt and deploy the malware in future supply chain attacks.

Figure 2 – TeamPCP’s cybercriminal “Supply Chain Competition”

Although we observed TeamPCP’s tempo decline by July, the public release of this malware to other threat actors allows the “vibe coded” tooling to create impacts beyond TeamPCP’s own activity.

Cybercriminal groups continue to push the boundaries of agentic AI powered attacks, and the end of Q2 saw the discovery of JADEPUFFER by security firm Sysdig, who assessed it to be the first documented ransomware campaign that was “driven end-to-end by a large language model.” Sysdig analysis of the python malware revealed interesting details: most notably, a large amount of LLM-styled code comments, sub-60-second correction and redeployment of payload code, and behavior indicative of an LLM processing “free-text context presented by the target.” While the likelihood of this attack being fully LLM-driven shows a troubling advancement in threat actor capability to operationalize agentic AI, in this case, at least, the damage was limited by the fact that the targeted system (internet-facing Langflow instances) did not represent a large attack surface globally.

TeamPCP and JADEPUFFER were the biggest but not the only stories involving threat actors leveraging AI in Q2. Iranian-linked threat actors also appeared to use AI to build attack tools. Check Point reported on a campaign by IRGC-affiliated Nimbus Manticore featuring malware payloads with code characteristics indicative of LLM use. Darktrace discovered IoT malware ZionSiphon, built to target water desalinization plants in Israel, while Dragos’ analysis of ZionSiphon’s ICS code revealed it was full of logic errors, likely attributable to LLM hallucination. Beazley Security believes threat actors will continue experimenting with AI across their operations, particularly to accelerate malware and exploit development, automate reconnaissance, and generate attack tooling for technologies outside of existing expertise. ZionSiphon demonstrates that turning AI-generated tooling into an effective attack still requires a level of technical expertise to identify and correct shortcomings.

Infostealer Activity Levels Out After Law Enforcement Takedowns

Beazley Security closely monitors the infostealer ecosystem because despite threat actors’ experimentation with agentic AI, stolen credentials harvested by infostealers frequently serve as the initial access that opens the door to downstream ransomware and other compromises. In addition to tracking unique submission counts of infostealer samples to VirusTotal, we monitor conversations in cybercrime communities to see the interactions between infostealer vendors and their criminal customer base. While we saw a surge of submissions at the end of Q1 following a holiday lull, Q2 signaled a drop in activity starting in May across the major infostealer families we track.

Figure 3 – Unique Infostealer submissions by family to VirusTotal

As we’ve reported in the past, international law enforcement efforts under Operation ENDGAME caused measurable declines in threat activity following major disruptions, and we again attribute the decline observed in Q2 to law enforcement takedowns. Multiple Operation ENDGAME “episodes” and actions took place during the quarter, beginning in May against the criminal service First VPN. While not an infostealer service, First VPN provided a network service that cybercriminals commonly used to hide malicious infrastructure from law enforcement.

The second event was a takedown of cybercriminal infrastructure operated by SocGholish, whose “loader” malware provides a foothold on victim systems to install secondary payloads leading to ransomware and infostealers. Then, at the end of June, that operation expanded to include Amadey (another loader) and StealC, a resurgent infostealer we reported on last quarter. The law enforcement action against StealC was supported by Proofpoint and IBM X-Force, which uncovered vulnerabilities in the infostealer’s infrastructure that were likely leveraged during the takedown. However, the operation did not result in any announced arrests, and the StealC operator remains active on cybercrime forums. Within four days of the public announcement, the operator posted a new version of their infostealer and offered the previous version’s source code for $60,000.

Figure 4 – StealC upgrades post Operation ENDGAME takedown actions

Finally, LummaStealer, which was the focus of major ENDGAME takedown operations last year, appears to be attempting a stealthy return, with the operators rebranding under the name “Remus” while publicly denying any connection to Lumma. Claims that these stealers were unrelated were quickly debunked both by cybersecurity researchers, who identified similarities in code and functionality between the two families, as well as by members of cybercrime communities with insider information linking Remus to Lumma operators.

Figure 5 – Cybercrime forum posts attempting to out Lumma/Remus

As part of this activity, we observed a sharp rise in Remus detections on VirusTotal during the quarter, likely accelerated by law enforcement actions that disrupted several of its largest competitors.

Figure 6 – LummaStealer re-emerging as Remus

Lumma dominated the infostealer ecosystem at its peak last year, and BSL will continue to track this attempted comeback closely.

Vulnerability Trends and Overview

Beazley Security Labs continually monitors for high-impact vulnerabilities as part of our mission to reduce risk in support of our Exposure Management platform. We track and publish advisories for vulnerabilities that we know to be under active exploitation or that our team believes will be exploited by threat actors in the coming days, providing organizations with technical analysis and remediation recommendations.

The vulnerability landscape experienced seismic changes in Q2 in response to widespread adoption of agentic AI into vulnerability research and discovery. It is rare to witness the emergence of a technology that is disruptive enough to cause fundamental changes in an industry, and agentic AI has done exactly that to cybersecurity (and many other industries).

Both total new vulnerabilities and high-risk vulnerabilities surged in Q2 2026. More than 20,700 new vulnerabilities were publicly disclosed, with nearly 5,600 of them considered high risk, meaning they could be exploited remotely with potential to cause harm if unpatched. This is a dramatic increase of over a third in volume for both total new vulnerabilities and those that were high risk from Q1 2026.

Of the approximately 5,600 high-risk vulnerabilities, Beazley Security Labs identified 21 that were severe enough to warrant publishing advisories to our customers in Q2 2026, an alarming 40% increase over the previous quarter.

Additionally, among the approximately 5,600 high-risk vulnerabilities, 44 were confirmed to be actively exploited in the wild, according to the US Cybersecurity and Infrastructure Security Agency (CISA). These “Known Exploited Vulnerabilities” (KEVs) are especially important because they represent real-world threats and impacts.

Vulnerability Trends Q4 2025 Q1 2026 Q2 2026 Change from Q1, 2026
New CVEs published by NIST 12,859 15,243 20,755 +36%
CVEs added to CISA KEV 28 40 44 +10%
Critical 0-Day advisories published by BSL 13 15 21 +40%

*Critical BSL advisories are made publicly available here.

Historically, vulnerability disclosure volume has remained consistent from quarter to quarter, with changes generally staying within a 10% deviation. Since the beginning of 2026, however, growth has accelerated dramatically, rising 18.5% in Q1 and another 36% in Q2. Beazley Security Labs attributes the across-the-board volume increases to the widespread adoption of agentic AI in vulnerability research programs, supported by various public pronouncements from many vendors and security researchers.

For example, NIST, which manages the U.S. National Vulnerability Database and CVE enrichment system, announced a change to their assessment process for new vulnerabilities. In short, they no longer have the capacity to analyze and “enrich” all new CVEs, instead prioritizing a reduced subset for evaluation that are most likely to have the greatest impact. In the private sector, specialized businesses that focus on vulnerability research and exploit development are also showing signs of stress. The Internet Bug Bounty program run by HackerOne paused new submissions, calling out “AI-assisted research” specifically in their announcement post. The international hacking contest Pwn2Own recently had so many AI-assisted submissions to their Berlin event that they had to issue contestant applicant rejections for the first time.

Vendors are also having to shift operations to manage the volume of disclosed vulnerabilities. Cisco, who was given very early access to Mythos, announced this quarter that they are changing their entire vulnerability disclosure model in response to “AI-accelerated vulnerability discovery.” One of the more interesting changes is a move to bundle multiple bugs into single CVEs, which is a departure from the standard use case of CVE IDs.

The good news is that, despite this upheaval, vendors are actively leveraging agentic AI in proactive vulnerability research. Of the 21 high-risk vulnerabilities Beazley Security issued advisories for, many of them were found by AI initiatives directly by vendors themselves.

Looking at the comparatively steady volume of additions to CISA KEV compared to the increase in total reported vulnerabilities, we see evidence that most new vulnerabilities are being found and fixed by the industry, rather than immediately weaponized by financially motivated threat actors. That does not mean threat actor use of zero days has stopped, however. As with every quarter, there were high-profile uses of zero-day exploits in the wild in Q2.

High-Profile Breaches and Zero Day Vulnerabilities Exploited in the Wild

  • ShinyHunters and Oracle PeopleSoft Zero Day: In June, Oracle released an advisory for CVE-2026-35273, a vulnerability in their PeopleSoft product. Immediately after, security researchers at Google published a report detailing the threat actor group ShinyHunters had been using it for several days in a campaign against over 100 targets worldwide, mostly targeting the education sector. ShinyHunters has a long history of high-profile cyberattack campaigns and ties to other infamous groups like Scattered Spider, LAPSUS$, and The Com.
  • cPanel and WHM Zero Day: In April, cPanel published an advisory for CVE-2026-41940, a vulnerability in their flagship webhost control software product. Several well-known large hosting providers quickly confirmed that the flaw was already being exploited in the wild, with some taking the extreme step to block all access to their cPanel deployments until patches could be applied. This software is used by service providers to provision control to hosted websites, so the threat actors using this exploit had immediate unauthorized access to millions of downstream victims.
  • Supply Chain: Klue and TanStack: Supply chain attacks continue to facilitate high-impact compromises of technology vendors, with two major incidents in Q2. In May, TeamPCP compromised TanStack, a tool suite package for web developers. While there were other targets in this campaign, TanStack was particularly damaging because of its use case as a development platform. Though TanStack packages were only compromised for a few hours, it resulted in over 500 million client downloads of infected packages. Then in June, competitive intelligence platform Klue was compromised, once again exposing client Salesforce instances. While the number of affected downstream victims was not as high, the victims themselves were large enterprises, including some cyber security organizations.

Emerging Ransomware Actors and TTPs

Beazley Security works directly with organizations affected by ransomware to provide digital forensics, incident response, and restoration services. Through these engagements, we track activity and surface how ransomware affiliates operate, monitoring for any shifts in attack patterns. The observations below come from what our responders observed in the field during the second quarter of 2026.

Figure 7 – Observed Ransomware Operators in Q2

The emergence of newly branded ransomware operator groups that we saw in Q1 continued into Q2 and coincided with a decrease in independent, or “Lone Wolf,” operators.  While the number of operating groups we observed grew, mature operators like Akira, INC Ransomware, and Qilin continued to be responsible for a high number of victims.

Two new ransomware operators surfacing in Q2 include CMD Organization, who posted around 31 victims, and Deadlock, with an estimated 86 posts throughout the quarter. Another trend that persisted through the first half of year was a gradual shift away from encryption as the primary pressure tactic in ransomware cases. Some operators relied exclusively on extortion, forgoing deployment of a locker in favor of data theft, threatening to post the stolen data through leak sites.

This tradecraft was observed in incidents involving affiliates of Inc Ransomware, Brain Cipher, and Pear. Notably, Inc Ransomware affiliates also used encryption in other intrusions, highlighting a willingness to employ either extortion model.

How Ransomware Attackers Gained Access in Q2

Understanding how ransomware operators gain initial access remains one of the most valuable indicators for mapping and prioritizing defensive efforts against weaknesses resulting in ransomware deployment. While AI-assisted attacks and massive software supply chain risk continued to make headlines in Q2, we continue to see a large number of financially motivated attackers succeed by targeting exposed internet facing services using valid, compromised credentials to gain a foothold and deploy ransomware, with 67% of incidents resulting from compromised credentials used to access VPN and remote desktop services.

Figure 8 – Ransomware Initial Access Category

Exploit-driven initial access tends to rise and fall from quarter to quarter depending on which zero-days can be weaponized by operators. Attacks exploiting internet-facing services and applications this quarter involved vulnerable Oracle platforms such as Peoplesoft, BeyondTrust, and additional fallout from prior FortiBleed-related compromise.

Malware-driven access remained a notable vector, accounting for roughly 14% of ransomware cases our response teams handled. In these cases, users are typically tricked into downloading and executing software disguised as something legitimate, most commonly delivered via SEO-poisoned search results. In one case, a lure was used to install an attacker-controlled MeshCentral agent, or remote monitoring and management (RMM) agent, that became the attacker's foothold. Organizations need to understand what remote management tools are allowed and expected within their environment and strictly audit when remote-tool access occurs. Browser-based protections against malicious SEO-poisoned installers and continued user-awareness training also help disrupt these otherwise effective initial access methods.

Q2 2026 Ransomware Trends

Ransomware incidents remained relatively consistent month over month throughout Q2, with less variation than in Q1. As the trend line below illustrates, a slump in reporting activity from the January holiday season evened out throughout the rest of the half of year.

Figure 9 – Reported Ransomware Incidents

Public ransomware leak-site postings provide insight into affiliate activity each month and serve as an indicator of victims that declined to meet a threat actor’s extortion demands or as a way to exert pressure during “negotiations”

Figure 10 shows public leak-site activity from known operators across the first half of 2026, with the total number of leak posts declining slightly this quarter, from 2,455 posts in Q1 to 2,268.

Figure 10 – Leak-site Posting Activity.

Leak-site postings were still nearly 60% higher than in Q2 of 2025, signaling an elevated level of ransomware post activity year over year.

A majority of posts this quarter originated from a handful of established operators. Qilin, The Gentlemen, and DrangonForce comprised nearly a third of all public Q2 leaks, with Qilin responsible for nearly one in every eight leak site victims.

The sustained leak-site activity indicates many extortion attempts continue to end without a negotiated resolution.

Ransomware Impact Analysis by Sector

Figure 11 – Reported Ransomware Incident by Sector

Healthcare overtook every other sector reporting the most incidents for ransomware, more than doubling from 10% to 21% of all reports this quarter. Professional Services moved in the opposite direction, falling from the top spot in Q1 but remaining in the top three for Q2.

What makes Healthcare’s rise particularly interesting is how the reporting compares to victims showing up on public leak sites. Healthcare victimology ranked 7th on public leak sites we monitored this quarter, but it surfaced as the largest contributor reporting ransomware incidents. Although it cannot be confirmed, the gap could reflect the healthcare industry’s regulatory breach notification requirements driving disclosure, regardless of how impactful the breach may have been or how negotiations work out.

Manufacturing and Professional Services continue to be highly targeted, sitting on sensitive client data, privileged communications, and contracts that are ideal for extortion on the one hand, and susceptible to pressure from damaging business interruption on the other.

Q2 2026 Business Email Compromise (BEC) Trends

BEC activity showed no signs of slowing in Q2 2026, remaining one of the most common incident types Beazley Security handled this quarter. Attackers typically gain their foothold through stolen credentials or hijacked sessions, and then use that access to monitor inboxes, reroute payments, or steal sensitive email correspondence.

The chart below highlights the distribution of reported BEC incidents we observed by sector quarter over quarter.

Figure 12 – Reported BEC Incidents by Sector

Business Services rose to the top, nearly doubling its share and becoming the leading sector by a wide margin. Professional Services slid down our list to fifth place with Financial Institutions also dropping, while Healthcare’s distribution remained the same.

Most BEC attacker tradecraft our responders observed held consistent with what we’ve reported in prior quarters. Threat actors continue to leverage malicious inbox rules in most cases, which presents a detection opportunity for defenders. These rules are commonly deployed to automatically forward or delete messages that help attackers sit inside a mailbox and exfiltrate data without being noticed by the end user.

Attackers continue to create lures and phishing flows that defeat MFA

Most victims from our cases reported that they had put efforts into either fully or partially enforcing MFA within their email environment. Attackers, however, are increasingly using an adversary-in-the-middle (AiTM) technique abusing Microsoft’s device code authentication flow to steal session tokens, and while device code phishing is not new, its evolution and effectiveness were noted this quarter.

The technique exploits device code sign-in flows, which are a legitimate mechanism to allow authentication on input-limited devices such as smart TVs or conference room systems where users authenticate using a second device such as a phone or laptop. Attackers abuse this device flow by initiating a device code request on behalf of the victim. The victim is lured into putting the supplied device code into what looks like a normal sign-in flow, approving the prompt within a genuine Microsoft login page. Because the victim performs a legitimate authentication, including completion of any organizational MFA requirement, the process appears completely normal and does not require the attacker to intercept any MFA codes. The attacker waits for the flow to be finished by the victim and then collects the resulting authenticated session token on success.

This technique traditionally relied on manual tradecraft, requiring an attacker to generate a device code, drop it into a phishing lure, and hope the target would complete the authentication flow before the code’s time expired in 15 minutes, creating a natural limiter. However, Microsoft’s research team documented a campaign this quarter demonstrating how new attack infrastructure can generate a device code dynamically once a victim clicks on a phishing link or lure. The approach maximizes runway by starting the 15-minute timeout period only after the victim has interacted with the phish.

Researchers in the article note that the campaign leverages heavy automation to spin up and monitor for the completed authentication flows, capturing successful authentication tokens instantly. Generative AI further enhanced the campaign by producing the phishing lures tailored toward an individual’s position within an organization.

Beazley Security MDR Trends and Overview

While ransomware and BEC investigations reveal the final stages of intrusion, our MDR telemetry captures the earliest indicators of attacker activity. Every day, our analysts monitor and investigate signals across the environments we protect, giving us a unique view into how attacker tactics, techniques, and intrusion lifecycle evolve from quarter to quarter.

To monitor the activity at scale, we map confirmed incidents to the MITRE ATT&CK framework, tracking adversaries across different phases of an intrusion attempt.

In Q2, Initial Access and Execution detections remained dominant, with identity-based attacks being the front door attackers are still trying to squeeze through. Underneath these attacks, our analysts responded to traditional brute force and password spraying activity, and other account compromise attempts.

We also observed device-code phishing, described earlier in the BEC section of this report, being used in attempt to capture valid authentication sessions, along with other modern AiTM hijacking campaigns designed to defeat MFA.

Figure 13 – MITRE ATT&CK Tactic Distribution.

Other consequential detections this quarter involved hunts to find compromised developer libraries due to fallout from the TanStack supply chain attack discussed earlier, where TeamPCP was able to hijack TanStack’s CI/CD pipeline and publish malicious packages to NPM. These attacks target developers and analysts, bypassing traditional defenses with poisoned package feeds from otherwise trusted software vendors.

The table below summarizes the distribution of confirmed MDR detections across early, middle, and late stages of attacks during the quarter.

Attack Phase Q2 Q1 2026 Descriptions
Early-stage Attacks 41% 45% Credential access attempts, recon, and discovery activity detected and contained
Middle-stage Attacks 41% 44% Attempts to sustain and expand adversarial control into environments contained
Late-stage Attacks 18% 11% High-risk threats contained such as infostealer persistence, data exfiltration, and attempted ransomware deployment

Sources

Executive Summary

Reported vulnerabilities grew 36% in Q2, but almost none of it changed how attackers got in.

While more than 20,700 new vulnerabilities were disclosed, confirmed exploitation in the wild grew by just 10%. The population of vulnerabilities disclosed grew by a third, but the methods attackers are using to gain initial access barely moved.

That gap is straining the systems built to track vulnerabilities. In response:

  • NIST has stopped enriching every CVE it receives.
  • HackerOne paused new submissions to its Internet Bug Bounty program.
  • Pwn2Own rejected contestant applications for the first time ever.
  • Cisco rebuilt its entire disclosure model, including bundling multiple flaws under a single CVE, a departure from how CVE IDs are supposed to work.

Even Anthropic's Mythos model got swept in, briefly restricted from foreign access by a US export order in June before the restriction was lifted later that same month.

Filtering that volume down to what matters is the point of this report. Beazley Security Labs continually monitors the vulnerability landscape to identify the threats most likely to result in real world compromise, supporting our Exposure Management platform. Of the roughly 5,600 high-risk CVEs disclosed this quarter, Beazley Security Labs issued 21 advisories, up 40% from Q1.

TeamPCP's continued run through the developer supply chain turned noise into impact. In May, the group hijacked TanStack's CI/CD pipeline and pushed malicious packages to NPM. The compromise lasted only a few hours but produced more than 500 million infected downloads before it was caught. TeamPCP also breached GitHub's own internal systems, exposing 3,800 repositories belonging to organizations that had nothing to do with the original compromise. TeamPCP further amplified the threat by publishing the worm's source code and build instructions on BreachForums and launching a cash-prize competition challenging others to cause the most damage with it.

While TeamPCP's own activity slowed by July, supply chain risk in Q2 wasn't limited to one actor. In June, competitive intelligence platform Klue was compromised, once again exposing client Salesforce instances, this time at large enterprises, with some cybersecurity firms among the victims.

Threat actors kept experimenting with AI beyond the supply chain, with uneven results. Sysdig documented JADEPUFFER, which it assessed as the first ransomware campaign run end to end by a large language model. At the other extreme, researchers analyzing Iranian-linked ICS malware found code riddled with logic errors, likely hallucinated by the model that wrote it.

Once again, law enforcement had a real (but temporary) effect on the infostealer market. Operation ENDGAME actions against First VPN, SocGholish, Amadey, and StealC produced a measurable drop in activity starting in May, though no arrests were announced. The StealC operator was back with a new build within four days and put the old source code up for sale at $60,000. LummaStealer, hit hard by ENDGAME last year, is attempting a quiet return under the name Remus.

None of that changed how ransomware gets in: 67% of intrusions started with compromised credentials against exposed VPN and RDP. Malware via SEO-poisoned installers accounted for another 14%.

What did change is what happens after. A growing share of affiliates skipped encryption entirely this quarter, opting for pure data theft and extortion. We saw the pattern emerge from Inc Ransomware, Brain Cipher, and Pear affiliates.

To bypass MFA in BEC cases, attackers increasingly abused Microsoft's device code sign-in flow, a mechanism built for devices like smart TVs where a second device completes the login. The attacker generates a device code and lures the victim into entering it on a real Microsoft sign-in page. Because the login and MFA are genuine, nothing looks wrong to the victim, and the attacker collects the resulting session token.

The front door has not changed. The noise around it has. Read the full report below.

Observations in the Threat Landscape

Agentic AI Leads to Tidal Wave of Reported Vulnerabilities

As discussed in our last Quarterly Threat Report, the sudden arrival of Anthropic’s Mythos model and its cybersecurity capabilities prompted organizations across the vulnerability management ecosystem to reassess how vulnerabilities are discovered, triaged, and reported. Responses to the Mythos’ capabilities escalated throughout Q2, including an order from the US government in June to restrict all foreign access to Mythos due to national security concerns. Anthropic’s efforts to address concerns and widen access resulted in the release of a public version of Mythos named Fable, and in late June the U.S. Department of Commerce lifted restrictions for both models. Fable was made publicly accessible on July 1st.

While Anthropic was able to slowly address concerns and provide access to more organizations and governments, third party researchers did not wait for the dust to settle or invites to Anthropic’s Project Glasswing, and instead matured their usage of AI in security testing programs, using other available models.

Figure 1 – Multiple research organizations leveraging proprietary offensive agentic AI tooling

The initial hype around Mythos may have subsided, but wide-spread adoption of agentic AI enhanced processes by vulnerability researchers and exploit developers is now a fact. We see this tidal wave of newly reported CVE vulnerabilities in Q2 and the resulting stress put on industry systems made to track and manage those vulnerabilities.

With the drastic increase in reported vulnerabilities, vendors are starting to change how they track and report flaws within their products and manage historical bug bounty programs, and even traditional vulnerability discovery contests are scaling back operations. NIST is changing how they process new CVEs because of the huge increase in discovered bugs by research teams empowered with AI. We discuss the nearly 36% increase in disclosed vulnerabilities quarter over quarter below

Threat Actors Leveraging Agentic AI in Cyberattack Chains

While the cybersecurity industry rapidly operationalized the use of agentic AI in vulnerability discovery, threat actors also experimented with ways to incorporate agentic AI into their attack chains.

The main story regarding threat actor usage of AI in Q2 were the continuing ramifications of TeamPCP’s developer supply chain attacks we reported on in Q1. Widespread incidents included compromises of Checkmarx KICS and AST solutions, the release of their “mini shai-hulud” worm variant, and a breach of internal GitHub systems, which further exposed 3.8k code repositories for other organizations. They also briefly partnered with Vect ransomware group, though the arrangement was short-lived as Vect quickly disbanded under other internal community conflicts.

In another notable escalation, TeamPCP publicly released source code for their Shai-Hulud worm on BreachForums and announced a supply chain hacking competition with a cash prize for the most damaging compromise. They released the project with build instructions and configurable settings, allowing other threat actors to adapt and deploy the malware in future supply chain attacks.

Figure 2 – TeamPCP’s cybercriminal “Supply Chain Competition”

Although we observed TeamPCP’s tempo decline by July, the public release of this malware to other threat actors allows the “vibe coded” tooling to create impacts beyond TeamPCP’s own activity.

Cybercriminal groups continue to push the boundaries of agentic AI powered attacks, and the end of Q2 saw the discovery of JADEPUFFER by security firm Sysdig, who assessed it to be the first documented ransomware campaign that was “driven end-to-end by a large language model.” Sysdig analysis of the python malware revealed interesting details: most notably, a large amount of LLM-styled code comments, sub-60-second correction and redeployment of payload code, and behavior indicative of an LLM processing “free-text context presented by the target.” While the likelihood of this attack being fully LLM-driven shows a troubling advancement in threat actor capability to operationalize agentic AI, in this case, at least, the damage was limited by the fact that the targeted system (internet-facing Langflow instances) did not represent a large attack surface globally.

TeamPCP and JADEPUFFER were the biggest but not the only stories involving threat actors leveraging AI in Q2. Iranian-linked threat actors also appeared to use AI to build attack tools. Check Point reported on a campaign by IRGC-affiliated Nimbus Manticore featuring malware payloads with code characteristics indicative of LLM use. Darktrace discovered IoT malware ZionSiphon, built to target water desalinization plants in Israel, while Dragos’ analysis of ZionSiphon’s ICS code revealed it was full of logic errors, likely attributable to LLM hallucination. Beazley Security believes threat actors will continue experimenting with AI across their operations, particularly to accelerate malware and exploit development, automate reconnaissance, and generate attack tooling for technologies outside of existing expertise. ZionSiphon demonstrates that turning AI-generated tooling into an effective attack still requires a level of technical expertise to identify and correct shortcomings.

Infostealer Activity Levels Out After Law Enforcement Takedowns

Beazley Security closely monitors the infostealer ecosystem because despite threat actors’ experimentation with agentic AI, stolen credentials harvested by infostealers frequently serve as the initial access that opens the door to downstream ransomware and other compromises. In addition to tracking unique submission counts of infostealer samples to VirusTotal, we monitor conversations in cybercrime communities to see the interactions between infostealer vendors and their criminal customer base. While we saw a surge of submissions at the end of Q1 following a holiday lull, Q2 signaled a drop in activity starting in May across the major infostealer families we track.

Figure 3 – Unique Infostealer submissions by family to VirusTotal

As we’ve reported in the past, international law enforcement efforts under Operation ENDGAME caused measurable declines in threat activity following major disruptions, and we again attribute the decline observed in Q2 to law enforcement takedowns. Multiple Operation ENDGAME “episodes” and actions took place during the quarter, beginning in May against the criminal service First VPN. While not an infostealer service, First VPN provided a network service that cybercriminals commonly used to hide malicious infrastructure from law enforcement.

The second event was a takedown of cybercriminal infrastructure operated by SocGholish, whose “loader” malware provides a foothold on victim systems to install secondary payloads leading to ransomware and infostealers. Then, at the end of June, that operation expanded to include Amadey (another loader) and StealC, a resurgent infostealer we reported on last quarter. The law enforcement action against StealC was supported by Proofpoint and IBM X-Force, which uncovered vulnerabilities in the infostealer’s infrastructure that were likely leveraged during the takedown. However, the operation did not result in any announced arrests, and the StealC operator remains active on cybercrime forums. Within four days of the public announcement, the operator posted a new version of their infostealer and offered the previous version’s source code for $60,000.

Figure 4 – StealC upgrades post Operation ENDGAME takedown actions

Finally, LummaStealer, which was the focus of major ENDGAME takedown operations last year, appears to be attempting a stealthy return, with the operators rebranding under the name “Remus” while publicly denying any connection to Lumma. Claims that these stealers were unrelated were quickly debunked both by cybersecurity researchers, who identified similarities in code and functionality between the two families, as well as by members of cybercrime communities with insider information linking Remus to Lumma operators.

Figure 5 – Cybercrime forum posts attempting to out Lumma/Remus

As part of this activity, we observed a sharp rise in Remus detections on VirusTotal during the quarter, likely accelerated by law enforcement actions that disrupted several of its largest competitors.

Figure 6 – LummaStealer re-emerging as Remus

Lumma dominated the infostealer ecosystem at its peak last year, and BSL will continue to track this attempted comeback closely.

Vulnerability Trends and Overview

Beazley Security Labs continually monitors for high-impact vulnerabilities as part of our mission to reduce risk in support of our Exposure Management platform. We track and publish advisories for vulnerabilities that we know to be under active exploitation or that our team believes will be exploited by threat actors in the coming days, providing organizations with technical analysis and remediation recommendations.

The vulnerability landscape experienced seismic changes in Q2 in response to widespread adoption of agentic AI into vulnerability research and discovery. It is rare to witness the emergence of a technology that is disruptive enough to cause fundamental changes in an industry, and agentic AI has done exactly that to cybersecurity (and many other industries).

Both total new vulnerabilities and high-risk vulnerabilities surged in Q2 2026. More than 20,700 new vulnerabilities were publicly disclosed, with nearly 5,600 of them considered high risk, meaning they could be exploited remotely with potential to cause harm if unpatched. This is a dramatic increase of over a third in volume for both total new vulnerabilities and those that were high risk from Q1 2026.

Of the approximately 5,600 high-risk vulnerabilities, Beazley Security Labs identified 21 that were severe enough to warrant publishing advisories to our customers in Q2 2026, an alarming 40% increase over the previous quarter.

Additionally, among the approximately 5,600 high-risk vulnerabilities, 44 were confirmed to be actively exploited in the wild, according to the US Cybersecurity and Infrastructure Security Agency (CISA). These “Known Exploited Vulnerabilities” (KEVs) are especially important because they represent real-world threats and impacts.

Vulnerability Trends Q4 2025 Q1 2026 Q2 2026 Change from Q1, 2026
New CVEs published by NIST 12,859 15,243 20,755 +36%
CVEs added to CISA KEV 28 40 44 +10%
Critical 0-Day advisories published by BSL 13 15 21 +40%

*Critical BSL advisories are made publicly available here.

Historically, vulnerability disclosure volume has remained consistent from quarter to quarter, with changes generally staying within a 10% deviation. Since the beginning of 2026, however, growth has accelerated dramatically, rising 18.5% in Q1 and another 36% in Q2. Beazley Security Labs attributes the across-the-board volume increases to the widespread adoption of agentic AI in vulnerability research programs, supported by various public pronouncements from many vendors and security researchers.

For example, NIST, which manages the U.S. National Vulnerability Database and CVE enrichment system, announced a change to their assessment process for new vulnerabilities. In short, they no longer have the capacity to analyze and “enrich” all new CVEs, instead prioritizing a reduced subset for evaluation that are most likely to have the greatest impact. In the private sector, specialized businesses that focus on vulnerability research and exploit development are also showing signs of stress. The Internet Bug Bounty program run by HackerOne paused new submissions, calling out “AI-assisted research” specifically in their announcement post. The international hacking contest Pwn2Own recently had so many AI-assisted submissions to their Berlin event that they had to issue contestant applicant rejections for the first time.

Vendors are also having to shift operations to manage the volume of disclosed vulnerabilities. Cisco, who was given very early access to Mythos, announced this quarter that they are changing their entire vulnerability disclosure model in response to “AI-accelerated vulnerability discovery.” One of the more interesting changes is a move to bundle multiple bugs into single CVEs, which is a departure from the standard use case of CVE IDs.

The good news is that, despite this upheaval, vendors are actively leveraging agentic AI in proactive vulnerability research. Of the 21 high-risk vulnerabilities Beazley Security issued advisories for, many of them were found by AI initiatives directly by vendors themselves.

Looking at the comparatively steady volume of additions to CISA KEV compared to the increase in total reported vulnerabilities, we see evidence that most new vulnerabilities are being found and fixed by the industry, rather than immediately weaponized by financially motivated threat actors. That does not mean threat actor use of zero days has stopped, however. As with every quarter, there were high-profile uses of zero-day exploits in the wild in Q2.

High-Profile Breaches and Zero Day Vulnerabilities Exploited in the Wild

  • ShinyHunters and Oracle PeopleSoft Zero Day: In June, Oracle released an advisory for CVE-2026-35273, a vulnerability in their PeopleSoft product. Immediately after, security researchers at Google published a report detailing the threat actor group ShinyHunters had been using it for several days in a campaign against over 100 targets worldwide, mostly targeting the education sector. ShinyHunters has a long history of high-profile cyberattack campaigns and ties to other infamous groups like Scattered Spider, LAPSUS$, and The Com.
  • cPanel and WHM Zero Day: In April, cPanel published an advisory for CVE-2026-41940, a vulnerability in their flagship webhost control software product. Several well-known large hosting providers quickly confirmed that the flaw was already being exploited in the wild, with some taking the extreme step to block all access to their cPanel deployments until patches could be applied. This software is used by service providers to provision control to hosted websites, so the threat actors using this exploit had immediate unauthorized access to millions of downstream victims.
  • Supply Chain: Klue and TanStack: Supply chain attacks continue to facilitate high-impact compromises of technology vendors, with two major incidents in Q2. In May, TeamPCP compromised TanStack, a tool suite package for web developers. While there were other targets in this campaign, TanStack was particularly damaging because of its use case as a development platform. Though TanStack packages were only compromised for a few hours, it resulted in over 500 million client downloads of infected packages. Then in June, competitive intelligence platform Klue was compromised, once again exposing client Salesforce instances. While the number of affected downstream victims was not as high, the victims themselves were large enterprises, including some cyber security organizations.

Emerging Ransomware Actors and TTPs

Beazley Security works directly with organizations affected by ransomware to provide digital forensics, incident response, and restoration services. Through these engagements, we track activity and surface how ransomware affiliates operate, monitoring for any shifts in attack patterns. The observations below come from what our responders observed in the field during the second quarter of 2026.

Figure 7 – Observed Ransomware Operators in Q2

The emergence of newly branded ransomware operator groups that we saw in Q1 continued into Q2 and coincided with a decrease in independent, or “Lone Wolf,” operators.  While the number of operating groups we observed grew, mature operators like Akira, INC Ransomware, and Qilin continued to be responsible for a high number of victims.

Two new ransomware operators surfacing in Q2 include CMD Organization, who posted around 31 victims, and Deadlock, with an estimated 86 posts throughout the quarter. Another trend that persisted through the first half of year was a gradual shift away from encryption as the primary pressure tactic in ransomware cases. Some operators relied exclusively on extortion, forgoing deployment of a locker in favor of data theft, threatening to post the stolen data through leak sites.

This tradecraft was observed in incidents involving affiliates of Inc Ransomware, Brain Cipher, and Pear. Notably, Inc Ransomware affiliates also used encryption in other intrusions, highlighting a willingness to employ either extortion model.

How Ransomware Attackers Gained Access in Q2

Understanding how ransomware operators gain initial access remains one of the most valuable indicators for mapping and prioritizing defensive efforts against weaknesses resulting in ransomware deployment. While AI-assisted attacks and massive software supply chain risk continued to make headlines in Q2, we continue to see a large number of financially motivated attackers succeed by targeting exposed internet facing services using valid, compromised credentials to gain a foothold and deploy ransomware, with 67% of incidents resulting from compromised credentials used to access VPN and remote desktop services.

Figure 8 – Ransomware Initial Access Category

Exploit-driven initial access tends to rise and fall from quarter to quarter depending on which zero-days can be weaponized by operators. Attacks exploiting internet-facing services and applications this quarter involved vulnerable Oracle platforms such as Peoplesoft, BeyondTrust, and additional fallout from prior FortiBleed-related compromise.

Malware-driven access remained a notable vector, accounting for roughly 14% of ransomware cases our response teams handled. In these cases, users are typically tricked into downloading and executing software disguised as something legitimate, most commonly delivered via SEO-poisoned search results. In one case, a lure was used to install an attacker-controlled MeshCentral agent, or remote monitoring and management (RMM) agent, that became the attacker's foothold. Organizations need to understand what remote management tools are allowed and expected within their environment and strictly audit when remote-tool access occurs. Browser-based protections against malicious SEO-poisoned installers and continued user-awareness training also help disrupt these otherwise effective initial access methods.

Q2 2026 Ransomware Trends

Ransomware incidents remained relatively consistent month over month throughout Q2, with less variation than in Q1. As the trend line below illustrates, a slump in reporting activity from the January holiday season evened out throughout the rest of the half of year.

Figure 9 – Reported Ransomware Incidents

Public ransomware leak-site postings provide insight into affiliate activity each month and serve as an indicator of victims that declined to meet a threat actor’s extortion demands or as a way to exert pressure during “negotiations”

Figure 10 shows public leak-site activity from known operators across the first half of 2026, with the total number of leak posts declining slightly this quarter, from 2,455 posts in Q1 to 2,268.

Figure 10 – Leak-site Posting Activity.

Leak-site postings were still nearly 60% higher than in Q2 of 2025, signaling an elevated level of ransomware post activity year over year.

A majority of posts this quarter originated from a handful of established operators. Qilin, The Gentlemen, and DrangonForce comprised nearly a third of all public Q2 leaks, with Qilin responsible for nearly one in every eight leak site victims.

The sustained leak-site activity indicates many extortion attempts continue to end without a negotiated resolution.

Ransomware Impact Analysis by Sector

Figure 11 – Reported Ransomware Incident by Sector

Healthcare overtook every other sector reporting the most incidents for ransomware, more than doubling from 10% to 21% of all reports this quarter. Professional Services moved in the opposite direction, falling from the top spot in Q1 but remaining in the top three for Q2.

What makes Healthcare’s rise particularly interesting is how the reporting compares to victims showing up on public leak sites. Healthcare victimology ranked 7th on public leak sites we monitored this quarter, but it surfaced as the largest contributor reporting ransomware incidents. Although it cannot be confirmed, the gap could reflect the healthcare industry’s regulatory breach notification requirements driving disclosure, regardless of how impactful the breach may have been or how negotiations work out.

Manufacturing and Professional Services continue to be highly targeted, sitting on sensitive client data, privileged communications, and contracts that are ideal for extortion on the one hand, and susceptible to pressure from damaging business interruption on the other.

Q2 2026 Business Email Compromise (BEC) Trends

BEC activity showed no signs of slowing in Q2 2026, remaining one of the most common incident types Beazley Security handled this quarter. Attackers typically gain their foothold through stolen credentials or hijacked sessions, and then use that access to monitor inboxes, reroute payments, or steal sensitive email correspondence.

The chart below highlights the distribution of reported BEC incidents we observed by sector quarter over quarter.

Figure 12 – Reported BEC Incidents by Sector

Business Services rose to the top, nearly doubling its share and becoming the leading sector by a wide margin. Professional Services slid down our list to fifth place with Financial Institutions also dropping, while Healthcare’s distribution remained the same.

Most BEC attacker tradecraft our responders observed held consistent with what we’ve reported in prior quarters. Threat actors continue to leverage malicious inbox rules in most cases, which presents a detection opportunity for defenders. These rules are commonly deployed to automatically forward or delete messages that help attackers sit inside a mailbox and exfiltrate data without being noticed by the end user.

Attackers continue to create lures and phishing flows that defeat MFA

Most victims from our cases reported that they had put efforts into either fully or partially enforcing MFA within their email environment. Attackers, however, are increasingly using an adversary-in-the-middle (AiTM) technique abusing Microsoft’s device code authentication flow to steal session tokens, and while device code phishing is not new, its evolution and effectiveness were noted this quarter.

The technique exploits device code sign-in flows, which are a legitimate mechanism to allow authentication on input-limited devices such as smart TVs or conference room systems where users authenticate using a second device such as a phone or laptop. Attackers abuse this device flow by initiating a device code request on behalf of the victim. The victim is lured into putting the supplied device code into what looks like a normal sign-in flow, approving the prompt within a genuine Microsoft login page. Because the victim performs a legitimate authentication, including completion of any organizational MFA requirement, the process appears completely normal and does not require the attacker to intercept any MFA codes. The attacker waits for the flow to be finished by the victim and then collects the resulting authenticated session token on success.

This technique traditionally relied on manual tradecraft, requiring an attacker to generate a device code, drop it into a phishing lure, and hope the target would complete the authentication flow before the code’s time expired in 15 minutes, creating a natural limiter. However, Microsoft’s research team documented a campaign this quarter demonstrating how new attack infrastructure can generate a device code dynamically once a victim clicks on a phishing link or lure. The approach maximizes runway by starting the 15-minute timeout period only after the victim has interacted with the phish.

Researchers in the article note that the campaign leverages heavy automation to spin up and monitor for the completed authentication flows, capturing successful authentication tokens instantly. Generative AI further enhanced the campaign by producing the phishing lures tailored toward an individual’s position within an organization.

Beazley Security MDR Trends and Overview

While ransomware and BEC investigations reveal the final stages of intrusion, our MDR telemetry captures the earliest indicators of attacker activity. Every day, our analysts monitor and investigate signals across the environments we protect, giving us a unique view into how attacker tactics, techniques, and intrusion lifecycle evolve from quarter to quarter.

To monitor the activity at scale, we map confirmed incidents to the MITRE ATT&CK framework, tracking adversaries across different phases of an intrusion attempt.

In Q2, Initial Access and Execution detections remained dominant, with identity-based attacks being the front door attackers are still trying to squeeze through. Underneath these attacks, our analysts responded to traditional brute force and password spraying activity, and other account compromise attempts.

We also observed device-code phishing, described earlier in the BEC section of this report, being used in attempt to capture valid authentication sessions, along with other modern AiTM hijacking campaigns designed to defeat MFA.

Figure 13 – MITRE ATT&CK Tactic Distribution.

Other consequential detections this quarter involved hunts to find compromised developer libraries due to fallout from the TanStack supply chain attack discussed earlier, where TeamPCP was able to hijack TanStack’s CI/CD pipeline and publish malicious packages to NPM. These attacks target developers and analysts, bypassing traditional defenses with poisoned package feeds from otherwise trusted software vendors.

The table below summarizes the distribution of confirmed MDR detections across early, middle, and late stages of attacks during the quarter.

Attack Phase Q2 Q1 2026 Descriptions
Early-stage Attacks 41% 45% Credential access attempts, recon, and discovery activity detected and contained
Middle-stage Attacks 41% 44% Attempts to sustain and expand adversarial control into environments contained
Late-stage Attacks 18% 11% High-risk threats contained such as infostealer persistence, data exfiltration, and attempted ransomware deployment

Sources

No items found.

Learn more

Purple webinar banner titled 'Top Threats for 2025' with blurred city street and pedestrians in sunlight on the right.

For more on the critical cybersecurity controls you should be using and how they can protect your organization, replay the webinar on demand at:

Top Threats for 2025 (Webinar Replay)

watch webinar

More Insights

View All >

Beazley Security can help protect you

We offer services and solutions to help you prepare and stay resilient in the changing threat landscape. Prepare to learn more about how we can help you

Visit Solutions