-

Forescout’s 2026H1 Threat Review Reveals Surge in Vulnerability Discovery Amid Rapid AI Advances, Rising Ransomware Activity, and Continued Targeting of Specialized Devices

Published vulnerabilities increased by 51% year-over-year while ransomware attack claims increased by 25% as threat actors exploit AI, supply chains, and overlooked devices across IT, OT, IoT, and IoMT environments

SAN JOSE, Calif.--(BUSINESS WIRE)--Forescout Technologies, Inc., a cybersecurity company focused on asset intelligence, exposure management, and network security, today released its 2026H1 Threat Review Report, a detailed analysis of global cyber threat trends. Forescout Research – Vedere Labs, Forescout’s threat research team, analyzed more than 37,000 newly published vulnerabilities, 1,033 tracked threat actors, and thousands of cyberattacks observed during the first half of 2026 (January through June 2026). The analysis was supplemented by third-party intelligence to provide a comprehensive view of the global threat landscape. The report finds that rapid advances in AI and the arrival of frontier AI models, combined with growing geopolitical tensions, are reshaping threat activity worldwide and increasing pressure on security teams already struggling to prioritize risk. Published vulnerabilities rose 51% year-over-year to 37,137, ransomware attack claims increased 25% to 4,544 incidents, and 103 ransomware groups were active worldwide during the first half of 2026.

Download the full 2026H1 Threat Review Report and read the accompanying Vedere Labs blog.

Key findings from the report include:

  • Published vulnerabilities increased by 51% year-over-year to 37,137, with more than half rated high or critical severity.
  • 46% of additions to CISA’s Known Exploited Vulnerabilities (KEV) catalog were CVEs published prior to 2026, underscoring how older vulnerabilities represent active risk.
  • Ransomware attack claims grew by 25% to 4,544 incidents, averaging 25 attacks per day.
  • The number of active ransomware groups increased by 16% to 103.
  • Threat actors associated with China, Russia, and Iran collectively accounted for 32% of threat actors with notable activity updates during 2026H1.
  • Vedere Labs tracked more than 5,700 hacktivist attack claims across 98 Telegram channels, primarily targeting Israel, the U.S., Ukraine, Indonesia, and Iran.

The report also highlights increasingly sophisticated software supply chain compromises, growing abuse of AI, and continued exploitation of network infrastructure, operational technology (OT), Internet of Things (IoT), and Internet of Medical Things (IoMT) devices.

“AI is dramatically increasing the speed and scale of cyberattacks,” said Daniel dos Santos, VP of Research at Forescout. “In observing attack patterns and threat actor activity, we can see that AI is helping threat actors discover and exploit vulnerabilities faster than security teams can realistically remediate them. At the same time, geopolitical conflicts are fueling waves of opportunistic and state-aligned cyber activity, with organizations in critical infrastructure sectors increasingly at risk. In the first half of 2026, the industries targeted by the largest number of tracked threat actors were government, technology, financial services, education, and healthcare. Organizations need to understand what is connected to their networks, identify the assets that pose the greatest risk, and contain threats before attackers can move laterally into critical systems.”

AI and Supply Chain Attacks Reshape the Threat Landscape

Among the most significant trends identified in the report were the growing impact of AI-enabled attacks, software supply chain compromises, and attacks on critical infrastructure. Vedere Labs researchers observed threat actors abusing AI to accelerate attacks and campaigns. Attackers also continued to target connected devices such as programmable logic controllers (PLCs), human-machine interfaces (HMIs), automatic tank gauges (ATGs), medical devices, routers, firewalls, and other specialized systems that often receive less security oversight than traditional IT assets.

Iranian Cyber Operations Evolve Amid Ongoing Conflict

Another key finding from the 2026H1 Threat Report is the evolving Iranian cyber threat ecosystem. Researchers describe how state-sponsored actors, hacktivist groups, and cybercriminal organizations are increasingly blurring traditional lines of attribution. The report examines the threat actors, capabilities, and infrastructure behind Iranian cyber operations, including espionage campaigns, influence operations, ransomware activity, and attacks targeting operational technology and critical infrastructure.

Visibility and Segmentation Are Critical Defensive Priorities

“As attack surfaces continue to expand, security teams can no longer focus exclusively on traditional endpoints,” said Barry Mainz, CEO of Forescout. “Many organizations still have significant blind spots across unmanaged assets and IoT, OT, and IoMT devices. Threat actors understand this and are increasingly exploiting those gaps. Security leaders should focus on finding and assessing these devices and using segmentation and automated controls to contain east-west movement, limit blast radius, and prevent a single compromise from spreading to more critical systems.”

The findings reinforce the need for organizations to reduce exposure across complex environments by continuously identifying vulnerable assets, prioritizing risk, strengthening network segmentation, and accelerating response when threats inevitably emerge.

Download the 2026H1 Threat Review Report here, and explore Forescout’s Frontier AI Readiness Resource Center for guidance on how to strengthen your organization’s ability to defend against attacks accelerated by frontier AI models.

The Forescout Research – Vedere Labs team will also present new threat research at Black Hat USA on August 5. The presentation will describe how vulnerabilities in Zero-Touch Provisioning (ZTP) can be chained together to enable large-scale network and supply chain compromise. Attendees can also meet with the Forescout team during the conference.

Frequently Asked Questions

Q: What is the Forescout 2026H1 Threat Review Report?
A: It is Forescout Research – Vedere Labs’ semiannual analysis of global cyber threat trends, based on more than 37,000 newly published vulnerabilities, 1,033 tracked threat actors, and thousands of cyberattacks observed in the first half of 2026.

Q: How many vulnerabilities were published in the first half of 2026?
A: 37,137, a 51% increase year-over-year, with more than half rated as high or critical.

Q: How many ransomware attack claims occurred in H1 2026?
A: 4,544 attack claims, a 25% increase over the same period last year, averaging 25 attack claims per day.

Q: Which countries account for the most cyber threat actors?
A: China, Russia, and Iran together account for 32% of tracked threat actors with notable activity updates during 2026H1.

Q: Where can I get the full report?
A: The 2026H1 Threat Review Report is available for download, along with an accompanying analysis on the Vedere Labs blog.

About Forescout

As AI-driven vulnerability discovery and exploitation accelerate attack velocity to machine speed, Forescout is a foundational cyber defense layer that allows organizations to segment and isolate compromised systems, block lateral movement, and automate response across IT, OT, IoT, and IoMT environments. The Forescout Vistaro™ platform, powered by agentic AI and enhanced with Vedere Labs threat intelligence, delivers a Universal Zero Trust Network Access (UZTNA) architecture that integrates seamlessly with 180+ security and IT products. With Forescout Vistaro, organizations get comprehensive inventory and classification of both managed and unmanaged assets, continuous exposure management, and real-time protection including dynamic network segmentation and automated threat response.

Contacts

Forescout Media Contacts:
RH Strategic for Forescout
forescoutpr@rhstrategic.com

Forescout Communications
press@forescout.com

Forescout Technologies, Inc.


Release Versions

Contacts

Forescout Media Contacts:
RH Strategic for Forescout
forescoutpr@rhstrategic.com

Forescout Communications
press@forescout.com

Social Media Profiles
More News From Forescout Technologies, Inc.

NATO Adds Forescout to Its Information Assurance Product Catalogue (NIAPC)

SAN JOSE, Calif.--(BUSINESS WIRE)--Forescout Technologies Inc., a global cybersecurity leader, today announced it has met NATO’s information assurance requirements and has been included in the NATO Information Assurance Product Catalogue (NIAPC). The NIAPC is a centralized resource for NATO nations and allied organizations to identify trusted cybersecurity solutions that meet stringent operational requirements. Maintained by the NATO Communications and Information Agency (NCIA), the NIAPC provi...

Forescout Launches New Post-Quantum Cryptography (PQC) Dashboards to Analyze Quantum-Exposure Risk Across IT, OT, IoT, and IoMT

SAN JOSE, Calif.--(BUSINESS WIRE)--Forescout Technologies Inc., a global cybersecurity leader, today announced the launch of its Post-Quantum Cryptography (PQC) Readiness and Encryption Hygiene Dashboards. The new dashboards are designed to help organizations identify, prioritize, and manage quantum risk across information technology (IT), operational technology (OT), Internet of Things (IoT), and medical devices (IoMT) environments. As organizations face new pressures from regulators, auditors...

Forescout Emphasizes AI-Driven Security with Forescout Vistaro™ Platform Rename

SAN JOSE, Calif.--(BUSINESS WIRE)--Forescout Technologies Inc., a global leader in cybersecurity, today announced the Forescout 4D Platform™ is now the Forescout Vistaro™ platform, reflecting the company’s AI-driven innovation and long-term vision for security operations. Amid escalating AI-driven threats, the Forescout Vistaro platform heralds proactive, AI-powered cybersecurity control. The platform provides comprehensive visibility and control across managed and unmanaged cyber-physical asse...
Back to Newsroom