HomeCyber BalkansForescout Report Reveals Increase in AI-Driven Cyber Threats

Forescout Report Reveals Increase in AI-Driven Cyber Threats

Published on

spot_img

Rise in Cyber Threats: Forescout’s 2026 H1 Threat Review Highlights Alarming Trends

According to the newly published Forescout 2026 H1 Threat Review, the cybersecurity landscape is increasingly fraught with dangers, underscored by a staggering 37,000 vulnerabilities identified during the first half of the year. This figure marks a striking 51% increase compared to the same period last year. Many of these vulnerabilities possess high or critical severity labels, signaling an urgent need for immediate attention. In parallel, the report reveals that ransomware attacks surged by 25%, with incidents reaching 4,544—an average of 25 attacks per day.

The comprehensive report, compiled by Forescout Research at Vedere Labs, provides an in-depth analysis of more than 37,000 vulnerabilities, over 1,000 tracked threat actors, and thousands of cyberattacks monitored between January and June 2026. Researchers have linked the accelerated pace of cybersecurity threats to rapid advancements in artificial intelligence (AI) and escalating geopolitical tensions. These factors are exerting significant pressure on security teams that already face challenges in prioritizing risks effectively.

One of the most striking findings of the report indicates that nearly half of all additions to the Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities (KEV) catalog were vulnerabilities published prior to 2026. This highlights a persistent threat emanating from older, unpatched flaws. Furthermore, the number of active ransomware groups rose to 103, with significant contributions from countries such as China, Russia, and Iran, collectively responsible for almost a third of all observed threat activity during the reporting period.

Moreover, the research emphasizes the growing tendency of threat actors to leverage AI technologies to expedite their attacks, in tandem with increasingly sophisticated compromises of software supply chains. Attackers are also honing in on critical areas such as network infrastructure, operational technology (OT), the Internet of Things (IoT), and Internet of Medical Things (IoMT) devices—many of which are not subjected to the same rigorous security measures as traditional endpoints.

Daniel dos Santos, the VP of Research at Forescout, outlined the implications of these developments: "AI is dramatically increasing the speed and scale of cyberattacks." He noted that AI is enabling threat actors to identify and exploit vulnerabilities at a pace surpassing that of security teams’ remediation efforts. Furthermore, geopolitical conflicts are exacerbating the situation, resulting in waves of both opportunistic and state-sponsored cyber activities. Organizations operating within critical infrastructure sectors are becoming increasingly vulnerable, necessitating more robust security measures.

Dos Santos stressed the need for organizations to have a clear understanding of their connected assets in order to better prioritize risks and contain threats before attackers have the opportunity to infiltrate critical systems. This systematic understanding can play a crucial role in safeguarding organizations against the rising tide of cyber threats.

The report further delves into the evolution of Iranian cyber operations, illustrating how the lines between state-sponsored actors, hacktivist groups, and cybercriminal organizations have become increasingly blurred. Researchers noted that these factions are employing a diverse array of tactics, encompassing espionage campaigns, ransomware attacks, and assaults directed at critical infrastructure and operational technology.

Barry Mainz, CEO of Forescout, also emphasized the growing importance of expanding security focus beyond traditional endpoints to encompass unmanaged assets and connected devices. “As attack surfaces continue to expand, security teams can no longer afford to concentrate exclusively on traditional endpoints,” he asserted. The significance of addressing unmanaged assets becomes even more apparent as threat actors continue to exploit the vulnerabilities inherent in such devices.

To mitigate these proliferating risks, the report proposes that organizations should adopt a proactive approach to continuously identify vulnerable assets. In addition, enhancing network segmentation, prioritizing the highest-risk systems, and accelerating response capabilities are critical recommendations to reduce exposure across increasingly complex cyber environments.

In conclusion, the Forescout 2026 H1 Threat Review paints a dire picture of the current cybersecurity landscape, marked by significant vulnerabilities and the rapid evolution of threat tactics facilitated by AI. Organizations must adapt their security strategies and broaden their focus to safeguard their networks effectively against the rising tide of cyber threats. As the landscape continues to evolve, vigilance and proactive measures will be key to ensuring cybersecurity resilience in an increasingly interconnected world.

The insights presented in this report underscore the urgent need for organizations to fortify their defenses and remain alert to the multifaceted nature of modern cyber threats.

Source link

Latest articles

How Zero Networks Targets AI Agents Through Microsegmentation

CEO Highlights Process-Level Controls for Enhanced Security Visibility In a recent discussion, Benny Lakunishok, co-founder...

New CAV3RN Module Substitutes WebSocket C2 with Outlook Calendar Dead Drops

In a notable shift within the landscape of advanced cyberespionage, the Project CAV3RN tooling...

EP 177: Exploring National Public Data

In a gripping episode of Darknet Diaries, the narrative unfolds around a hacker known...

More like this

How Zero Networks Targets AI Agents Through Microsegmentation

CEO Highlights Process-Level Controls for Enhanced Security Visibility In a recent discussion, Benny Lakunishok, co-founder...

New CAV3RN Module Substitutes WebSocket C2 with Outlook Calendar Dead Drops

In a notable shift within the landscape of advanced cyberespionage, the Project CAV3RN tooling...

EP 177: Exploring National Public Data

In a gripping episode of Darknet Diaries, the narrative unfolds around a hacker known...