More Vulnerabilities, Same Old Door: What Q2’s Cyber Data Means for Risk Managers

New security flaws surged 36% this spring, but the way criminals actually break in — stolen passwords on remote-access systems — barely budged, according to Beazley Security report.
By: | September 3, 2026
Topics: Cyber | Cyber Risks | News
cyber concept
Cybersecurity researchers disclosed more than 20,700 new software vulnerabilities in the second quarter of 2026, a 36% jump largely driven by artificial intelligence tools accelerating bug discovery, yet confirmed real-world attacks grew just 10% and 67% of ransomware cases still traced back to stolen login credentials, according to Beazley Security’s Quarterly Threat Report.

A Flood of New Flaws, But Old Tactics Still Win

The explosion in reported vulnerabilities is straining the systems built to track them. NIST, which manages the U.S. government’s vulnerability database, said it can no longer thoroughly review every new flaw and is now prioritizing only the most impactful ones. HackerOne paused new submissions to its Internet Bug Bounty program, citing AI-assisted research, while the hacking contest Pwn2Own rejected contestant applications for the first time ever due to volume. Cisco went further, overhauling its entire disclosure process and bundling multiple bugs into single tracking numbers.

Despite the noise, attackers’ actual methods have changed little. Beazley Security Labs identified roughly 5,600 high-risk vulnerabilities this quarter and issued 21 advisories for the most dangerous ones — a 40% increase from the prior quarter — but only 44 vulnerabilities were confirmed as actively exploited by the Cybersecurity and Infrastructure Security Agency (CISA), up just 10%. That gap suggests most new flaws are being found and patched by defenders rather than weaponized by criminals.

Criminals also experimented with AI directly. Security firm Sysdig documented what it believes is the first ransomware campaign run end-to-end by a large language model, dubbed JADEPUFFER.

Meanwhile, researchers found Iranian-linked malware targeting Israeli water systems was riddled with logic errors, likely because the AI that wrote the code hallucinated flawed instructions. Beazley Security called this a reminder that AI-generated attack tools still require human expertise to work reliably.

Ransomware and Fraud Risks for the Insurance Industry

The persistence of credential theft as the top ransomware entry point remains the central concern for cyber risk management. Two-thirds of ransomware intrusions in the field started with compromised passwords used against exposed remote-access systems, while malware delivered through poisoned search results accounted for 14%. A supply-chain attack on the TanStack developer platform, carried out by a group called TeamPCP, briefly hijacked software downloads and resulted in more than 500 million infected downloads within hours.

Health care organizations saw ransomware incident reports more than double, from 10% to 21% of all cases, even though the sector ranked just seventh in public leak-site postings. Beazley Security attributes that gap partly to strict regulatory breach-notification rules.

Business email compromise also remains a steady threat, with attackers increasingly abusing a legitimate Microsoft feature called “device code” sign-in, normally used for devices like smart TVs, to steal valid login sessions without ever needing to bypass multifactor authentication directly.

What This Means Going Forward

The Q2 cyber threat data underscores that identity-based attacks, not exotic zero-days, remain the primary underwriting concern. A growing share of ransomware affiliates are also skipping data encryption entirely in favor of pure extortion, a shift observed among Inc Ransomware, Brain Cipher, and Pear-linked attackers.

Law enforcement’s Operation ENDGAME briefly disrupted infostealer networks like StealC and SocGholish in May, but the effect proved temporary as the StealC operator returned with new tools within four days. As the report concludes, the front door attackers use hasn’t changed. Only the surrounding noise has.

Read the full report here.

The R&I Editorial Team can be reached at [email protected].

More from Risk & Insurance