Skip to content

AI drives 36% rise in disclosed vulnerabilities as credential attacks remain dominant

Intelligentciso September 4, 2026

Beazley Security has reported a sharp increase in newly disclosed vulnerabilities as agentic AI accelerates security research, although compromised credentials continue to provide the main route into organisations during ransomware attacks.

The number of newly disclosed cybersecurity vulnerabilities increased by 36% during the second quarter of 2026 as agentic AI increasingly reshapes vulnerability research, according to Beazley Security.

The company’s Q2 2026 Quarterly Threat Report found the increase followed an 18.5% rise during the first quarter, breaking with a historical pattern in which disclosure volumes typically fluctuated within 10% from one quarter to the .

However, the increase in disclosed vulnerabilities has not been matched by exploitation. Vulnerabilities confirmed as actively exploited and added to the US Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalogue increased by 10% during Q2.

Beazley Security Labs also issued 40% more critical zero-day advisories to clients than during the quarter. Researchers attributed the broader increase in vulnerability discoveries to the rapid adoption of agentic AI within security research programmes.

Despite increased experimentation with AI by threat actors, more traditional techniques remain responsible for most successful ransomware intrusions investigated by Beazley Security.

Compromised credentials used against Internet-facing VPN and remote desktop services accounted for 67% of ransomware intrusions during Q2. This was down from 74% during the quarter but remained the dominant initial access technique.

Business email compromise also remained among the most common incident types, with researchers observing attackers increasingly targeting Microsoft’s device code authentication process to capture session tokens.

Alton Kizziah, CEO of Beazley Security, said: “The headline this quarter is that AI made the security industry’s job noisier without making the attacker’s job fundamentally different. But AI assisted attacks are gaining in both frequency and effectiveness, and we seem to be watching the attackers learn in real time.”

Ransomware leak-site postings declined slightly during the quarter to 2,268 but remained almost 60% higher than during Q2 2025.

Beazley Security said the findings demonstrate the continuing importance of fundamental security controls alongside preparations for emerging AI-enabled threats.

A Intelligent Global Media Brand