Back Technadu Recorded Future: 215 CVEs Exploited in H1 2026, AsyncRAT Leads Malware Data
Exploitation rises: Insikt Group identified 215 actively exploited CVEs in H1 2026, up almost 35% from 160+ a year earlier.
AsyncRAT leads: AsyncRAT topped Recorded Future’s malware data with approximately 60,000 unique hashes and 44,000 C2 configurations.
NFC threats surge: NFC-based Android attacks increased 188% between January and April 2026.
Threat actors continued to exploit known vulnerabilities, trusted software, and legitimate tools at scale during the first half of 2026, with 215 actively exploited CVEs, a 34% increase from the 161 recorded during H1 2025, according to Recorded Future’s Insikt Group.
The report also highlights the continued prominence of remote access trojans (RATs) , the growing use of AI to augment established attack techniques, and a sharp increase in Android attacks that abuse NFC functionality.
Microsoft Leads Actively Exploited Vulnerabilities
The report identified 82 vulnerabilities involving remote code execution ( RCE ), with 60 combining network accessibility and no authentication requirement. Insikt Group also found that 66 of the 215 vulnerabilities had publicly available proof-of-concept (POC) exploits.
For vendors associated with the largest number of actively exploited vulnerabilities, the following were among the listed:
Microsoft – 40 unique CVEs in H1 2026, up 43% from 28 during the same period last year.
Across all 215 vulnerabilities, 142 were both network-accessible and exploitable without authentication.
AsyncRAT Tops H1 2026 Malware Data
RATs remained prominent in Recorded Future’s malware intelligence. The ranking was as follows:
AsyncRAT – 59,507 unique hashes and 43,549 unique command-and-control (C2) configurations.
Cobalt Strike – 52,567 hashes but just 1,250 unique C2 configurations,
Gh0st RAT – 37,575 hashes and 201 configurations.
Recorded Future reports that AsyncRAT, Cobalt Strike, XWorm, StealC, and REMCOS RAT appeared in the top 10 in both H1 2025 and H1 2026, indicating continued use of established malware families.
AI Adds Speed to Existing Attack Techniques
AI -enabled malware activity became more visible during H1 2026, but Insikt Group said most observed activity remained within Levels 1 through 3 of its AI Malware Maturity Model (AIM3). Rather than fully autonomous malware, attackers primarily used AI for discrete functions such as persistence, user interface interpretation, malware development, and delivery. Examples include the PromptSpy and PixRevolution campaigns .
Ransomware operators also continued using established techniques, including ClickFix -style social engineering and legitimate tools such as s5cmd, PsExec, and AnyDesk.
Android NFC Malware Emerges as Major Threat
Mobile threats also shifted toward payment fraud. Recorded Future identified Android NFC malware as one of the most notable mobile trends, with public reporting showing a 188% increase in NFC-based Android attacks between January and April 2026.
Families including NFCShare and NGate abused NFC functionality to steal payment card information, relay contactless transactions, and facilitate ATM cash-outs . The report also highlights supply-chain activity targeting developer environments, such as TeamPCP’s campaigns .
For defenders, Recorded Future recommends:
prioritizing exposed and unauthenticated vulnerabilities,
strengthening credential and developer-environment controls,
monitoring legitimate tools for abnormal behavior,
applying layered detection rather than relying on individual malware signatures.
An August Malwarebytes report tracked PavinLoader everywhere, as this single malware family is powering ClickFix scams , fake software downloads, and malicious RenPy game campaigns. Among the 2025 campaigns delivering AsyncRAT are hijacked Discord links and fake Booking.com Sites .
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
