Technadu
Surge in Exploited CVEs and Malware Activity in H1 2026
Article Content
In the first half of 2026, Insikt Group reported 215 actively exploited CVEs, marking a 34% increase from the previous year. Notably, AsyncRAT emerged as the leading malware, with nearly 60,000 unique hashes. The report highlighted a significant rise in NFC-based Android attacks, which surged by 188%. Threat actors continued to exploit known vulnerabilities and legitimate tools, emphasizing the use of remote access trojans (RATs). Microsoft was identified as the vendor with the highest number of exploited vulnerabilities, totaling 40. AI-enabled malware activity became more prominent, although it remained within lower maturity levels. The findings underscore a trend of attackers leveraging established techniques rather than novel methods. Overall, the landscape reflects a growing risk as attackers blend malicious activity with legitimate workflows.
Key Points: • 215 CVEs were actively exploited in H1 2026, a 34% increase from H1 2025. • AsyncRAT led malware activity with around 60,000 unique hashes. • NFC-based Android attacks increased by 188% in early 2026.
Ask AI about this cluster
Answers cite the sources they use
Analyzing cluster data...
Referenced clusters
Something went wrong. Please try again.