Insurtech Eye — Insurance Technology News

AI Triggers 36% Surge in Cyber Vulnerabilities as Ransomware Tactics Stagnate

By Lauren Towner · 20 August 2026

Press Release: AI Triggers 36% Surge in Cyber Vulnerabilities as Ransomware Tactics Stagnate | Featured Image by FF News

Beazley Security today releases its Quarterly Threat Report for Q2 2026, finding that the widespread adoption of agentic AI in vulnerability research drove a 36% quarter-over-quarter increase in newly disclosed vulnerabilities while the methods attackers used to breach organizations remained almost entirely unchanged.

Vulnerabilities confirmed as actively exploited and added to the Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities catalog rose only 10% over the same period, a gap that further amplifies an already difficult prioritization challenge facing security teams. Read the full report at: https://beazley.security/insights/quarterly-threat-report-second-quarter-2026.

Disclosure volume has historically moved within a 10% band from quarter to quarter. That pattern broke in 2026, rising 18.5% in Q1 and another 36% in Q2. Beazley Security Labs (BSL) attributes the surge to the rapid operationalization of agentic AI across research programs. The strain of the higher volumes is visible industry-wide: NIST no longer enriches every new CVE; HackerOne's Internet Bug Bounty paused submissions citing AI-assisted research; Pwn2Own issued applicant rejections for the first time; and Cisco restructured its disclosure model outright.

Threat group TeamPCP compromised the TanStack developer package suite in an incident that produced more than 500 million downloads of infected packages within hours, then published its worm's vibe coded source code on a criminal forum alongside a cash-prize competition for the most damaging supply chain compromise. Sysdig separately documented JADEPUFFER, assessed as the first ransomware campaign driven end to end by a large language model.

While dramatic, these headlines did not change how most intrusions actually started. Compromised credentials used against internet-facing VPN and remote desktop services accounted for 67% of ransomware intrusions investigated by Beazley Security. This is down from 74% in Q1 but is still dominant by a wide margin.

Law enforcement efforts to disrupt infostealer families have had success but are proving to be short-lived. Within four days of an Operation ENDGAME takedown, StealC malware authors shipped a new version of the malware and offered the previous source code for $60,000. Public ransomware leak-site postings fell slightly to 2,268 but remained nearly 60% above Q2 2025.

Business email compromise (BEC) remained among the most common incident types, with attackers increasingly abusing Microsoft's device code authentication flow to capture session tokens. Because the victim completes a legitimate sign-in and satisfies any organizational MFA requirement, the attacker never needs to intercept a code.

"The headline this quarter is that AI made the security industry's job noisier without making the attacker's job fundamentally different. But AI assisted attacks are gaining in both frequency and effectiveness, and we seem to be watching the attackers learn in real time. As AI adoption in the enterprise increases, and as attackers continue to evolve tactics, clients need to remain vigilant and attend to cybersecurity basics. We also recommend organizations consider AI assessments to monitor what AI capabilities are in use across the organization, how these tools are being used, and what is needed to improve management and control frameworks." said Alton Kizziah, CEO of Beazley Security.

Companies in this story: NIST, Microsoft, Cisco, Sysdig, Hackerone, Cybersecurity and Infrastructure Security Agency, Beazley Security, TeamPCP

More from News