RELEReleases

AI research surge exposes 36% more vulnerabilities while old hacks prevail

A 36% jump in disclosed vulnerabilities during the second quarter of 2026 highlights a new era of AI-driven research, yet the reality of cyberattacks remains stubbornly traditional. While security teams struggle with the influx of data, 67% of ransomware intrusions still rely on simple compromised credentials for initial access.

Bio & NewsAugust 18, 2026350 reads0

The sharp rise in vulnerability disclosures marks a departure from historical norms, where fluctuations typically stayed within a 10% margin. Beazley Security Labs attributes this acceleration to the rapid deployment of agentic AI in research programs. The impact is reverberating across the industry: NIST has ceased enriching every new Common Vulnerabilities and Exposures (CVE) entry, while platforms like HackerOne and Pwn2Own have been forced to adjust their submission and acceptance models to cope with the sheer volume of AI-generated research.

Despite the noise, attackers are showing a preference for proven methods over experimental AI tactics. While high-profile incidents like the JADEPUFFER campaign—the first end-to-end LLM-driven ransomware attack—capture headlines, they do not reflect the standard threat landscape. Compromised credentials targeting VPNs and remote desktop services remain the primary vehicle for breaches. Even as law enforcement disrupts infostealer networks, malware authors demonstrate remarkable resilience, often releasing updated versions within days of a takedown.

Identity-based attacks are also becoming more sophisticated. Attackers are increasingly bypassing multifactor authentication by abusing Microsoft’s device code authentication flow to capture session tokens. By forcing victims to complete a legitimate sign-in, attackers gain access without needing to intercept traditional codes. Alton Kizziah, CEO of Beazley Security, warns that while AI has made the industry’s job significantly noisier, the fundamental threat remains tied to basic security failures. He urges organizations to prioritize AI assessments and return to cybersecurity fundamentals to manage the evolving risk.

Comments (0)

Leave a comment

No comments yet. Be the first!