Threat reportThreat IntelligenceTL-2026-1614

Forescout 2026H1 Threat Review: 51% Surge in Published Vulnerabilities as AI and Supply-Chain Attacks Drive Threats Across IoT/OT/IoMT Infrastructure

mediumACTIVE

Forescout 2026H1 Threat Review (TL-2026-1614), also tracked as Forescout 2026H1 Threat Review, is a medium-severity tracked intrusion set, first published 2026-07-21. It is linked to a China, Russia, Iran-nexus actor with medium confidence, affects Multiple (aggregate industry report) Programmable Logic Controllers, maps to 23 MITRE ATT&CK techniques (T1005, T1018, T1041), and is covered by 9 detection rules and 25 indicators of compromise.

Severity
MEDIUMAssessed severity
CVEs
0None referenced
Techniques
23MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
25Indicators of compromise

Key facts for TL-2026-1614

Threat ID
TL-2026-1614
Also known as
Forescout 2026H1 Threat Review, Vedere Labs 2026H1 Threat Review
Severity
MEDIUM
Status
ACTIVE
Category
THREAT_INTEL
First published
Last reviewed
Attribution confidence
MEDIUM
Nation-state nexus
China, Russia, Iran
Motivation
FINANCIAL
Target sectors
government administration, technology, financial services, education, health, manufacturing, critical infrastructure
Target regions
Global, North America, Middle East, Europe, israel, ukraine, indonesia
Detection rules
9
Indicators of compromise
25

Malware and tooling in Forescout 2026H1 Threat Review

Malware and tooling: AgendaCrypt, Akira, LockBit, LockBit 5.0, the gentlemen

How Forescout 2026H1 Threat Review works

Forescout Vedere Labs' 2026H1 Threat Review (Jan-Jun 2026) documents 37,137 newly published vulnerabilities (51% YoY increase, >50% high/critical), a 25% rise in ransomware attack claims to 4,544 incidents across 103 active groups, and continued heavy targeting of specialized OT/IoT/IoMT devices, attributing much of the acceleration to AI-assisted vulnerability discovery/exploitation and rising software supply-chain compromise.

Forescout Technologies' research arm, Vedere Labs, published its 2026H1 Threat Review on 21 July 2026, covering the January-June 2026 analysis period ahead of a Black Hat USA presentation scheduled for 5 August 2026. The report analyzed more than 37,000 newly published vulnerabilities, 1,033 tracked threat actors, and thousands of observed cyberattacks.

Vulnerability discovery accelerated sharply: 37,137 new CVEs were published in 1H2026, a 51% year-over-year increase, with more than half rated high or critical severity. Vedere Labs attributes part of this acceleration to threat actors and researchers alike leveraging AI to speed up vulnerability discovery, exploit development, and attack execution -- outpacing defenders' remediation capacity. Separately, 46% of the CVEs added to CISA's Known Exploited Vulnerabilities (KEV) catalog during the period were CVEs originally published before 2026, underscoring that legacy, unpatched vulnerabilities remain an actively exploited attack surface even as new-vulnerability volume grows.

Ransomware activity intensified: Vedere Labs tracked 4,544 ransomware attack claims (a 25% increase over the prior period), averaging roughly 25 attacks per day, attributed to 103 active ransomware groups (a 16% increase in active-group count). Related industry tracking for the surrounding quarters shows a reconsolidating ransomware ecosystem: Qilin, Akira, The Gentlemen, and LockBit together accounted for 41% of all named victims, with the top 10 groups collectively responsible for 71.1% of victims -- the highest concentration since Q1 2024 -- even as the total number of active groups fell from 85 to 71. LockBit relaunched as LockBit 5.0 in September 2025 after the February 2024 Operation Cronos law-enforcement disruption and was extorting new victims within weeks. Akira pursued an economically optimized targeting model focused on consumer goods and industrial manufacturing (sectors with high downtime costs and complex IT/OT environments), accumulating an estimated $244 million in total proceeds. Qilin claimed 701 victims by October 2025, a 280% surge from April 2025, averaging 75 victims/month and becoming the most active ransomware family by Q3 2025.

The report also tracked hacktivist activity: more than 5,700 hacktivist attack claims were observed across 98 Telegram channels, primarily targeting Israel, the United States, Ukraine, Indonesia, and Iran. Nation-state-linked activity remained significant, with actors associated with China, Russia, and Iran accounting for 32% of notable threat-actor activity updates tracked in the period.

On the device/infrastructure side, the report highlights continued and expanding targeting of specialized OT, IoT, and IoMT devices: programmable logic controllers (PLCs), human-machine interfaces (HMIs), automatic tank gauges (ATGs), medical devices, and network infrastructure (routers and firewalls). Routers and switches alone account for roughly one-third (34%) of devices carrying the most critical vulnerabilities, averaging nearly 32 vulnerabilities per device -- reinforcing their position as some of the most exposed and consequential assets on enterprise networks. The report also identifies 11 new device types entering the "riskiest" category across IT/OT/IoT/IoMT compared to prior editions, including serial-to-IP converters, RFID readers, BACnet routers, and medication dispensing systems, reflecting an expanding and diversifying attack surface as more specialized/embedded device classes are connected to IP networks.

Most-targeted sectors by tracked threat actors were government, technology, financial services, education, and healthcare. The report frames software supply-chain compromise as an increasingly sophisticated vector compounding the vulnerability surge, alongside AI-accelerated attacker tradecraft, and calls for defenders to broaden visibility beyond traditional IT endpoints to cover OT/IoT/IoMT and network infrastructure asset classes.

This threat record captures the aggregate industry-trend findings of the report itself (not a single CVE/exploit) for downstream correlation against device-specific and ransomware-specific threats already tracked in the platform.

MITRE ATT&CK techniques used in TL-2026-1614

Collection

T1005 Data from Local System

Discovery

T1018 Remote System Discovery; T1046 Network Service Discovery

Exfiltration

T1041 Exfiltration Over C2 Channel

Execution

T1059 Command and Scripting Interpreter

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Command and Control

T1071 Application Layer Protocol

Initial Access

T1133 External Remote Services; T1190 Exploit Public-Facing Application; T1195 Supply Chain Compromise; T1195.001 Compromise Software Dependencies and Development Tools

Lateral Movement

T1210 Exploitation of Remote Services

Impact

T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery; T1491.002 External Defacement; T1565.001 Stored Data Manipulation

Persistence

T1505.003 Web Shell

Resource Development

T1584 Compromise Infrastructure; T1585.001 Social Media Accounts; T1588.005 Exploits

Reconnaissance

T1595 Active Scanning; T1596 Search Open Technical Databases

defense-impairment

T1685 Disable or Modify Tools

Affected products and versions in Forescout 2026H1 Threat Review

  • Multiple (aggregate industry report) — Programmable Logic Controllers (PLCs)
    Vulnerable versions: various, per-vendor
    Fixed in: N/A - aggregate trend report
  • Multiple (aggregate industry report) — Human-Machine Interfaces (HMIs)
    Vulnerable versions: various, per-vendor
    Fixed in: N/A - aggregate trend report
  • Multiple (aggregate industry report) — Automatic Tank Gauges (ATGs)
    Vulnerable versions: various, per-vendor
    Fixed in: N/A - aggregate trend report
  • Multiple (aggregate industry report) — Medical devices / Internet of Medical Things (IoMT)
    Vulnerable versions: various, per-vendor
    Fixed in: N/A - aggregate trend report
  • Multiple (aggregate industry report) — Routers and firewalls / network infrastructure
    Vulnerable versions: various, per-vendor
    Fixed in: N/A - aggregate trend report
  • Multiple (aggregate industry report) — Emerging riskiest device categories: serial-to-IP converters, RFID readers, BACnet routers, medication dispensing systems
    Vulnerable versions: various, per-vendor
    Fixed in: N/A - aggregate trend report

Remediation for Forescout 2026H1 Threat Review

Patches

  • No single CVE/patch applies to this aggregate report; apply vendor patches per device-specific advisories for PLCs, HMIs, ATGs, medical devices, routers, and firewalls flagged in the underlying Forescout Riskiest Connected Devices dataset

Immediate actions

  • Prioritize patching for pre-2026 CVEs already in the CISA KEV catalog -- 46% of new KEV additions in 1H2026 were legacy CVEs, not newly discovered ones
  • Inventory and segment routers/switches and network infrastructure; they account for 34% of devices carrying the most critical vulnerabilities
  • Extend asset visibility and monitoring beyond traditional IT endpoints to OT, IoT, and IoMT device classes (PLCs, HMIs, ATGs, medical devices)
  • Validate ransomware detection/response playbooks against the top consolidated groups (Qilin, Akira, The Gentlemen, LockBit) given they represent 41% of named victims

Workarounds

  • Where patching specialized OT/IoMT devices is infeasible, apply network segmentation, allow-listing, and monitoring as compensating controls

Longer-term hardening

  • Adopt AI-assisted vulnerability triage and patch prioritization to match the pace of AI-accelerated vulnerability discovery/exploitation by adversaries
  • Harden software supply-chain security (SBOM adoption, dependency provenance verification, code-signing enforcement) given rising supply-chain compromise sophistication
  • Build dedicated OT/IoT/IoMT network segmentation and monitoring programs as newly emerging device categories (serial-to-IP converters, RFID readers, BACnet routers, medication dispensers) enter production networks
  • Establish continuous threat-actor and ransomware-ecosystem tracking to anticipate cartelization/consolidation trends

Timeline of Forescout 2026H1 Threat Review

  • Law enforcement Operation Cronos severely disrupts the original LockBit ransomware operation and infrastructure.
  • Qilin ransomware begins a rapid victim-claim surge, later measured as a 280% increase by October 2025.
  • LockBit relaunches as LockBit 5.0 following the Operation Cronos disruption and begins extorting new victims within weeks.
  • Qilin reaches 701 claimed victims, averaging 75/month, becoming the most active ransomware family by Q3 2025.
  • Industry tracking shows ransomware sector reconsolidating: Qilin, LockBit, and The Gentlemen expand influence; top 10 groups reach 71.1% of victims, highest concentration since Q1 2024, even as total active groups fall from 85 to 71.
  • Start of the January-June 2026 analysis period covered by Forescout Vedere Labs' 2026H1 Threat Review.
  • End of the January-June 2026 analysis period; Vedere Labs has tracked 37,137 newly published vulnerabilities, 4,544 ransomware attack claims, 103 active ransomware groups, 1,033 threat actors, and 5,700+ hacktivist attack claims across 98 Telegram channels.
  • Forescout publishes the 2026H1 Threat Review via press release and syndicated coverage (BusinessWire, IndustrialCyber, CIOInfluence, IntelligentCIO).
  • Forescout Vedere Labs scheduled to present the 2026H1 Threat Review findings at Black Hat USA.

Sources cited for Forescout 2026H1 Threat Review

Detection coverage for TL-2026-1614

As of 2026-07-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1614 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
25 indicators of compromise · Red and above. Compare plans

Further reading

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats