Threat reportThreat IntelligenceTL-2026-1614
Forescout 2026H1 Threat Review: 51% Surge in Published Vulnerabilities as AI and Supply-Chain Attacks Drive Threats Across IoT/OT/IoMT Infrastructure
Forescout 2026H1 Threat Review (TL-2026-1614), also tracked as Forescout 2026H1 Threat Review, is a medium-severity tracked intrusion set, first published 2026-07-21. It is linked to a China, Russia, Iran-nexus actor with medium confidence, affects Multiple (aggregate industry report) Programmable Logic Controllers, maps to 23 MITRE ATT&CK techniques (T1005, T1018, T1041), and is covered by 9 detection rules and 25 indicators of compromise.
- Severity
- MEDIUMAssessed severity
- CVEs
- 0None referenced
- Techniques
- 23MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 25Indicators of compromise
Key facts for TL-2026-1614
- Threat ID
- TL-2026-1614
- Also known as
- Forescout 2026H1 Threat Review, Vedere Labs 2026H1 Threat Review
- Severity
- MEDIUM
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- Last reviewed
- Attribution confidence
- MEDIUM
- Nation-state nexus
- China, Russia, Iran
- Motivation
- FINANCIAL
- Target sectors
- government administration, technology, financial services, education, health, manufacturing, critical infrastructure
- Target regions
- Global, North America, Middle East, Europe, israel, ukraine, indonesia
- Detection rules
- 9
- Indicators of compromise
- 25
Malware and tooling in Forescout 2026H1 Threat Review
Malware and tooling: AgendaCrypt, Akira, LockBit, LockBit 5.0, the gentlemen
How Forescout 2026H1 Threat Review works
Forescout Vedere Labs' 2026H1 Threat Review (Jan-Jun 2026) documents 37,137 newly published vulnerabilities (51% YoY increase, >50% high/critical), a 25% rise in ransomware attack claims to 4,544 incidents across 103 active groups, and continued heavy targeting of specialized OT/IoT/IoMT devices, attributing much of the acceleration to AI-assisted vulnerability discovery/exploitation and rising software supply-chain compromise.
Forescout Technologies' research arm, Vedere Labs, published its 2026H1 Threat Review on 21 July 2026, covering the January-June 2026 analysis period ahead of a Black Hat USA presentation scheduled for 5 August 2026. The report analyzed more than 37,000 newly published vulnerabilities, 1,033 tracked threat actors, and thousands of observed cyberattacks.
Vulnerability discovery accelerated sharply: 37,137 new CVEs were published in 1H2026, a 51% year-over-year increase, with more than half rated high or critical severity. Vedere Labs attributes part of this acceleration to threat actors and researchers alike leveraging AI to speed up vulnerability discovery, exploit development, and attack execution -- outpacing defenders' remediation capacity. Separately, 46% of the CVEs added to CISA's Known Exploited Vulnerabilities (KEV) catalog during the period were CVEs originally published before 2026, underscoring that legacy, unpatched vulnerabilities remain an actively exploited attack surface even as new-vulnerability volume grows.
Ransomware activity intensified: Vedere Labs tracked 4,544 ransomware attack claims (a 25% increase over the prior period), averaging roughly 25 attacks per day, attributed to 103 active ransomware groups (a 16% increase in active-group count). Related industry tracking for the surrounding quarters shows a reconsolidating ransomware ecosystem: Qilin, Akira, The Gentlemen, and LockBit together accounted for 41% of all named victims, with the top 10 groups collectively responsible for 71.1% of victims -- the highest concentration since Q1 2024 -- even as the total number of active groups fell from 85 to 71. LockBit relaunched as LockBit 5.0 in September 2025 after the February 2024 Operation Cronos law-enforcement disruption and was extorting new victims within weeks. Akira pursued an economically optimized targeting model focused on consumer goods and industrial manufacturing (sectors with high downtime costs and complex IT/OT environments), accumulating an estimated $244 million in total proceeds. Qilin claimed 701 victims by October 2025, a 280% surge from April 2025, averaging 75 victims/month and becoming the most active ransomware family by Q3 2025.
The report also tracked hacktivist activity: more than 5,700 hacktivist attack claims were observed across 98 Telegram channels, primarily targeting Israel, the United States, Ukraine, Indonesia, and Iran. Nation-state-linked activity remained significant, with actors associated with China, Russia, and Iran accounting for 32% of notable threat-actor activity updates tracked in the period.
On the device/infrastructure side, the report highlights continued and expanding targeting of specialized OT, IoT, and IoMT devices: programmable logic controllers (PLCs), human-machine interfaces (HMIs), automatic tank gauges (ATGs), medical devices, and network infrastructure (routers and firewalls). Routers and switches alone account for roughly one-third (34%) of devices carrying the most critical vulnerabilities, averaging nearly 32 vulnerabilities per device -- reinforcing their position as some of the most exposed and consequential assets on enterprise networks. The report also identifies 11 new device types entering the "riskiest" category across IT/OT/IoT/IoMT compared to prior editions, including serial-to-IP converters, RFID readers, BACnet routers, and medication dispensing systems, reflecting an expanding and diversifying attack surface as more specialized/embedded device classes are connected to IP networks.
Most-targeted sectors by tracked threat actors were government, technology, financial services, education, and healthcare. The report frames software supply-chain compromise as an increasingly sophisticated vector compounding the vulnerability surge, alongside AI-accelerated attacker tradecraft, and calls for defenders to broaden visibility beyond traditional IT endpoints to cover OT/IoT/IoMT and network infrastructure asset classes.
This threat record captures the aggregate industry-trend findings of the report itself (not a single CVE/exploit) for downstream correlation against device-specific and ransomware-specific threats already tracked in the platform.
MITRE ATT&CK techniques used in TL-2026-1614
Collection
Discovery
T1018 Remote System Discovery; T1046 Network Service Discovery
Exfiltration
T1041 Exfiltration Over C2 Channel
Execution
T1059 Command and Scripting Interpreter
Privilege Escalation
T1068 Exploitation for Privilege Escalation
Command and Control
T1071 Application Layer Protocol
Initial Access
T1133 External Remote Services; T1190 Exploit Public-Facing Application; T1195 Supply Chain Compromise; T1195.001 Compromise Software Dependencies and Development Tools
Lateral Movement
T1210 Exploitation of Remote Services
Impact
T1486 Data Encrypted for Impact; T1490 Inhibit System Recovery; T1491.002 External Defacement; T1565.001 Stored Data Manipulation
Persistence
Resource Development
T1584 Compromise Infrastructure; T1585.001 Social Media Accounts; T1588.005 Exploits
Reconnaissance
T1595 Active Scanning; T1596 Search Open Technical Databases
defense-impairment
Affected products and versions in Forescout 2026H1 Threat Review
- Multiple (aggregate industry report) — Programmable Logic Controllers (PLCs)
Vulnerable versions: various, per-vendor
Fixed in: N/A - aggregate trend report - Multiple (aggregate industry report) — Human-Machine Interfaces (HMIs)
Vulnerable versions: various, per-vendor
Fixed in: N/A - aggregate trend report - Multiple (aggregate industry report) — Automatic Tank Gauges (ATGs)
Vulnerable versions: various, per-vendor
Fixed in: N/A - aggregate trend report - Multiple (aggregate industry report) — Medical devices / Internet of Medical Things (IoMT)
Vulnerable versions: various, per-vendor
Fixed in: N/A - aggregate trend report - Multiple (aggregate industry report) — Routers and firewalls / network infrastructure
Vulnerable versions: various, per-vendor
Fixed in: N/A - aggregate trend report - Multiple (aggregate industry report) — Emerging riskiest device categories: serial-to-IP converters, RFID readers, BACnet routers, medication dispensing systems
Vulnerable versions: various, per-vendor
Fixed in: N/A - aggregate trend report
Remediation for Forescout 2026H1 Threat Review
Patches
- No single CVE/patch applies to this aggregate report; apply vendor patches per device-specific advisories for PLCs, HMIs, ATGs, medical devices, routers, and firewalls flagged in the underlying Forescout Riskiest Connected Devices dataset
Immediate actions
- Prioritize patching for pre-2026 CVEs already in the CISA KEV catalog -- 46% of new KEV additions in 1H2026 were legacy CVEs, not newly discovered ones
- Inventory and segment routers/switches and network infrastructure; they account for 34% of devices carrying the most critical vulnerabilities
- Extend asset visibility and monitoring beyond traditional IT endpoints to OT, IoT, and IoMT device classes (PLCs, HMIs, ATGs, medical devices)
- Validate ransomware detection/response playbooks against the top consolidated groups (Qilin, Akira, The Gentlemen, LockBit) given they represent 41% of named victims
Workarounds
- Where patching specialized OT/IoMT devices is infeasible, apply network segmentation, allow-listing, and monitoring as compensating controls
Longer-term hardening
- Adopt AI-assisted vulnerability triage and patch prioritization to match the pace of AI-accelerated vulnerability discovery/exploitation by adversaries
- Harden software supply-chain security (SBOM adoption, dependency provenance verification, code-signing enforcement) given rising supply-chain compromise sophistication
- Build dedicated OT/IoT/IoMT network segmentation and monitoring programs as newly emerging device categories (serial-to-IP converters, RFID readers, BACnet routers, medication dispensers) enter production networks
- Establish continuous threat-actor and ransomware-ecosystem tracking to anticipate cartelization/consolidation trends
Timeline of Forescout 2026H1 Threat Review
- Law enforcement Operation Cronos severely disrupts the original LockBit ransomware operation and infrastructure.
- Qilin ransomware begins a rapid victim-claim surge, later measured as a 280% increase by October 2025.
- LockBit relaunches as LockBit 5.0 following the Operation Cronos disruption and begins extorting new victims within weeks.
- Qilin reaches 701 claimed victims, averaging 75/month, becoming the most active ransomware family by Q3 2025.
- Industry tracking shows ransomware sector reconsolidating: Qilin, LockBit, and The Gentlemen expand influence; top 10 groups reach 71.1% of victims, highest concentration since Q1 2024, even as total active groups fall from 85 to 71.
- Start of the January-June 2026 analysis period covered by Forescout Vedere Labs' 2026H1 Threat Review.
- End of the January-June 2026 analysis period; Vedere Labs has tracked 37,137 newly published vulnerabilities, 4,544 ransomware attack claims, 103 active ransomware groups, 1,033 threat actors, and 5,700+ hacktivist attack claims across 98 Telegram channels.
- Forescout publishes the 2026H1 Threat Review via press release and syndicated coverage (BusinessWire, IndustrialCyber, CIOInfluence, IntelligentCIO).
- Forescout Vedere Labs scheduled to present the 2026H1 Threat Review findings at Black Hat USA.
Sources cited for Forescout 2026H1 Threat Review
- Forescout's 2026H1 Threat Review Reveals Surge in Vulnerability Discovery Amid Rapid AI Advances, Rising Ransomware Activity, and Continued Targeting of Specialized Devices
- Forescout's 2026 H1 Threat Review reveals surge in vulnerability discovery amid AI advances and ransomware activity
- Forescout reports 51% surge in vulnerabilities as AI, supply-chain attacks drive threats across IoT/OT infrastructure
- Forescout's 2026H1 Threat Review Reveals Surge in Vulnerability Discovery Amid Rapid AI Advances, Rising Ransomware Activity, and Continued Targeting of Specialized Devices (BusinessWire press release)
- Ransomware sector reconsolidating as Qilin, LockBit, and The Gentlemen expand influence in Q1 2026
- 2026 Ransomware Cartelization: Qilin, LockBit and Akira Convergence
- Forescout 2026 Riskiest Connected Devices report warns of rising OT, ICS risk as network infrastructure becomes prime target
- Forescout Research reveals 162 vulnerabilities in connected medical devices, elevating risks to patient data and safety
- Forescout's 2025H1 Threat Review Highlights Surge in Zero-Day Exploits, Nation-Backed Hacktivism, and Healthcare Vulnerabilities
- Forescout Threat Reports Overview
Detection coverage for TL-2026-1614
As of 2026-07-21, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1614 across Splunk SPL, Microsoft KQL and Sigma, covering 25 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.