Forescout 2026H1 Threat Review: 51% Surge in Published Vulnerabilities as AI and Supply-Chain Attacks Drive Threats Across IoT/OT/IoMT Infrastructure — Threadlinqs Intelligence
As of 2026-07-21, Forescout 2026H1 Threat Review: 51% Surge in Published Vulnerabilities as AI and Supply-Chain Attacks Drive Threats Across IoT/OT/IoMT Infrastructure is a medium-severity threat intel threat attributed to Multiple (ransomware groups (China, Russia, Iran), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 25 indicators of compromise.
Threat ID: TL-2026-1614 · Severity: MEDIUM · Status: ACTIVE · Category: THREAT_INTEL
Attribution: Multiple (ransomware groups · China, Russia, Iran · FINANCIAL
Forescout Vedere Labs' 2026H1 Threat Review (Jan-Jun 2026) documents 37,137 newly published vulnerabilities (51% YoY increase, >50% high/critical), a 25% rise in ransomware attack claims to 4,544
Forescout Technologies' research arm, Vedere Labs, published its 2026H1 Threat Review on 21 July 2026, covering the January-June 2026 analysis period ahead of a Black Hat USA presentation scheduled for 5 August 2026. The report analyzed more than 37,000 newly published vulnerabilities, 1,033 tracked threat actors, and thousands of observed cyberattacks.
Vulnerability discovery accelerated sharply: 37,137 new CVEs were published in 1H2026, a 51% year-over-year increase, with more than half rated high or critical severity. Vedere Labs attributes part of this acceleration to threat actors and researchers alike leveraging AI to speed up vulnerability discovery, exploit development, and attack execution -- outpacing defenders' remediation capacity. Separately, 46% of the CVEs added to CISA's Known Exploited Vulnerabilities (KEV) catalog during the period were CVEs originally published before 2026, underscoring that legacy, unpatched vulnerabilities remain an actively exploited attack surface even as new-vulnerability volume grows.
Ransomware activity intensified: Vedere Labs tracked 4,544 ransomware attack claims (a 25% increase over the prior period), averaging roughly 25 attacks per day, attributed to 103 active ransomware groups (a 16% increase in active-group count). Related industry tracking for the surrounding quarters shows a reconsolidating ransomware ecosystem: Qilin, Akira, The Gentlemen, and LockBit together accounted for 41% of all named victims, with the top 10 groups collectively responsible for 71.1% of victims -- the highest concentration since Q1 2024 -- even as the total number of active groups fell from 85 to 71. LockBit relaunched as LockBit 5.0 in September 2025 after the February 2024 Operation Cronos law-enforcement disruption and was extorting new victims within weeks. Akira pursued an economically optimized targeting model focused on consumer goods and industrial manufacturing (sectors with high downtime costs and complex IT/OT environments), accumulating an estimated $244 million in total proceeds. Qilin claimed 701 victims by October 2025, a 280% surge from April 2025, averaging 75 victims/month and becoming the most active ransomware family by Q3 2025.
The report also tracked hacktivist activity: more than 5,700 hacktivist attack claims were observed across 98 Telegram channels, primarily targeting Israel, the United States, Ukraine, Indonesia, and Iran. Nation-state-linked activity remained significant, with actors associated with China, Russia, and Iran accounting for 32% of notable threat-actor activity updates tracked in the period.
On the device/infrastructure side, the report highlights continued and expanding targeting of specialized OT, IoT, and IoMT devices: programmable logic controllers (PLCs), human-machine interfaces (HMIs), automatic tank gauges (ATGs), medical devices, and network infrastructure (routers and firewalls). Routers and switches alone account for roughly one-third (34%) of devices carrying the most critical vulnerabilities, averaging nearly 32 vulnerabilities per device -- reinforcing their position as some of the most exposed and consequential assets on enterprise networks. The report also identifies 11 new device types entering the "riskiest" category across IT/OT/IoT/IoMT compared to prior editions, including serial-to-IP converters, RFID readers, BACnet routers, and medication dispensing systems, reflecting an expanding and diversifying attack surface as more specialized/embedded device classes are connected to IP networks.
Most-targeted sectors by tracked threat actors were government, technology, financial services, education, and healthcare. The report frames software supply-chain compromise as an increasingly sophisticated vector compounding the vulnerability surge, alongside AI-accelerated attacker tradecraft, and calls for defenders to broaden visibility beyond traditional IT endpoints to cover OT/IoT/IoMT and network infrastructure asset classes.
This threat re
Target sectors: government administration, technology, financial services, education, health, manufacturing, critical infrastructure
Target regions: Global, North America, Middle East, Europe, israel, ukraine, indonesia
References
- Forescout's 2026H1 Threat Review Reveals Surge in Vulnerability Discovery Amid Rapid AI Advances, Rising Ransomware Activity, and Continued Targeting of Specialized Devices
- Forescout's 2026 H1 Threat Review reveals surge in vulnerability discovery amid AI advances and ransomware activity
- Forescout reports 51% surge in vulnerabilities as AI, supply-chain attacks drive threats across IoT/OT infrastructure
- Forescout's 2026H1 Threat Review Reveals Surge in Vulnerability Discovery Amid Rapid AI Advances, Rising Ransomware Activity, and Continued Targeting of Specialized Devices (BusinessWire press release)
- Ransomware sector reconsolidating as Qilin, LockBit, and The Gentlemen expand influence in Q1 2026
- 2026 Ransomware Cartelization: Qilin, LockBit and Akira Convergence
- Forescout 2026 Riskiest Connected Devices report warns of rising OT, ICS risk as network infrastructure becomes prime target
- Forescout Research reveals 162 vulnerabilities in connected medical devices, elevating risks to patient data and safety
- Forescout's 2025H1 Threat Review Highlights Surge in Zero-Day Exploits, Nation-Backed Hacktivism, and Healthcare Vulnerabilities
- Forescout Threat Reports Overview
Detections & IOCs
As of 2026-07-22, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 25 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_INTEL, MEDIUM, threat intelligence, cybersecurity, T1595, T1596, T1588.005, T1585.001, T1584, T1190, T1195, T1195.001, T1133, T1059