# Forescout 2026H1 Threat Review: 51% Surge in Published Vulnerabilities as AI and Supply-Chain Attacks Drive Threats Across IoT/OT/IoMT Infrastructure

> Forescout Vedere Labs' 2026H1 Threat Review (Jan-Jun 2026) documents 37,137 newly published vulnerabilities (51% YoY increase, >50% high/critical), a 25% rise in ransomware attack claims to 4,544 incidents across 103 active groups, and continued heavy targeting of specialized OT/IoT/IoMT devices, attributing much of the acceleration to AI-assisted vulnerability discovery/exploitation and rising software supply-chain compromise.

- **Published:** 2026-07-21T00:00:00Z
- **Last reviewed:** 2026-07-21T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-1614
- **ID:** TL-2026-1614
- **Severity:** MEDIUM
- **Category:** THREAT_INTEL
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 25 (full data via the Threadlinqs MCP server — Purple tier)

## Description

Forescout Technologies' research arm, Vedere Labs, published its 2026H1 Threat Review on 21 July 2026, covering the January-June 2026 analysis period ahead of a Black Hat USA presentation scheduled for 5 August 2026. The report analyzed more than 37,000 newly published vulnerabilities, 1,033 tracked threat actors, and thousands of observed cyberattacks.

Vulnerability discovery accelerated sharply: 37,137 new CVEs were published in 1H2026, a 51% year-over-year increase, with more than half rated high or critical severity. Vedere Labs attributes part of this acceleration to threat actors and researchers alike leveraging AI to speed up vulnerability discovery, exploit development, and attack execution -- outpacing defenders' remediation capacity. Separately, 46% of the CVEs added to CISA's Known Exploited Vulnerabilities (KEV) catalog during the period were CVEs originally published before 2026, underscoring that legacy, unpatched vulnerabilities remain an actively exploited attack surface even as new-vulnerability volume grows.

Ransomware activity intensified: Vedere Labs tracked 4,544 ransomware attack claims (a 25% increase over the prior period), averaging roughly 25 attacks per day, attributed to 103 active ransomware groups (a 16% increase in active-group count). Related industry tracking for the surrounding quarters shows a reconsolidating ransomware ecosystem: Qilin, Akira, The Gentlemen, and LockBit together accounted for 41% of all named victims, with the top 10 groups collectively responsible for 71.1% of victims -- the highest concentration since Q1 2024 -- even as the total number of active groups fell from 85 to 71. LockBit relaunched as LockBit 5.0 in September 2025 after the February 2024 Operation Cronos law-enforcement disruption and was extorting new victims within weeks. Akira pursued an economically optimized targeting model focused on consumer goods and industrial manufacturing (sectors with high downtime costs and complex IT/OT environments), accumulating an estimated $244 million in total proceeds. Qilin claimed 701 victims by October 2025, a 280% surge from April 2025, averaging 75 victims/month and becoming the most active ransomware family by Q3 2025.

The report also tracked hacktivist activity: more than 5,700 hacktivist attack claims were observed across 98 Telegram channels, primarily targeting Israel, the United States, Ukraine, Indonesia, and Iran. Nation-state-linked activity remained significant, with actors associated with China, Russia, and Iran accounting for 32% of notable threat-actor activity updates tracked in the period.

On the device/infrastructure side, the report highlights continued and expanding targeting of specialized OT, IoT, and IoMT devices: programmable logic controllers (PLCs), human-machine interfaces (HMIs), automatic tank gauges (ATGs), medical devices, and network infrastructure (routers and firewalls). Routers and switches alone account for roughly one-third (34%) of devices carrying the most critical vulnerabilities, averaging nearly 32 vulnerabilities per device -- reinforcing their position as some of the most exposed and consequential assets on enterprise networks. The report also identifies 11 new device types entering the "riskiest" category across IT/OT/IoT/IoMT compared to prior editions, including serial-to-IP converters, RFID readers, BACnet routers, and medication dispensing systems, reflecting an expanding and diversifying attack surface as more specialized/embedded device classes are connected to IP networks.

Most-targeted sectors by tracked threat actors were government, technology, financial services, education, and healthcare. The report frames software supply-chain compromise as an increasingly sophisticated vector compounding the vulnerability surge, alongside AI-accelerated attacker tradecraft, and calls for defenders to broaden visibility beyond traditional IT endpoints to cover OT/IoT/IoMT and network infrastructure asset classes.

This threat record captures the aggregate industry-trend findings of the report itself (not a single CVE/exploit) for downstream correlation against device-specific and ransomware-specific threats already tracked in the platform.

## MITRE ATT&CK

- T1595 Active Scanning
- T1596 Search Open Technical Databases
- T1588.005 Exploits
- T1585.001 Social Media Accounts
- T1584 Compromise Infrastructure
- T1190 Exploit Public-Facing Application
- T1195 Supply Chain Compromise
- T1195.001 Compromise Software Dependencies and Development Tools
- T1133 External Remote Services
- T1059 Command and Scripting Interpreter
- T1505.003 Web Shell
- T1068 Exploitation for Privilege Escalation
- T1685 Disable or Modify Tools
- T1046 Network Service Discovery
- T1018 Remote System Discovery
- T1210 Exploitation of Remote Services
- T1005 Data from Local System
- T1071 Application Layer Protocol
- T1041 Exfiltration Over C2 Channel
- T1486 Data Encrypted for Impact
- T1490 Inhibit System Recovery
- T1565.001 Stored Data Manipulation
- T1491.002 External Defacement

## Sources

- [Forescout's 2026H1 Threat Review Reveals Surge in Vulnerability Discovery Amid Rapid AI Advances, Rising Ransomware Activity, and Continued Targeting of Specialized Devices](https://cioinfluence.com/security/forescouts-2026h1-threat-review-reveals-surge-in-vulnerability-discovery-amid-rapid-ai-advances-rising-ransomware-activity-and-continued-targeting-of-specialized-devices/)
- [Forescout's 2026 H1 Threat Review reveals surge in vulnerability discovery amid AI advances and ransomware activity](https://www.intelligentcio.com/me/2026/07/21/forescouts-2026-h1-threat-review-reveals-surge-in-vulnerability-discovery-amid-ai-advances-and-ransomware-activity/)
- [Forescout reports 51% surge in vulnerabilities as AI, supply-chain attacks drive threats across IoT/OT infrastructure](https://industrialcyber.co/industrial-cyber-attacks/forescout-reports-51-surge-in-vulnerabilities-as-ai-supply-chain-attacks-drive-threats-across-iot-ot-infrastructure/)
- [Forescout's 2026H1 Threat Review Reveals Surge in Vulnerability Discovery Amid Rapid AI Advances, Rising Ransomware Activity, and Continued Targeting of Specialized Devices (BusinessWire press release)](https://businesswire.com/news/home/20260721573714/en/Forescouts-2026H1-Threat-Review-Reveals-Surge-in-Vulnerability-Discovery-Amid-Rapid-AI-Advances-Rising-Ransomware-Activity-and-Continued-Targeting-of-Specialized-Devices)
- [Ransomware sector reconsolidating as Qilin, LockBit, and The Gentlemen expand influence in Q1 2026](https://industrialcyber.co/ransomware/ransomware-sector-reconsolidating-as-qilin-lockbit-and-the-gentlemen-expand-influence-in-q1-2026/)
- [2026 Ransomware Cartelization: Qilin, LockBit and Akira Convergence](https://www.secureblink.com/threat-research/2026-ransomware-cartelization-qilin-lock-bit-and-akira-convergence)
- [Forescout 2026 Riskiest Connected Devices report warns of rising OT, ICS risk as network infrastructure becomes prime target](https://industrialcyber.co/reports/forescout-2026-riskiest-connected-devices-report-warns-of-rising-ot-ics-risk-as-network-infrastructure-becomes-prime-target/)
- [Forescout Research reveals 162 vulnerabilities in connected medical devices, elevating risks to patient data and safety](https://industrialcyber.co/medical/forescout-research-reveals-162-vulnerabilities-in-connected-medical-devices-elevating-risks-to-patient-data-and-safety/)
- [Forescout's 2025H1 Threat Review Highlights Surge in Zero-Day Exploits, Nation-Backed Hacktivism, and Healthcare Vulnerabilities](https://www.forescout.com/press-releases/forescout-2025h1-threat-review-highlights-surge-in-zero-day-exploits-nation-backed-hacktivism-and-healthcare-vulnerabilities/)
- [Forescout Threat Reports Overview](https://www.forescout.com/threat-briefings/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-1614
