I have been warning about AI-powered attacks for years. Most of the time, those warnings felt premature. Not this week. Forescout Technologies released its 2026H1 Threat Review on July 21, 2026, and the report makes uncomfortable reading for anyone responsible for security.
The headline numbers are big. Published vulnerabilities jumped 51% year-over-year to 37,137. Ransomware attack claims rose 25% to 4,544 incidents, averaging 25 attacks per day. Active ransomware groups hit 103, up 16%. But the underlying trend is what should concentrate the mind.
AI is compressing the attack timeline
Daniel dos Santos, VP of Research at Forescout, put it plainly: “AI is dramatically increasing the speed and scale of cyberattacks.” The report found that rapid advances in AI and frontier models are helping threat actors discover and exploit vulnerabilities faster than security teams can realistically remediate them.
This is not theoretical. Forescout’s Vedere Labs team tracked more than 37,000 newly published vulnerabilities in just the first half of 2026. That is over 200 new CVEs every single day. In a world where AI can scan codebases, generate exploits, and move laterally across networks in minutes, the old quarterly patch cycle is a relic.
The attack surface is also expanding beyond traditional IT. Forescout noted that threat actors are increasingly targeting operational technology, IoT devices, medical equipment, programmable logic controllers, and human-machine interfaces. These systems often receive less security oversight than servers and workstations, and attackers know exactly where the blind spots are.
What this means in practice
The practical implications are clear. Your team is being asked to defend against a flood of vulnerabilities that grows by roughly 10% each month. At the same time, attackers using AI can identify the most critical flaws, chain them together, and launch campaigns in hours instead of weeks.
Here is what should happen immediately:
- Map your entire attack surface. Include IoT, OT, and IoMT devices. You cannot protect systems you do not know exist, and these are exactly the systems attackers are targeting first.
- Prioritise exposure management. Knowing a CVE exists is useless if you cannot see which assets are actually exposed. Focus on internet-facing and critical systems first.
- Segment your networks. Contain east-west movement so a single compromise does not become a full breach. Zero trust is not just a buzzword here; it is a survival strategy.
- Accelerate patching cycles. The window between disclosure and exploitation is shrinking. Move critical updates from monthly to weekly, or faster where possible.
- Invest in visibility before AI-powered defence. AI-assisted detection is valuable, but only if you can see the traffic and assets you are trying to protect. Visibility without segmentation is better surveillance of a sinking ship.
Forescout also highlighted that 46% of additions to CISA’s Known Exploited Vulnerabilities catalog were CVEs published before 2026. Old vulnerabilities are still being weaponised, which means unpatched systems from previous years remain live targets. Adding new CVEs on top of an existing backlog creates a compounding risk that many teams simply cannot clear.
This is not a call to panic. Panic does not close ports or apply patches. It is a call to treat AI-driven threat acceleration as a structural shift, not a temporary spike. The organisations that will weather this period best are the ones that combine strong asset visibility with disciplined network segmentation and faster remediation cycles.
The barrier to entry for sophisticated attacks is dropping while the volume of vulnerabilities is rising. Security teams do not need to work harder. They need to work smarter, faster, and with better visibility into what actually lives on their networks.
Related Reading
- Nine Out of Ten Companies Are Not Ready for AI-Driven Attacks – The Accenture report showing enterprise readiness is still dangerously low.
- AI Turned a Single Hacker Into a Cloud-Breaking Threat – How AI compressed a cloud breach into a three-day operation.
- Senators Target AI Security Loophole With Antitrust Exemption – Why current laws are blocking coordinated vulnerability disclosure.
