Beazley Security reports 43% surge in exploited vulnerabilities and AI‑driven attacks in Q1 2026
Beazley Security’s Q1 2026 Threat Report found that exploited vulnerabilities rose 43% in the first three months, with more than 15,200 new flaws disclosed and almost 3,900 classified as high risk. The number of entries in the CISA Known Exploited Vulnerabilities catalog also increased by 43% compared with Q4 2025, indicating faster weaponisation of newly discovered bugs. Critical zero‑day advisories issued to clients grew 15%, many affecting edge infrastructure such as VPNs and firewalls.
The report highlighted a shift toward AI‑enabled supply‑chain attacks. An autonomous AI agent scanned public code repositories, identified mis‑configured access controls and compromised the open‑source scanner Trivy, spreading credential‑stealing malware to downstream tools including the AI gateway LiteLLM. An Iranian‑linked hacktivist group used Microsoft Intune to remotely wipe more than 200,000 Stryker medical‑device systems worldwide. Threat actor group TeamPCP employed an AI tool dubbed “hackerbot‑claw” to exploit GitHub CI/CD workflows, further compromising developer pipelines.
Ransomware activity remained steady, with compromised credentials accounting for 74% of ransomware intrusions and a rise in extortion‑only attacks that steal data without encryption. Alton Kizziah, CEO of Beazley Security, warned that AI‑driven automation is increasing the efficiency and impact of attacks, while director Josh Carolan noted attackers are refining, not reinventing, their playbooks.