Insurance
Home›Insurance›Industry & Deals›AI-driven vulnerability research boosts disclosed secu…
AI-driven vulnerability research boosts disclosed security flaws by 36%
Beazley Security said actively exploited vulnerabilities listed by CISA rose only 10%, widening the gap security teams must prioritize.
Beazley Security’s Q2 2026 Quarterly Threat Report says the broad adoption of agentic AI for vulnerability research helped drive a 36% quarter-over-quarter increase in newly disclosed vulnerabilities.
The report found a smaller rise in the subset of vulnerabilities confirmed as actively exploited, with those added to the Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalogue up 10% over the same period. It also said total disclosure volume broke its usual pattern, rising 18.5% in Q1 and another 36% in Q2.
Beazley Security attributed the surge to the rapid operationalisation of agentic AI across research programs, saying the industry has shown strain as new disclosures accelerate. It cited examples including NIST no longer enriching every new CVE, HackerOne pausing bug bounty submissions citing AI-assisted research, Pwn2Own issuing applicant rejections, and Cisco restructuring its disclosure model.
On ransomware and initial access, the firm said compromised credentials used against internet-facing VPN and remote desktop services accounted for 67% of ransomware intrusions it investigated, down from 74% in Q1. It also said business email compromise remained among the most common incident types, and that attackers increasingly exploited Microsoft’s device code authentication flow to capture session tokens without intercepting authentication codes.