Insurance
Home›Insurance›Industry & Deals›Ransomware still starts with stolen logins as vulnerab…
Ransomware still starts with stolen logins as vulnerabilities surge
Beazley Security found ransomware intrusions were still driven mainly by stolen login credentials, even as newly disclosed software vulnerabilities jumped 36% in Q2 2026.
Cybersecurity data reviewed by Risk & Insurance shows a sharp rise in newly disclosed software flaws in Q2 2026, even as the real-world attack pattern changed little. Beazley Security’s Quarterly Threat Report said researchers disclosed more than 20,700 new vulnerabilities in the quarter, up 36% from the prior period, with AI tools accelerating bug discovery.
While vulnerability disclosures surged, confirmed incidents moved at a slower pace. The report said real-world attacks grew 10%, and 67% of ransomware cases were traced back to stolen login credentials, keeping credential theft as the leading ransomware entry point.
The increased volume of findings is stressing vulnerability tracking systems. Risk & Insurance reports that NIST, which manages the U.S. government’s vulnerability database, said it can no longer thoroughly review every new flaw and is prioritizing only the most impactful issues.
Beazley Security Labs identified roughly 5,600 high-risk vulnerabilities in the quarter and issued 21 advisories for the most dangerous items, a 40% increase from the prior quarter. However, only 44 vulnerabilities were confirmed as actively exploited by CISA, up 10%, suggesting most new flaws are being found and patched rather than widely weaponized.