Reinsurance News

AI making security ‘noisier’ as vulnerability disclosures surge 36%: Beazley Security

18th August 2026 - Author: Kane Wells -

Share

According to Beazley Security’s Q2 2026 Quarterly Threat Report, the widespread adoption of agentic AI for vulnerability research drove a 36% quarter-over-quarter increase in newly disclosed vulnerabilities, while the methods attackers used to breach organisations remained largely unchanged.

Beazley logo“The headline this quarter is that AI made the security industry’s job noisier without making the attacker’s job fundamentally different. But AI-assisted attacks are gaining in both frequency and effectiveness, and we seem to be watching the attackers learn in real time,” Alton Kizziah, CEO of Beazley Security, explained.

Beazley Security’s new report found that vulnerabilities confirmed as actively exploited and added to the Cybersecurity and Infrastructure Security Agency’s (CISA) Known Exploited Vulnerabilities catalogue rose by just 10% over the same period, a gap that “further amplifies” the already difficult prioritisation challenge facing security teams.

What’s more, the firm noted that disclosure volume, which has historically fluctuated within a 10% quarter-on-quarter band, broke that pattern in 2026, rising 18.5% in Q1 and a further 36% in Q2.

Beazley Security Labs (BSL) has attributed the surge to the rapid operationalisation of agentic AI across research programs.

“The strain of the higher volumes is visible industry-wide: NIST no longer enriches every new CVE; HackerOne’s Internet Bug Bounty paused submissions citing AI-assisted research; Pwn2Own issued applicant rejections for the first time; and Cisco restructured its disclosure model outright,” the report observed.

Elsewhere in Beazley Security’s report, compromised credentials used against internet-facing VPN and remote desktop services accounted for 67% of ransomware intrusions investigated by the firm.

While down from 74% in Q1, credential-based access remained the dominant entry point by a wide margin.

Business email compromise (BEC) is also said to have remained among the most common incident types, with attackers increasingly exploiting Microsoft’s device code authentication flow to capture session tokens.

Because victims complete a legitimate sign-in and satisfy any organisational MFA requirements themselves, attackers do not need to intercept an authentication code, Beazley Security said.

Kizziah continued, “As AI adoption in the enterprise increases, and as attackers continue to evolve tactics, clients need to remain vigilant and attend to cybersecurity basics.

“We also recommend organisations consider AI assessments to monitor what AI capabilities are in use across the organisation, how these tools are being used, and what is needed to improve management and control frameworks.”