The report found a 51% increase in published vulnerabilities and warned that attackers continue to target connected medical devices and other specialized systems.
Forescout Technologies released its 2026H1 Threat Review Report, finding that published vulnerabilities increased 51% year over year alongside continued attacks targeting connected medical devices and other specialized systems.
The report, produced by Forescout Research – Vedere Labs, analyzed more than 37,000 newly published vulnerabilities and 1,033 threat actors between January and June 2026. Ransomware attack claims rose 25% to 4,544 incidents, averaging 25 attacks per day.
According to the report, rapid advances in artificial intelligence and rising geopolitical tensions are driving this activity. Healthcare was among the five industries targeted by the largest number of tracked threat actors during the first half of the year, alongside government, technology, financial services, and education.
“AI is dramatically increasing the speed and scale of cyberattacks,” says Daniel dos Santos, vice president of research at Forescout, in a release. “In observing attack patterns and threat actor activity, we can see that AI is helping threat actors discover and exploit vulnerabilities faster than security teams can realistically remediate them.”
The analysis shows that threat actors are increasingly targeting specialized systems that often have less security oversight, including Internet of Medical Things devices, programmable logic controllers, and routers. The report also highlights that 46% of additions to the Cybersecurity and Infrastructure Security Agency Known Exploited Vulnerabilities catalog were published prior to 2026, indicating that older vulnerabilities remain an active risk.
“Many organizations still have significant blind spots across unmanaged assets and IoT, OT, and IoMT devices,” says Barry Mainz, CEO of Forescout, in a release. “Threat actors understand this and are increasingly exploiting those gaps. Security leaders should focus on finding and assessing these devices and using segmentation and automated controls to contain east-west movement, limit blast radius, and prevent a single compromise from spreading to more critical systems.”
The report also identifies evolving cyber operations from state-sponsored actors in China, Russia, and Iran, which collectively accounted for 32% of threat actors with notable activity updates. Additionally, researchers tracked more than 5,700 hacktivist attack claims primarily targeting Israel, the US, Ukraine, Indonesia, and Iran.
The findings emphasize the need for healthcare organizations to identify vulnerable assets and use network segmentation to contain threats. Forescout researchers are scheduled to present additional findings at Black Hat USA regarding how vulnerabilities in zero-touch provisioning can be used for large-scale supply chain compromises.
ID 447185347 © BiancoBlue | Dreamstime.com