H1 2026 reveals a surge in malware activity, emphasizing familiar tactics and vulnerabilities, with AI playing a supporting role in enhancing intrusions.

Executive Overview
The first half of 2026 has underscored a growing trend among threat actors: the manipulation of established tools, trusted platforms, and ordinary workflows within both corporate and consumer domains. Cyber adversaries increasingly leveraged exposed software, developer utilities, remote access tools, and trusted third-party services to infiltrate networks, exfiltrate credentials, and monetize breaches while staying under the radar of security measures. This strategy of blending malicious activities with normal operations complicates the detection of intrusions, driving the necessity for organizations to implement stronger identity and credential governance, enhance exposure management, and bolster their security frameworks.
While AI-related cyber threats gained visibility in H1 2026, they primarily augmented existing attack methods instead of replacing them with fully autonomous capabilities. AI's role within the vulnerability landscape also expanded, leading to a higher volume of reported vulnerabilities—215 active exploits were identified during this period, reflecting a significant increase compared to previous trends. This escalation has the potential to tighten remediation timelines as attackers become more adept at developing exploits quickly, raising the stakes for organizational defense strategies.
Key Findings
- The number of actively exploited vulnerabilities soared to 215 in H1 2026, a 34% increase from the same period in the previous year, with notable security flaws characterized by combining easy network access and code execution capabilities.
- Analysis from Recorded Future indicated that remote access trojans (RATs) maintained a strong presence, with AsyncRAT emerging as the most reported malware variant in both H1 2025 and 2026.
- AI-enhanced malware activity in H1 2026 was primarily observed in lower levels of threat sophistication, utilized more for operational refinement than for autonomous attacks.
- Persistent exploitation tactics and social engineering efforts remained prevalent among ransomware actors, who refined their techniques while continuing to use familiar channels.
- Mobile threats, particularly those manipulating NFC technology, emerged as a significant concern, facilitating payment fraud and data breaches.
AI's Impact on Cyberattacks
In H1 2026, AI's influence on cyber threats became clearer, though the evidence suggests that much of the activity was more about improving existing tactics than automating attacks entirely.
The emergence of Anthropic's Claude Mythos Preview played a role in amplifying vulnerability detection, with a remarkable increase in reported flaws—43% higher than the previous six-month average. This spike demonstrates the effect of AI on vulnerability management, effectively contributing to the depletion of defender resources by hastening exploit development and reducing the time available for remedial actions. While AI has sparked a surge in discovered vulnerabilities, it hasn't fundamentally altered the dynamics of vulnerability management—attackers still need to operationalize these vulnerabilities effectively.
Nevertheless, organizations are likely to face increasing pressure due to escalating AI-assisted vulnerability disclosures. Defenders will need to prioritize their mitigation strategies amidst tighter timelines and identify which vulnerabilities pose the greatest threat. The growing sophistication of AI tools used by threat actors highlights the urgent need for proactive measures in vulnerability enrichment and remediation planning.
ESET's identification of PromptSpy as the first Android malware utilizing generative AI illustrates how attackers are leveraging such technology to navigate user interfaces and enhance their intrusion methodologies. Additionally, campaigns like CANFAIL have revealed how threat actors employ AI-generated logic to obscure their activities and complicate incident analysis.
Exploitation Trends and Vulnerability Dynamics
The exploitation of vulnerabilities has been characterized by dual pressures: an uptick in newly discovered flaws and the persistent existence of unpatched vulnerabilities. Specifically, 142 of the exploited CVEs were accessible via the network and did not require prior authentication, while many exploits are now readily available for varied targets. This landscape necessitates that organizations remain vigilant and prioritize exposure management across their software inventories, rather than focusing solely on prominent vendors.
With Microsoft dominating the field, accounting for 40 unique CVEs in the first half of 2026 alone, followed by Red Hat, Cisco, Vercel, and others, defenders cannot afford to overlook less common products during their vulnerability assessments and patching efforts. Understanding that exploitation spanned a diverse array of software vendors highlights a necessary shift in how risk is prioritized: a reminder that weaker vendors could harbor critical vulnerabilities waiting to be exploited.
The Strategic Outlook
The emerging trends in malware and vulnerability exploitation from H1 2026 signal crucial adjustments that cybersecurity teams must consider. The methodologies shown by threat actors emphasize that proficient attackers will continue to exploit known vulnerabilities and existing infrastructures, capitalizing on the familiarity of user workflows and systems. For businesses, ensuring a fortified defense against malware incursions will necessitate comprehensive exposure management, prioritization of actionable vulnerabilities, and continual enhancement of detection processes.
As we move forward, the rise of AI in cyberattacks—though currently focused on augmenting existing workflows—presents not just an immediate hurdle but a long-term paradigm shift in the approach toward cybersecurity defense. Organizations must remain agile to preemptively address evolving threats before they escalate into more significant breaches.
Discussion
Sign in to join the discussion.