Security1 distinct publisher3 min readUpdated
NIST stopped enriching every CVE, HackerOne paused the Internet Bug Bounty, Pwn2Own turned entrants away, and Cisco began bundling flaws under one ID. Attackers barely changed method.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Four load-bearing parts of the vulnerability disclosure pipeline changed how they operate in the second quarter, and each change removed coverage rather than adding it [3][4][5][6]. According to Beazley Security's Q2 2026 quarterly threat report, that retrenchment happened while disclosed vulnerabilities grew 36% to more than 20,700 and confirmed exploitation in the wild grew by only 10% [1][2].
The two figures are the argument. Volume is arriving faster than the institutions that process it can absorb, and almost none of the extra volume is showing up as attacker capability. Beazley attributes the surge to agentic AI producing reported vulnerabilities at scale [7], and reports that Anthropic's Mythos model was briefly restricted from foreign access by a US export order in June before the restriction was lifted the same month [8].
The responses are worth reading as a set. NIST has stopped enriching every CVE it receives [3]. HackerOne paused new submissions to its Internet Bug Bounty program [4]. Pwn2Own rejected contestant applications for the first time in its history [5]. Cisco rebuilt its disclosure model and now bundles multiple flaws under a single CVE, which Beazley describes as a departure from how CVE IDs are meant to work [6]. Three of those are queue management. The fourth is different in kind: if one identifier can cover several defects, then counting CVEs is no longer counting bugs, and any remediation SLA written in terms of CVE IDs quietly changes meaning without anyone editing the policy. The enrichment that NIST is no longer doing does not disappear either. It moves to whoever consumes the feed, which in practice means the vulnerability management team that was already behind.
Beazley's own numbers show what triage at this volume looks like. Of roughly 5,600 high-risk CVEs disclosed in the quarter, Beazley Security Labs issued 21 advisories, up 40% from Q1 [9]. That is about one advisory per 267 high-risk CVEs [1], and the high-risk pool itself is only around 27% of everything disclosed [2]. The 36% growth rate implies roughly 15,200 disclosures in Q1 [3], so the quarter added something like five thousand new records to the pile while the vendor lab watching it raised its signal count from 15 to 21 [4]. The filtering ratio is not a marketing point. It is a measurement of how little of the feed is actionable.
Meanwhile the entry points did not move. Beazley reports that 67% of ransomware intrusions began with compromised credentials against exposed VPN and RDP, and another 14% with malware delivered by SEO-poisoned installers [10]. What changed was after entry: a growing share of affiliates skipped encryption entirely for data theft and extortion, a pattern Beazley saw from Inc Ransomware, Brain Cipher and Pear affiliates [11]. For BEC, attackers increasingly abused Microsoft's device code sign-in flow, in which the victim enters an attacker-generated code on a genuine Microsoft page, so the login and the MFA prompt are real and the attacker collects the session token [12].
Watch whether other large vendors copy Cisco's bundling, because that is the change that breaks downstream counting rather than merely delaying it [6]. Watch whether HackerOne reopens IBB submissions with new intake rules [4]. And watch the Q3 ratio: if disclosures grow another third and exploitation again grows a tenth, the case for spending on identity at the VPN and RDP edge gets stronger, not weaker [1][2][10].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Reported vulnerabilities grew 36% in Q2, with more than 20,700 new vulnerabilities disclosed.
Cisco rebuilt its entire disclosure model, including bundling multiple flaws under a single CVE, which the report calls a departure from how CVE IDs are supposed to work.
Anthropic's Mythos model was briefly restricted from foreign access by a US export order in June, with the restriction lifted later that same month.
Of the roughly 5,600 high-risk CVEs disclosed in the quarter, Beazley Security Labs issued 21 advisories, up 40% from Q1.
Confirmed exploitation in the wild grew by just 10% during the quarter, even as the disclosed vulnerability population grew by a third.
NIST has stopped enriching every CVE it receives.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Specific figures, single interested source, no methodology
Every number and event in this cluster comes from one self-published vendor report with no independent corroboration in the supplied sources. The figures are concrete and internally consistent (20,700+ disclosures at +36%, ~5,600 high-risk CVEs, 21 advisories at +40%, 67%/14% intrusion split), which raises evidence above hearsay, but the report publishes no methodology for counting disclosures or 'confirmed exploitation', no telemetry base for the ransomware percentages, and no primary citation for the NIST, HackerOne, Pwn2Own or Cisco process changes it reports.
Concrete ecosystem behaviour changes, all reported second-hand
Adoption here is not product uptake but observable behaviour change across the disclosure ecosystem, and there is a lot of it: NIST curtailing CVE enrichment, HackerOne pausing Internet Bug Bounty intake, Pwn2Own rejecting entrants for the first time, Cisco changing CVE issuance practice, Anthropic's Fable shipping publicly on July 1, and Beazley's own advisory output rising 40%. These are real, dated-to-quarter, consequential actions by named organisations. The score is held mid-range because each is relayed by a single third party rather than confirmed from the acting organisations, and because the report gives no scale figures for AI-assisted research adoption among vulnerability researchers.
Conservative on threat, overstated on cause
The report is unusually deflationary about danger - it repeatedly stresses that disclosure volume rose a third while exploitation rose a tenth and the front door has not changed - which pushes the gap toward zero or negative on the threat axis. It is pushed positive by the explanatory framing: a 'Tidal Wave' heading and the declaration that agentic AI adoption 'is now a fact' carry no supporting measurement, and the report's filtering-to-21-advisories narrative sits directly alongside promotion of its Exposure Management platform. Net result is a mild overstatement concentrated in causation and vendor positioning rather than in the numbers themselves.
Vendor report promoting its own exposure management practice
The publisher is the subject: Beazley Security states in the same passage that filtering disclosure volume 'is the point of this report' and that Beazley Security Labs monitoring supports its Exposure Management platform. A narrative in which public triage infrastructure (NIST, HackerOne, Pwn2Own) is buckling under volume while the vendor's curated advisory output grows 40% is commercially favourable to the vendor. That does not make the figures wrong, but the incentive to emphasise unmanageable noise and a paid filter is direct and undisclosed as a conflict.
Directionally credible, single-source and unverifiable
Confidence is moderate-low. The cluster is one publisher with clear commercial incentive, no methodology, and no corroborating source, so individual figures should not be quoted as settled. Confidence is not lower because the report's claims are specific, named and falsifiable - NIST enrichment, the Internet Bug Bounty pause, Pwn2Own rejections, Cisco's CVE bundling and the July 1 Fable release can each be checked against primary sources - and because the mechanically described device code sign-in abuse is internally coherent and independently actionable.
invest
Kraken's parent now runs a security model that Washington can switch off1 distinct publisher
build
Claude's system prompt grew ninefold in two years. Version yours like code.1 distinct publisher
security
Mythos's method, not its zero-day count, is what breaks CVE-keyed vuln management1 distinct publisher
invest
Behind-the-meter gas is the data center buildout's real cost: 318 Mt a year1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 18, 2026