Security1 distinct publisher2 min readPublished
Insikt Group counted 215 actively exploited CVEs in six months, up 34% year on year, and describes attackers running them through remote access utilities, package registries and payment flows defenders already permit.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Do the arithmetic on the reachability figures and the prioritisation argument makes itself. Sixty of the 215 actively exploited CVEs were network-reachable, required no credentials and ended in code execution [3][1], which is 28 percent of the exploited set [14]. Of the 146 that needed no prior authentication, 142 were also network-accessible [2], or 97 percent [15]. Pre-auth and remote is not the exception in this data set; it is the shape of most of it.
That ratio is what a patch queue runs on. Insikt Group's own framing is that exposure and impact say more about operational risk than vendor ranking or severity score alone, because campaign reporting showed the same post-exploitation playbooks reused against newly disclosed and long-standing vulnerabilities [4][13]. Same playbook, different entry point.
The evasion claim is a separate argument resting on softer evidence. Recorded Future describes actors leaning on exposed software, developer tools, remote access utilities, payment workflows and third-party services, and on familiar execution, obfuscation, discovery and payload-transfer techniques rather than new ones [18][7]. Two of the named cases show what that costs a detection team. Mobile malware abused NFC to commit payment fraud, and Magecart operators worked through trusted third-party services and checkout manipulation [9]. In both, the thing to catch is a sequence inside a payment path, which is why the report pushes detection toward suspicious sequences of behaviour rather than isolated events [12].
AI is the part most likely to be over-read. Recorded Future places observed AI-enabled malware capability at levels 1 to 3 of its AIM3 model, with AI handling discrete functions such as persistence, UI interaction, malware development and delivery rather than autonomous operations [10]. The budget consequence sits on the vulnerability side instead, where AI-assisted research has already increased the volume of vulnerability reports and could compress remediation timelines further by accelerating exploit-path analysis and lowering exploit-development costs for skilled operators [11].
One caveat on the headline count. The 215 figure is what one vendor's analysts tracked as actively exploited, so the year-on-year increase of 54 CVEs [16] measures Insikt Group's coverage as well as attacker behaviour. The rate it implies, roughly 1.2 newly exploited CVEs per day across the half [17], is the arrival load a triage rota has to absorb, and the reason the ordering rule matters more than the total.
Ranked by verification strength, evidence, and original report placement.
Insikt Group identified 215 actively exploited CVEs in H1 2026, up 34% from 161 in H1 2025.
142 of the 146 vulnerabilities that could be exploited without prior authentication were also network-accessible.
60 of the 82 remote code execution vulnerabilities combined network access with no authentication requirement.
Recorded Future states that exposure and impact are more informative indicators of operational risk than vendor ranking or severity score alone.
RATs led Insikt Group malware reporting in H1 2026, and Recorded Future Malware Intelligence submissions identified AsyncRAT as the top submitted malware family by total unique hashes and command-and-control configurations.
AsyncRAT, Cobalt Strike, XWorm, Stealc and REMCOS RAT remained in the top ten across both H1 2025 and H1 2026.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 2, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
leadership
ClickFix scales by asking employees to paste the command themselves1 distinct publisher
security
The disclosure pipeline is triaging itself: 20,700 new CVEs, 10% more exploitation1 distinct publisher
product
Harness hands vulnerability triage to agents, and concedes code fixes cannot keep pace2 distinct publishers
build
GitVenom dressed hundreds of repositories over several years to ship AsyncRAT and Quasar1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Precise numbers, one set of books
The specificity is real — 215, 161, 146, 142, 82, 60 — and the ratios hold up when you do the arithmetic yourself. But the counting rule behind 'actively exploited' is never stated, the malware league table is built from submissions to Recorded Future's own platform, and the AI grading is scored against a maturity model the company wrote. Strong primary observation, zero independent corroboration, and the qualitative strands on supply chain and post-exploitation reuse arrive without a single named package or campaign.
Exploitation at scale, AI still assisting
On the attacker side the uptake evidence is thick: hundreds of CVEs under real exploitation, five malware families holding top-ten position across two consecutive halves, NFCShare and NGate cashing out at ATMs, ransomware crews reaching for s5cmd and AnyDesk. On the AI side the same report caps things at Levels 1 to 3 of its own scale, and the only hard AI numbers describe defensive discovery — 271 Mythos-found fixes in Firefox 150, June NVD disclosures 43% above trend. Widespread abuse of the ordinary; early, additive use of the new.
Talks AI down, counts itself up
A threat-intel vendor had every commercial reason to declare the age of autonomous AI attackers and instead files them at Levels 1 to 3, additive to existing tradecraft — that restraint runs the other way from the market's noise. The offset is the 34%, a growth figure produced by the same organisation that decides what enters the set, presented without the collection caveat that would make it honest, and the projection that remediation windows 'could' compress further, which is asserted rather than observed. Slightly understated overall, with the one forward lean sitting exactly where the vendor's product story lives.
The scoreboard and the remedy, same author
Recorded Future counts the exploitation, ranks the malware from its own submission platform, grades AI maturity on a model it named, and then closes with a control list — exposure management, identity and credential governance, behavioural detection, developer-environment security, backup resilience, mobile fraud monitoring, third-party oversight — that reads like a description of the threat-intelligence market it competes in. None of that makes the numbers wrong; it does mean every step from measurement to recommendation runs through one interested party, and the report never says so.
Credible source, unverified alone
Confidence sits mid-range for a structural reason rather than a quality one: the observer is well placed and the figures are internally coherent, but there is exactly one observer. Nothing here has been cross-checked, the definitional questions behind the counts stay open, and several claims — playbook reuse, familiar delivery techniques, supply-chain propagation — are qualitative summaries whose supporting detail was not published. Firm enough to act on for triage; too thin to quote as a settled measurement of the half.