1. Executive summary
Recorded Future's Insikt Group identified 215 actively exploited CVEs in H1 2026, up 34% from 161 in H1 2025, with exploitation broadening beyond Microsoft (40 unique CVEs) into Red Hat Enterprise Linux (13), Vercel Next.js (11), Cisco Catalyst SD-WAN Manager (8), and Apple iOS/iPadOS (7). The dominant adversary pattern is evasion through normalcy: abuse of legitimate tools, trusted platforms, remote access utilities, developer environments, and payment workflows rather than technical novelty. AI-enabled activity increased but remained additive — concentrated in Levels 1–3 of Recorded Future's AIM3 model (discrete tasks such as UI interpretation, persistence guidance, and malware development) rather than autonomous operations. The bottom-line risk for EMEA financial services is that intrusion activity progresses through approved tools and trusted services before defenders recognise it, and that AI-assisted vulnerability research is compressing the window between disclosure and weaponisation. No VERIFIED REFERENCE DATA resolved for this item; no specific CVEs, CVSS scores, or CISA-KEV states are asserted here.
2. Regulatory framing
No specific DORA/NIS2 article is directly engaged by this item. This is a trend analysis, not an incident affecting a client or a specific third-party provider; the general recommendations (exposure management, patching discipline, developer-credential governance) map to standing obligations rather than a distinctive trigger fact in this item.
3. Technical analysis & attack chain
This is a trend report, not a single intrusion; there is no single attack chain to reconstruct. The following are the confirmed, source-supported findings that matter to defenders.
Vulnerability exploitation landscape (H1 2026)
- 215 actively exploited CVEs identified by Insikt Group, up 34% from 161 in H1 2025; an average increase of seven exploited vulnerabilities per month from January to June.
- 142 of the 146 vulnerabilities exploitable without prior authentication were also network-accessible. 60 of the 82 RCE vulnerabilities combined network access with no authentication requirement. These are the profiles that matter most: network reachability, few access prerequisites, code execution.
- Vendor concentration: Microsoft 40 unique CVEs (up from 28 in H1 2025, +43% YoY), Red Hat 15, Cisco 13, Vercel 11, Fortinet 9. Exploitation affected products from 98 vendors, 67 of which had only one CVE — exploitation is not confined to the big vendors.
- Product-family concentration: Windows/Windows Server 20 CVEs, RHEL 13, Vercel Next.js 11, Cisco Catalyst SD-WAN Manager 8, Apple iOS/iPadOS 7. Concentration is product-driven: all 11 Vercel CVEs centred on Next.js; 8 of Cisco's 13 affected Catalyst SD-WAN; 13 of Red Hat's 15 affected RHEL.
- Threat actors reused established post-exploitation playbooks across both newly disclosed and long-standing vulnerabilities. Exposure and impact are more informative risk indicators than vendor ranking or CVSS score alone.
AI-enabled activity
- PromptSpy (identified by ESET): first known Android malware to use generative AI, using Google's Gemini to interpret on-screen UI elements and generate step-by-step instructions to improve persistence across device layouts.
- CANFAIL: threat actors used LLM-generated decoy logic / AI-assisted development artifacts to complicate analysis and facilitate malware delivery against Ukrainian organisations.
- Malicious OpenClaw ecosystem abuse (February 2026): VirusTotal reported malicious OpenClaw skills disguised as useful automation for a local AI agent ecosystem; Malwarebytes reported fake OpenClaw installers hosted on GitHub and surfaced through search results, delivering infostealers and proxy malware.
- AI-assisted vulnerability research: following the release of Anthropic's Claude Mythos Preview under Project Glasswing, June 2026 NVD disclosures were 43% above the previous six-month average; Mozilla reported Mythos Preview identified 271 vulnerabilities fixed in Firefox 150 (vs. 22 fixed after earlier testing with Claude Opus 4.6). Microsoft, Anthropic, and HackerOne have reported rising vulnerability discovery/submission volumes.
- Insikt assesses most observed AI-enabled malware sits at AIM3 Levels 1–3 (experimentation, adoption, optimization). Early H2 2026 reporting on the July 2026 Hugging Face incident demonstrated autonomous agents performing discovery, validation, weaponization, and operationalization with limited human intervention.
Other prominent activity: supply-chain compromises targeting package managers and developer environments (including AI-enabled tooling) via compromised credentials, trusted integrations, and software distribution channels; mobile malware enabling payment fraud through NFC abuse; Magecart campaigns leveraging trusted third-party services and checkout manipulation.
Confidence caveat: All findings above are single-sourced to the Recorded Future/Insikt Group report. The CrowdStrike 2026 Threat Hunting Report (corroborating source) independently supports the broader thesis — abuse of trusted identities, cloud services, AI tools, and software supply chains, with intrusion activity up ~4% year-over-year — but the specific figures (215 CVEs, vendor counts, PromptSpy/CANFAIL details) rest on the Recorded Future item alone. Verify before enforcement.
4. Mitigation & containment
No active incident to contain. Prioritised hardening actions drawn from the report's findings:
P1 — within 24h
- Triage your asset inventory against the exploited profiles identified: network-accessible, no-authentication, RCE vulnerabilities first. Prioritise the named product families — Windows/Windows Server, RHEL, Vercel Next.js, Cisco Catalyst SD-WAN Manager, Apple iOS/iPadOS — and Fortinet estate.
- Do not deprioritise less common products: 67 of 98 affected vendors had a single exploited CVE. Apply risk-based remediation across the full software inventory, including low-visibility products that receive slower patching.
P2 — within 72h
- Developer-environment security: enforce MFA and credential hygiene on developer identities, restrict trusted integrations and tokens in CI/CD and package-manager ecosystems, and control what can be published or promoted through software distribution channels.
- AI-tool governance: restrict unapproved AI tools and installers on endpoints; block fake/trojanized AI-installer delivery paths (search-result-driven GitHub-hosted installers for AI agent ecosystems were observed delivering infostealers and proxy malware).
- Mobile estate: via MDM, monitor for accessibility-service abuse and automated UI interaction on company-owned devices; strengthen payment-fraud monitoring for NFC-abuse patterns.
P3 — within 7 days
- Automate vulnerability enrichment, prioritisation, and mitigation to narrow the gap between machine-speed exploit development and defensive response — the report's central defensive recommendation given AI-compressed weaponisation timelines.
- Shift detection toward suspicious sequences of behaviour rather than isolated events, consistent with the observed abuse of legitimate tools and trusted services.
- Strengthen backup resilience and third-party oversight (including AI-enabled tooling in the supply chain).
5. Indicators of compromise
No indicators of compromise available in the source material.
Behavioural indicators (from source descriptions; no atomic IOCs published in the provided content):
| Behaviour | Where to observe | Confidence |
|---|---|---|
| Automated UI interaction / accessibility-service abuse on Android (PromptSpy-class) | MDM, mobile endpoint telemetry | Moderate — single-sourced (ESET via Recorded Future) |
| Suspicious script or installer activity tied to AI-themed downloads, extensions, repositories, or packages | Endpoint detection (EDR) | Moderate — single-sourced |
| Malicious "skills" published for local AI agent ecosystems (OpenClaw) | Package/skill repository monitoring, VirusTotal | Moderate — single-sourced (VirusTotal, February 2026) |
| Fake AI-tool installers surfaced via search results to GitHub | Web proxy/DNS logs, EDR installer execution events | Moderate — single-sourced (Malwarebytes) |
| Checkout-page manipulation via trusted third-party services (Magecart) | Web-page integrity monitoring, client-side script review | Moderate — single-sourced |
6. Detection
Insufficient indicators to author detection rules. The source material names no file hashes, distinctive strings, command-line flags, mutexes, registry keys, or exact file paths for any of the described malware families; authoring rules from the narrative alone would fabricate artefacts.
7. Sources
- Recorded Future / Insikt Group — H1 2026 Malware Vulnerability Trends — https://www.recordedfuture.com/research/h1-2026-malware-vulnerability-trends — 2026-09-03
- Help Net Security — Suppliers, logins, and AI tools are all becoming attack paths (CrowdStrike 2026 Threat Hunting Report coverage) — https://www.helpnetsecurity.com/2026/08/06/crowdstrike-cyber-threat-trends-report/ — 2026-08-06
8. Adverse Trace position
This is a strategic trend item, not an incident: severity is assessed as moderate but rising for EMEA financial services — no new CVE, CVSS score, or CISA-KEV state is asserted because no VERIFIED REFERENCE DATA resolved for this item, and we will not re-assess severity from press narrative. The actionable core for clients is threefold: (1) re-weight vulnerability prioritisation toward network-accessible, no-auth, RCE profiles across the full inventory — including single-CVE vendors and product families like Next.js and Catalyst SD-WAN that sit outside traditional Microsoft-centric patch focus; (2) treat developer environments, AI-tool install paths, and mobile payment flows as primary attack surface, since adversaries are deliberately blending into legitimate workflows; and (3) invest in automated vulnerability triage now, because AI-assisted research is shortening the disclosure-to-weaponisation window. All quantitative findings are single-sourced to Recorded Future/Insikt; the CrowdStrike report corroborates the directional thesis only. We will monitor for the full Insikt report annexes, specific CVE lists, and any IOCs published for PromptSpy, CANFAIL, and the OpenClaw installer campaigns, and will issue a follow-up advisory if exploit-in-the-wild confirmation or KEV additions materialise against the named product families.
Published via PulseTrace — Adverse Trace threat intelligence.