Beazley Security’s Q2 2026 Quarterly Threat Report (released August 18, 2026) says agentic AI made vulnerability research much louder without changing how most attackers still get in. Newly disclosed CVEs jumped 36% quarter over quarter. Confirmed exploitation added to CISA’s Known Exploited Vulnerabilities catalog rose only 10%. In Beazley’s own ransomware investigations, 67% of intrusions still began with compromised credentials on exposed VPN and RDP.
That is the EmailMeNow read: patch the flood, but do not treat a CVE dashboard as the front door. PropertyCasualty360 recapped the same report for insurance buyers. This post cites Beazley’s published figures — it does not invent Texas-only cuts the report does not publish.
This is not a duplicate of IBM Cost of a Data Breach 2026 (Ponemon cost study) or Mozilla / Mythos Firefox patches (one vendor’s AI-found bugs). Beazley is a Q2 incident + disclosure report from a carrier’s security lab.

Snapshot
| Field | Beazley Q2 2026 |
|---|---|
| New CVEs (NIST published) | 20,755 (+36% vs Q1) |
| High-risk CVEs (Beazley cut) | ~5,600 |
| CISA KEV additions | 44 (+10%) |
| BSL critical 0-day advisories | 21 (+40%) |
| Ransomware initial access | 67% stolen VPN / RDP credentials |
| Malware / SEO-poisoned installers | 14% of ransomware cases |
CEO Alton Kizziah: AI made the industry’s job noisier without making the attacker’s job fundamentally different — while AI-assisted attacks are still gaining frequency.
Why the CVE flood is not the same as more breaches
Beazley Security Labs attributes the 2026 break from the old ±10% quarterly CVE band (+18.5% in Q1, then +36% in Q2) to agentic AI in research programs. Downstream strain, as Beazley lists it:
| System | What changed |
|---|---|
| NIST / NVD | No longer enriches every new CVE |
| HackerOne Internet Bug Bounty | Paused submissions, citing AI-assisted research |
| Pwn2Own | First-time applicant rejections (Berlin volume) |
| Cisco | Rebuilt disclosure, including bundling flaws under one CVE |
Anthropic’s Mythos (and public Fable) sat in the same quarter’s export-control noise; that is context for Mozilla’s Mythos Firefox patch wave, not proof that every new CVE is already in the wild.
Of ~5,600 high-risk CVEs, Beazley issued 21 client advisories. CISA confirmed 44 as actively exploited (KEV). Most of the new paper is being found and fixed — not immediately weaponized.
The front door did not move: credentials, then BEC
Beazley responders still see financially motivated actors succeed with valid stolen passwords on internet-facing remote access. Healthcare became the largest reported ransomware sector this quarter (21%, up from 10%). Leak-site posts fell slightly vs Q1 but stayed ~60% above Q2 2025.
BEC remained one of the most common incident types Beazley handled. Attackers sit in mailboxes, add forwarding rules, and reroute payments. The Q2 twist: device-code phishing against Microsoft sign-in.
The victim types a code on a real Microsoft login page and completes real MFA. The attacker collects the session token. Microsoft researchers documented automation that starts the 15-minute code clock only after the victim clicks. A YubiKey on that Microsoft account still helps against fake login pages — it does not stop a user who finishes a genuine device-code flow.

MFA: YubiKey and Google Authenticator still matter — and still get bypassed
We graded public login docs for the domains this report names. Fail remains SMS/voice/email OTP. Pass is open TOTP. Strong is a documented FIDO / YubiKey-class key. Device-code / AiTM abuse is why phishing-resistant MFA plus Conditional Access that blocks device-code belongs on the same checklist.
| Service | Documented methods | Grade |
|---|---|---|
| Microsoft account / Entra | FIDO2 keys, passkeys, Authenticator / TOTP | Strong — still phishable via device code |
| HackerOne | YubiKey named; Google Authenticator / open TOTP required (non-SSO) | Strong |
| Login.gov (CISA portal path) | FIDO security key; Google Authenticator; PIV/CAC for eligible .gov | Strong |
| myBeazley / Beazley portals | Public enrollment docs do not name YubiKey or open TOTP | Not documented |
CISA recommends phishing-resistant FIDO for everyone (More than a Password). That is policy guidance, not a claim that every cisa.gov visitor already uses a key. External CISA partner apps have documented Google Authenticator / Okta Verify; *.cisa.dhs.gov staff can use PIV.
Beazley’s own insured applications have long listed FIDO2 / YubiKey as an acceptable MFA form. That is what they ask you to attest — not a documented myBeazley self-serve key.
Recommended MFA tools
| Product | Best for | Get it |
|---|---|---|
| YubiKey 5C NFC | USB-C laptops + NFC phones | Amazon |
| YubiKey 5 NFC | USB-A desktops + NFC phones | Amazon |
| YubiKey 5 / 5C NFC case | Keychain protection for the key | Amazon |
| Proton Pass | Passkeys + authenticator-style TOTP vault | Proton Pass |
We may earn a commission if you buy a YubiKey or sign up for Proton Pass through the links above.

Independent cybersecurity audits
We audited publisher, catalog, and identity hosts on August 22, 2026. 100% is the ideal. None reach it. These scores are public email / transport / website posture — not a grade of Beazley’s IR work.
| Organization | Domain | Overall | vs 100% |
|---|---|---|---|
| HackerOne | hackerone.com | 88% | −12 |
| NIST | nist.gov | 84% | −16 |
| Beazley Security | beazley.security | 78% | −22 |
| Microsoft | microsoft.com | 71% | −29 |
| CISA | cisa.gov | 70% | −30 |
| Beazley | beazley.com | 68% | −32 |
| Domain | Identity | Transport | Website |
|---|---|---|---|
| hackerone.com | 85% | 100% | 98% |
| nist.gov | 90% | 45% | 87% |
| beazley.security | 75% | 15% | 90% |
| microsoft.com | 90% | 70% | 37% |
| cisa.gov | 90% | 45% | 40% |
| beazley.com | 90% | 15% | 37% |
beazley.com and beazley.security share the familiar 15% transport gap (MTA-STS / related). hackerone.com is the only host at 100% transport. Soft transport on a cyber insurer’s own brand is exactly the spoof window “your renewal questionnaire” mail abuses.
Audit links: hackerone.com · nist.gov · beazley.security · microsoft.com · cisa.gov · beazley.com

Website stack note
Passive website-tech probes on August 22, 2026:
| Domain | Stack signal |
|---|---|
| beazley.security | Webflow (vendor-managed SaaS) |
| beazley.com | Stack undetected; TLS to Oct 6, 2026 |
| cisa.gov | Drupal 11 (probe: not at 11.4.5) |
| nist.gov | Drupal 10 (probe: not at 11.4.5) |
| hackerone.com | Drupal (version hidden) |
| microsoft.com | Stack undetected |
Point-in-time only. An older public CMS is not proof of a Beazley or CISA incident.
Blacklist, lookalikes, CourtListener
Email blacklist checks (public DoH, August 22, 2026): beazley.security, beazley.com, cisa.gov, nist.gov, hackerone.com, and microsoft.com were clear on mail/domain lists we can query. Apex/CDN SPFBL notes on Cloudflare or Microsoft edges are not mail-reputation hits.
DNS lookalike scan of beazley.com (BEC profile, registered signals): 25 to review, 0 likely owned pointing at the brand, 3 BEC staging. beazley.security is the legitimate Security site (tld-swap of .com), not a squat.
| Lookalike | Technique | Note |
|---|---|---|
| beaziey.com | homoglyph | BEC staging (NS, MX) |
| beazley.biz / beazley.org | tld-swap | BEC staging (NS, MX) |
| baezley.com / beazely.com / beazly.com | transposition / omission | Registered — investigate |
| beasley.com | adjacent-key | Beasley is a real other brand, not proof of this report |
cisa.gov standard scan: 14 registered lookalikes, 0 BEC staging. cia.gov is the CIA, not a CISA typo.
CourtListener RECAP: no Texas Southern/Western docket naming Beazley after 2026-01-01, and no matching “device code” phishing filing after that date. This report is not a lawsuit.
What to do with this report
- Prioritize credentials on VPN / RDP / email — that is still 67% of Beazley’s ransomware cases.
- Block or tightly control Microsoft device-code flow and train staff never to type a code from a chat or SMS.
- Enroll a hardware key where docs allow it (Microsoft, HackerOne, Login.gov) — then still treat unexpected “approve this TV login” prompts as hostile.
- Patch KEVs first, not the entire 20k CVE firehose. NIST is already triaging enrichment.
- Document MFA for insurance the way cyber insurance controls already warn: attest only what you can prove on remote access and backup admin.
- Aim email posture at 100% — DMARC
p=reject, MTA-STS — so spoofed “Beazley questionnaire” and “CISA advisory” mail fails earlier.
Related coverage
- IBM Cost of a Data Breach 2026
- Cyber insurance: controls decide coverage
- Five Eyes AI cyberattacks warning
- Mozilla Firefox Mythos vulnerabilities
- MFA directory — YubiKey, TOTP, passkeys
- National banks MFA scorecard
Run a free audit at audit.emailmenow.com or contact EmailMeNow for DMARC / MTA-STS and MFA baselines aimed at the 100% ideal.
Sources: Beazley Security Q2 2026 Quarterly Threat Report · Beazley news release · PR Newswire, Aug 18, 2026 · PropertyCasualty360, Aug 19, 2026 · Insurance Journal · HackerOne 2FA / security keys · Login.gov authentication methods · CISA MFA. Independent EmailMeNow audits, website-tech, blacklist, cybersquat, and CourtListener searches August 22, 2026. Domain scores: audit.emailmenow.com only.