Back to news
Cybersecurity Alert
August 22, 2026 by EmailMeNow IT Consulting

Beazley Q2 2026: Agentic AI Flooded CVE Lists — Ransomware Still Starts With Stolen Passwords

Beazley Security’s Q2 2026 threat report: disclosed CVEs +36%, CISA KEV +10%, but 67% of ransomware still starts with stolen VPN/RDP passwords. Device-code phishing beats MFA. Audits (ideal 100%): hackerone.com 88%, nist.gov 84%, beazley.security 78% — none at 100%.

Source: Beazley Security · PropertyCasualty360

NewsArtificial IntelligenceRansomwareMFAPhishingBECCyber InsuranceCybersecurity
CVE tickets flooding an AI research console beside a locked remote-access door still using a stolen password

Beazley Security’s Q2 2026 Quarterly Threat Report (released August 18, 2026) says agentic AI made vulnerability research much louder without changing how most attackers still get in. Newly disclosed CVEs jumped 36% quarter over quarter. Confirmed exploitation added to CISA’s Known Exploited Vulnerabilities catalog rose only 10%. In Beazley’s own ransomware investigations, 67% of intrusions still began with compromised credentials on exposed VPN and RDP.

That is the EmailMeNow read: patch the flood, but do not treat a CVE dashboard as the front door. PropertyCasualty360 recapped the same report for insurance buyers. This post cites Beazley’s published figures — it does not invent Texas-only cuts the report does not publish.

This is not a duplicate of IBM Cost of a Data Breach 2026 (Ponemon cost study) or Mozilla / Mythos Firefox patches (one vendor’s AI-found bugs). Beazley is a Q2 incident + disclosure report from a carrier’s security lab.

CVE tickets flooding an AI research console beside a locked remote-access door still using a stolen password

Snapshot

FieldBeazley Q2 2026
New CVEs (NIST published)20,755 (+36% vs Q1)
High-risk CVEs (Beazley cut)~5,600
CISA KEV additions44 (+10%)
BSL critical 0-day advisories21 (+40%)
Ransomware initial access67% stolen VPN / RDP credentials
Malware / SEO-poisoned installers14% of ransomware cases

CEO Alton Kizziah: AI made the industry’s job noisier without making the attacker’s job fundamentally different — while AI-assisted attacks are still gaining frequency.

Why the CVE flood is not the same as more breaches

Beazley Security Labs attributes the 2026 break from the old ±10% quarterly CVE band (+18.5% in Q1, then +36% in Q2) to agentic AI in research programs. Downstream strain, as Beazley lists it:

SystemWhat changed
NIST / NVDNo longer enriches every new CVE
HackerOne Internet Bug BountyPaused submissions, citing AI-assisted research
Pwn2OwnFirst-time applicant rejections (Berlin volume)
CiscoRebuilt disclosure, including bundling flaws under one CVE

Anthropic’s Mythos (and public Fable) sat in the same quarter’s export-control noise; that is context for Mozilla’s Mythos Firefox patch wave, not proof that every new CVE is already in the wild.

Of ~5,600 high-risk CVEs, Beazley issued 21 client advisories. CISA confirmed 44 as actively exploited (KEV). Most of the new paper is being found and fixed — not immediately weaponized.

The front door did not move: credentials, then BEC

Beazley responders still see financially motivated actors succeed with valid stolen passwords on internet-facing remote access. Healthcare became the largest reported ransomware sector this quarter (21%, up from 10%). Leak-site posts fell slightly vs Q1 but stayed ~60% above Q2 2025.

BEC remained one of the most common incident types Beazley handled. Attackers sit in mailboxes, add forwarding rules, and reroute payments. The Q2 twist: device-code phishing against Microsoft sign-in.

The victim types a code on a real Microsoft login page and completes real MFA. The attacker collects the session token. Microsoft researchers documented automation that starts the 15-minute code clock only after the victim clicks. A YubiKey on that Microsoft account still helps against fake login pages — it does not stop a user who finishes a genuine device-code flow.

Office worker entering a device code on a genuine-looking sign-in page while a second laptop collects a session token

MFA: YubiKey and Google Authenticator still matter — and still get bypassed

We graded public login docs for the domains this report names. Fail remains SMS/voice/email OTP. Pass is open TOTP. Strong is a documented FIDO / YubiKey-class key. Device-code / AiTM abuse is why phishing-resistant MFA plus Conditional Access that blocks device-code belongs on the same checklist.

ServiceDocumented methodsGrade
Microsoft account / EntraFIDO2 keys, passkeys, Authenticator / TOTPStrong — still phishable via device code
HackerOneYubiKey named; Google Authenticator / open TOTP required (non-SSO)Strong
Login.gov (CISA portal path)FIDO security key; Google Authenticator; PIV/CAC for eligible .govStrong
myBeazley / Beazley portalsPublic enrollment docs do not name YubiKey or open TOTPNot documented

CISA recommends phishing-resistant FIDO for everyone (More than a Password). That is policy guidance, not a claim that every cisa.gov visitor already uses a key. External CISA partner apps have documented Google Authenticator / Okta Verify; *.cisa.dhs.gov staff can use PIV.

Beazley’s own insured applications have long listed FIDO2 / YubiKey as an acceptable MFA form. That is what they ask you to attest — not a documented myBeazley self-serve key.

ProductBest forGet it
YubiKey 5C NFCUSB-C laptops + NFC phonesAmazon
YubiKey 5 NFCUSB-A desktops + NFC phonesAmazon
YubiKey 5 / 5C NFC caseKeychain protection for the keyAmazon
Proton PassPasskeys + authenticator-style TOTP vaultProton Pass

We may earn a commission if you buy a YubiKey or sign up for Proton Pass through the links above.

Hardware security key beside an authenticator app and a reminder that stolen VPN passwords still beat unpatched CVEs

Independent cybersecurity audits

We audited publisher, catalog, and identity hosts on August 22, 2026. 100% is the ideal. None reach it. These scores are public email / transport / website posture — not a grade of Beazley’s IR work.

OrganizationDomainOverallvs 100%
HackerOnehackerone.com88%−12
NISTnist.gov84%−16
Beazley Securitybeazley.security78%−22
Microsoftmicrosoft.com71%−29
CISAcisa.gov70%−30
Beazleybeazley.com68%−32
DomainIdentityTransportWebsite
hackerone.com85%100%98%
nist.gov90%45%87%
beazley.security75%15%90%
microsoft.com90%70%37%
cisa.gov90%45%40%
beazley.com90%15%37%

beazley.com and beazley.security share the familiar 15% transport gap (MTA-STS / related). hackerone.com is the only host at 100% transport. Soft transport on a cyber insurer’s own brand is exactly the spoof window “your renewal questionnaire” mail abuses.

Audit links: hackerone.com · nist.gov · beazley.security · microsoft.com · cisa.gov · beazley.com

Domain security scoreboard cards versus a 100 percent ideal

Website stack note

Passive website-tech probes on August 22, 2026:

DomainStack signal
beazley.securityWebflow (vendor-managed SaaS)
beazley.comStack undetected; TLS to Oct 6, 2026
cisa.govDrupal 11 (probe: not at 11.4.5)
nist.govDrupal 10 (probe: not at 11.4.5)
hackerone.comDrupal (version hidden)
microsoft.comStack undetected

Point-in-time only. An older public CMS is not proof of a Beazley or CISA incident.

Blacklist, lookalikes, CourtListener

Email blacklist checks (public DoH, August 22, 2026): beazley.security, beazley.com, cisa.gov, nist.gov, hackerone.com, and microsoft.com were clear on mail/domain lists we can query. Apex/CDN SPFBL notes on Cloudflare or Microsoft edges are not mail-reputation hits.

DNS lookalike scan of beazley.com (BEC profile, registered signals): 25 to review, 0 likely owned pointing at the brand, 3 BEC staging. beazley.security is the legitimate Security site (tld-swap of .com), not a squat.

LookalikeTechniqueNote
beaziey.comhomoglyphBEC staging (NS, MX)
beazley.biz / beazley.orgtld-swapBEC staging (NS, MX)
baezley.com / beazely.com / beazly.comtransposition / omissionRegistered — investigate
beasley.comadjacent-keyBeasley is a real other brand, not proof of this report

cisa.gov standard scan: 14 registered lookalikes, 0 BEC staging. cia.gov is the CIA, not a CISA typo.

CourtListener RECAP: no Texas Southern/Western docket naming Beazley after 2026-01-01, and no matching “device code” phishing filing after that date. This report is not a lawsuit.

What to do with this report

  1. Prioritize credentials on VPN / RDP / email — that is still 67% of Beazley’s ransomware cases.
  2. Block or tightly control Microsoft device-code flow and train staff never to type a code from a chat or SMS.
  3. Enroll a hardware key where docs allow it (Microsoft, HackerOne, Login.gov) — then still treat unexpected “approve this TV login” prompts as hostile.
  4. Patch KEVs first, not the entire 20k CVE firehose. NIST is already triaging enrichment.
  5. Document MFA for insurance the way cyber insurance controls already warn: attest only what you can prove on remote access and backup admin.
  6. Aim email posture at 100% — DMARC p=reject, MTA-STS — so spoofed “Beazley questionnaire” and “CISA advisory” mail fails earlier.

Run a free audit at audit.emailmenow.com or contact EmailMeNow for DMARC / MTA-STS and MFA baselines aimed at the 100% ideal.


Sources: Beazley Security Q2 2026 Quarterly Threat Report · Beazley news release · PR Newswire, Aug 18, 2026 · PropertyCasualty360, Aug 19, 2026 · Insurance Journal · HackerOne 2FA / security keys · Login.gov authentication methods · CISA MFA. Independent EmailMeNow audits, website-tech, blacklist, cybersquat, and CourtListener searches August 22, 2026. Domain scores: audit.emailmenow.com only.