The world of cybersecurity is in a constant state of evolution, and the latest report from Flashpoint highlights some alarming trends. In the first half of 2026, security researchers recorded a staggering 7.4 million devices infected with infostealer malware, a 27% increase from the previous six months. This equates to a massive 1.7 billion credentials harvested by hackers using infostealer malware, with Vidar, StealC, and Lumma being the top three most prolific variants. The report emphasizes that the infostealer landscape has become a fully automated threat ecosystem, capable of ingesting and orchestrating data at machine speed. This evolution is redefining the lifecycle of a breach, with threat networks connecting these malicious agents directly to raw log supply chains. Once infostealers harvest data, they immediately ingest records, parse high-value metadata, and initiate parallel credential stuffing and active session testing across thousands of environments simultaneously.
One of the most concerning aspects of this development is the role of identity as an attack surface. The report points out that the proliferation of software vulnerabilities is also on the rise, with 21,667 vulnerability disclosures over the period, an 8% increase from the previous six months. Nearly one in five (19%) of these flaws was accompanied by public or functional exploit code, and Flashpoint's Known Exploited Vulnerabilities (KEV) catalog tracked 239 flaws undergoing active, in-the-wild exploitation during H1 2026. This is a 191% increase compared to the federal CISA KEV list.
The report also highlights the surge in malicious AI activity in underground markets. Over the period, Flashpoint captured over 22 million posts related to the malicious use of AI on illicit forums and closed-chat channels. With commoditized access to open-source AI, many threat actors are deploying tooling locally, reducing their reliance on public underground networks or specially built deployment services. However, these platforms remain concentrated within rapid-delivery messaging platforms and open-source infrastructure, such as Telegram, Reddit, GitHub, and Pastebin.
Another disturbing trend noted in the report is the rise in ransomware attacks. Flashpoint counted 6256 ransomware victims in the first six months of this year, a 45% increase from the previous six months. This trend is driven by automation, low-cost initial access, and a mature ransomware-as-a-service (RaaS) ecosystem. However, there is a silver lining: fewer organizations are paying their extorters, which could potentially disrupt the ransomware business model.
In conclusion, the cybersecurity landscape is facing unprecedented challenges. The rapid evolution of infostealers, the proliferation of software vulnerabilities, the surge in malicious AI activity, and the rise in ransomware attacks all point to a more dangerous and complex environment. As threat actors become more sophisticated and automated, it is crucial for organizations to invest in robust security measures and stay vigilant to protect their data and systems.