UPDATED 09:35 EDT / AUGUST 13 2026

SECURITY

Criminals have moved AI out of testing and into daily use, Flashpoint finds

A new report from threat intelligence company Flashpoint has found that criminals now use artificial intelligence in day-to-day operations, well past the experimental stage.

The 2026 Global Threat Intelligence Report: Midyear Edition covers the first six months of the year. Flashpoint’s analysts worked through 3.9 petabytes of material for it, most of it lifted from illicit forums, encrypted channels and infrastructure tied to attackers. Criminal AI toolkits came up in more than 22 million posts.

Much of the tooling has since disappeared from public view. Criminals are running custom language models with the safety guardrails stripped out, on private infrastructure they control. The uses include target profiling, malware evasion scripts, phishing content and exploit generation. Flashpoint said that makes the activity far harder to spot from outside, leaving defenders with a visibility gap.

Josh Lefkowitz, co-founder and chief executive of Flashpoint, said AI is “compressing the time between opportunity and exploitation.” Tools that once took real expertise to build now take much less of it, he said.

Infostealer malware infected 7.4 million hosts worldwide over the six months. The haul came to 1.7 billion credentials and identity artifacts. Vidar, StealC and Lumma led the field, selling subscription products that quietly harvest active browser session tokens from infected machines. Attackers who hold a live session token do not need the password.

Nearly one in five vulnerability disclosures now land with working exploit code attached. The half produced 21,667 disclosures in all. Exploit code was public for 4,015. Flashpoint logged 6,808 of them before they reached the National Vulnerability Database. More than 34% of the vulnerabilities were rated critical or high on the CVSS scale, and Flashpoint said that volume has left security teams unable to work a patching queue sorted by severity alone.

Verified ransomware victims rose 45% from the first half of 2025 to 6,256, with 2,669 of them tracked in the U.S. manufacturing led sectors at 18%. Leading the list was Qilin with 901 victims, followed by Akira, 0APT, The Gentlemen and Dragon Force. Among them, the top five accounted for 44% of activity.

Ransom revenue fell anyway. Total on-chain payments dropped about 8% to $820 million, based on Chainalysis Inc. data cited in the report. The share of victims who paid slid to 28%, which Flashpoint called a possible all-time low. Automated access tooling has pushed the average price of initial access sold on criminal markets down 69%, to $439.

The report ties military conflict in the Middle East to a rise in state-aligned cyber operations during the period. Targets included supply chains, financial institutions and industrial control systems. Flashpoint identified several wiper families used in those campaigns, with some of the tooling linked to the Handala Hack group and APT39.

“The data from the first half of 2026 suggests that cybercrime continues to operate as a service economy, with specialization at every stage,” Ian Gray, vice president of intelligence at Flashpoint, said ahead of the report’s release. “Disrupting individual campaigns remains important, but understanding the relationships between these actor ecosystems provides a much stronger indicator of where threats are heading next.”

Image: SiliconANGLE/GPT Image 2

A message from John Furrier, co-founder of SiliconANGLE:

Support our mission to keep content open and free by engaging with theCUBE community. Join theCUBE’s Alumni Trust Network, where technology leaders connect, share intelligence and create opportunities.

  • 15M+ viewers of theCUBE videos, powering conversations across AI, cloud, cybersecurity and more
  • 11.4k+ theCUBE alumni — Connect with more than 11,400 tech and business leaders shaping the future through a unique trusted-based network.

Are you AWS customer?  Support SiliconANGLE Financially by buying your AWS services from our Marketplace portal page and links.  

About SiliconANGLE Media
SiliconANGLE Media is a recognized leader in digital media innovation, uniting breakthrough technology, strategic insights and real-time audience engagement. As the parent company of SiliconANGLE, theCUBE Network, theCUBE Research, CUBE365, theCUBE AI and theCUBE SuperStudios — with flagship locations in Silicon Valley and the New York Stock Exchange — SiliconANGLE Media operates at the intersection of media, technology and AI.

Founded by tech visionaries John Furrier and Dave Vellante, SiliconANGLE Media has built a dynamic ecosystem of industry-leading digital media brands that reach 15+ million elite tech professionals. Our new proprietary theCUBE AI Video Cloud is breaking ground in audience interaction, leveraging theCUBEai.com neural network to help technology companies make data-driven decisions and stay at the forefront of industry conversations.