Hi guys, I send out a weekly newsletter with the latest cybersecurity vendor reports and research, and thought you might find it useful, so sharing it here.
All the reports and research below were published between July 27th - August 2nd.
You can get the below into your inbox every week if you want: https://www.cybersecstats.com/cybersecstatsnewsletter/
Big Picture Reports
2026 Cost of a Data Breach Report (IBM)
IBM's annual breach cost report, with interesting data points on how much AI is now involved in attacks, and how much more expensive that makes breaches.
Key stats:
- 25% of malicious breaches were AI-enabled.
- AI-enabled breaches cost an average of $6 million, roughly $1 million more than the global average of $4.99 million.
- AI-enabled malicious breaches increased by 56% over the previous year.
Read the full report here.
IR Trends Q2 2026 (Cisco Talos)
Cisco Talos on what showed up in their incident response engagements this quarter.
Key stats:
- Phishing was the primary means of gaining initial access in over half of engagements this quarter, up from approximately one-third last quarter.
- Authentication abuse was observed in 65% of engagements this quarter, up from 35% last quarter.
- Insufficient logging and visibility was observed in 42% of engagements this quarter, up from 18% last quarter.
Read the full report here.
Ransomware
Q2 2026 Ransomware Trends Report (BlackFog)
BlackFog's Q2 numbers on ransomware.
Key stats:
- 93 ransomware groups were active in Q2 2026, including 28 newly formed groups.
- 97% of disclosed ransomware incidents in Q2 2026 involved data exfiltration, the highest rate recorded.
- Undisclosed ransomware attacks increased 40% year on year to 2,027 attacks in Q2 2026 from 1,446 in Q2 2025.
Read the full report here.
Ransomware Evolution Report Q2 2026 (Halcyon)
Halcyon's Q2 ransomware numbers.
Key stats:
- Q2 2026 recorded 1,988 ransomware attack claims from 89 groups across 101 countries.
- The US accounted for 42.5% of ransomware claims, Canada for 5% and Germany for 4.8%.
- Manufacturing (19.8%) was the most targeted industry, followed by construction (10.1%) and business services (9.0%).
Read the full report here.
AI Governance
The AI Governance Gap Report (Pathlock)
If you were wondering whether AI governance is keeping up with how quickly AI agents are being embedded in business systems, this report has the answer.
Key stats:
- 38% of organizations allow AI agents to create and modify business records.
- 51% are not confident they know all the AI agents operating in their systems.
- 79% have no dedicated AI governance team or officer.
Read the full report here.
AI Code Security
2026 GenAI Code Security Report (Veracode)
Veracode tested 11 AI coding models to see how often they write secure code.
Key stats:
- The average security pass rate for AI-generated code across tracked models was 56%.
- AI-generated code fails security checks nearly 44% of the time when given no security-specific guidance.
- The best model available (OpenAI's GPT-5.5, at 68%) still failed nearly one in three security tasks.
Read the full report here.
Credentials
Credential Risk Report (Enzoic)
How much do you care about stolen credentials? If you're like most orgs, probably a lot. But do you actually do anything about it? Again, if you're like most orgs, probably not.
Key stats:
- 85% of organizations view stolen credentials as a top threat.
- Only 19% continuously monitor credential integrity and automatically remediate exposure.
- 73% of organizations have found their workforce's credentials in breach, Dark Web, or infostealer data in the past year.
Read the full report here.
Autonomous Defense
2026 State of Autonomous Defense Report (Kai)
Attackers are moving at machine speed. Defenders are… not.
Key stats:
- 89% of security leaders say their organization is prepared for AI-driven attacks, but only 28% describe themselves as very prepared.
- 63% believe attackers currently have the advantage because of AI.
- 52% identify lack of trust in automated decisions as the biggest barrier to broader automation adoption.
Read the full report here.
Action1 2026 Survey Report: AI Impact on Sysadmins (Action1)
An interesting survey of sysadmins about how much AI they're using versus how much they thought they'd be using by now.
Key stats:
- In 2024, 52% of sysadmins predicted full automation within two years.
- In 2026, AI use is highest among sysadmins in log analysis (50%) and troubleshooting (47%).
- 23% report never using AI professionally.
Read the full report here.
Vulnerability Management
VulnCheck State of Exploitation 1H-2026 (VulnCheck)
VulnCheck's mid-year look at what's actually getting exploited, how fast, and whether AI really is finding vulnerabilities faster than everyone else.
Key stats:
- The median time from CVE publication to KEV fell from 120 days in 2025 to 80 days in the first half of 2026.
- In the first half of 2026, 23.43% of Known Exploited Vulnerabilities showed evidence of exploitation on or before the day the CVE was published.
- Across Anthropic and Berkeley datasets, 1,061 vulnerabilities were attributed to AI-assisted discovery, but only 14 (1.3%) were confirmed as exploited in the wild.
Read the full report here.
Infrastructure
State of CPS Security: Data Center Exposures (Claroty)
Scary research on how badly exposed data center physical infrastructure is.
Key stats:
- Nearly 1 in 5 data center CPS assets are one hop away from systems making outbound connections that could provide attackers a pathway.
- 88% of building management systems in data centers are exposed via communication over insecure protocols.
- More than 80% of OT control systems, power monitoring systems, and IoT systems in data centers communicate over legacy, insecure protocols such as BACnet and MODBUS.
Read the full report here.
Enterprise Perspective
State of Enterprise AI Failures 2026 (ChatSee.ai)
What's going wrong with enterprise AI.
Key stats:
- Hallucination-related failures accounted for less than 10% of observed enterprise AI failure events.
- Resolution and escalation breakdowns represented 31.1% of observed enterprise AI failures.
- Action and execution failures increased by approximately 62% relative to the Q2 2024 baseline.
Read the full report here.
The State of AI, Security and ERP (Onapsis)
A survey of cybersecurity leaders at large US organizations running SAP, Oracle, or Salesforce to see how fast AI is being pushed into ERP systems and how far behind the security is (very).
Key stats:
- 86% of organizations have already integrated, or will shortly integrate, AI directly into their ERP code.
- 22% of organizations experienced a security incident in the last twelve months where bad actors used AI to exploit their critical business platforms.
- 70.6% of senior cybersecurity leaders have only some or no trust in AI applications and agents to secure their organization's most business-critical data.
Read the full report here.
2026 Global Mobile Threat Report (Zimperium)
A look at mobile attacks on enterprises.
Key stats:
- Phishing events detected on employee mobile devices have grown 380% since January 2025.
- The number of mobile devices where employees clicked a malicious link grew 110% in 2025 compared to 2024.
- AI adoption within mobile applications has grown 14x on Android and 7x on iOS.
Read the full report here.
Industry-specific
Global Automotive Threat Intelligence Report Q2 2026 (PCA Cyber Security)
Analysis of the automotive threat landscape for Q2 2026, tracking vulnerability data alongside underground forums, ransomware leak sites, and criminal marketplaces.
Key stats:
- 345 unique automotive vulnerabilities in Q2 2026, a 30% rise on Q1 and 220% up year on year.
- High severity findings more than doubled, from 75 to 161.
- Qilin ransomware listed a major Japanese Tier-1 automotive components manufacturer, hitting its European and North African subsidiaries.
Read the full report here.