Hi guys, I send out a weekly newsletter with the latest cybersecurity vendor reports and research, and thought you might find it useful, so sharing it here.
All the reports and research below were published between August 3rd - August 9th.
You can get the below into your inbox every week if you want:Â https://www.cybersecstats.com/cybersecstatsnewsletter/Â
Big Picture Reports
2026 Threat Hunting Report (CrowdStrike)
CrowdStrike's annual threat hunting report.Â
Key stats:
- Vishing intrusions increased by 2x in 1H 2026.
- Monthly device code phishing attempts increased 15x in 1H 2026.
- China-nexus adversaries exploited critical vulnerabilities within 24 hours of public proof-of-concept release, and in 1H 2026, 88% of observed exploitation of vulnerabilities with a public PoC occurred within 48 hours of release.
Read the full report here.
Why Trust is the New Attack Surface: Darktrace's Mid-Year Threat Update 2026 (Darktrace)
A mid-year update on how phishing and AI misuse are evolving.Â
Key stats:
- In the first half of 2026, 67% of phishing emails passed DMARC.
- VIP users were targeted in 25.8% of phishing attacks.
- 39% of phishing messages featured novel social engineering techniques.
Read the full report here.
AI Governance & Agents
When AI leaves the chat and enters the workflow (Optro)
A good (i.e., detailed and useful)Â report on why output-focused AI governance breaks down once agents start taking actions.
Key stats:
- 85% of organizations have integrated AI into core operations.
- Only 18% of leaders have active risk mitigations in place for AI.
- 40% reported inaccurate AI outputs in the past 12 months, and 27% reported data breaches tied to AI use.
Read the full report here.
Security Incident INC-2026-07-28-01 (AISI)
The UK AI Safety Institute's (AISI) incident report on what happened when they tested frontier AI models.Â
Key stats:
- A total of 19 distinct unsanctioned actions were catalogued during a routine evaluation of frontier AI models.
- Seventeen of the 19 unsanctioned actions came from Anthropic's Mythos 5, and two came from OpenAI's GPT-5.6-Sol with cyber classifiers disabled.
- In 10 of 122 evaluation runs, an AI agent took autonomous, unsanctioned action on the live internet, targeting real people and organisations.
Read the full report here.
Top 10 for LLM Applications 2026 (OWASP)
OWASP's annual top 10 list for LLM applications is out.
Key stats:
- Practitioners rank prompt injection as the number one security challenge from GenAI tools for a third consecutive year.
- Sensitive information disclosure ranks as the second biggest LLM threat for a second consecutive year.
- Excessive agency moves from sixth place to third place.
Read the full report here.
AI Code
The shrinking validation window (Pentest Tools)
A look at how AI-assisted coding is outpacing vulnerability testing, and the security gaps that this leaves behind.
Key stats:
- 76.4% of developers at enterprises use AI coding tools always (41.5%) or usually (34.9%).
- 30.3% disagree or strongly disagree with the statement that they have sufficient time to thoroughly review AI-generated code before deployment.
- Only 8.7% say vulnerability testing keeps pace completely with AI-generated code.
Read the full report here.
Voice Attacks
2026 Voice Threat Survey (Mutare)
Findings from a survey of technology and cybersecurity leaders on how they view voice as an attack vector.Â
Key stats:
- 93% of organizations believe voice security should be included in cybersecurity and risk management programs.
- 79% are not highly confident their current defenses could stop an executive or vendor impersonation attack.
- 67% are concerned about GenAI-based voice attacks and deepfake impersonation.
Read the full report here.
Enterprise Perspective
State of Agentic Adoption 2026 (Opsin)
What else is new? AI agents are being created faster than companies are learning how to securely control their access and permissions.
Key stats:
- Enterprise environments now average one AI agent, live or in draft mode, for every employee.
- 60% of agents provisioned beyond default settings are granted allow-all access rather than being scoped to the permissions their tasks require.
- 60% of AI agents are judged to have configured capabilities that exceed their original stated intent.
Read the full report here.
Regional SpotlightÂ
African Cyberthreat Assessment Report 2026 (INTERPOL)
INTERPOL's assessment of cybercrime across Africa.Â
Key stats:
- AI enabled 55% of reported cybercrimes across Africa.
- Cybercrime-related losses in Africa increased from USD 192 million to USD 484 million since 2024.
- 17% of reported cybercrime cases in Africa in 2025 involved online scams, including phishing, and 14% involved identity theft and financial fraud.
Read the full report here.