Forescout
Reports
All Statistics
Only 3% of identified servers running Dropbear – common in embedded devices – support PQC
50% of IT devices in enterprise networks use OpenSSH versions that support PQC
In enterprise networks, IT devices most commonly support PQC on TLS (8%), while specialized devices are again left behind (5.6% for IoT and IoMT, 0.8% for OT)
A year ago, 55% of AI models failed basic vulnerability research and 93% failed exploit development tasks
Every model produced at least one false-positive run by hallucinating vulnerable paths in the OpenNDS real-world task
All tested AI models now complete vulnerability research tasks, and 50% generate working exploits autonomously
Telnet exposure in healthcare is 8%, up from 6%.
40% of the riskiest device types are new compared to last year.
75% of the riskiest device types are new compared to two years ago.
24% of devices across organizations are classified as part of the extended IoT, including IoT, OT, and IoMT.
11% of devices across organizations are classified as network equipment.
There are 3,200 unique operating system versions observed across organizations, averaging 876 versions per organization.
40% of threat actor updates in H1 2025 were attributed to state-sponsored groups.
Ransomware attacks are averaging 20 incidents per day.
50% of industrial organizations claim that supply chain threats and cybercriminal activity are their top security concern.
8% of industrial organizations claim that nation-state actors are their top security concern.
64% of industrial organizations classify their OT cybersecurity maturity as foundational.
18% of hacktivist groups targeted Asia, including the Middle East.
Less than 1% of hacktivist attacks impacted organizations in the Americas.
NoName057(16) was the most active hacktivist group, accounting for 90% of attacks analyzed. It is also cited as being behind 90% of state-aligned cyberattacks in 2024.
Four new IoMT device types were added this year to Forescout's riskiest connected devices list: imaging devices, lab equipment, healthcare workstations, and infusion pump controllers.
Since 2023, network infrastructure, especially routers, has continued to outpace endpoints as the riskiest IT devices.
Routers account for over 50% of devices with the most dangerous vulnerabilities.
Nearly 90% of SSH servers remain non-PQC-capable.
40% of OpenSSH servers on the internet now support PQC by default
SSH servers supporting PQC increased 72% from 11.5 million to over 19 million.
Total PQC-capable SSH servers grew from 6.2% to 11.8%.
Claude Opus 4.6 identified exploitable RCE vulnerabilities in 3 of 5 runs.
Telnet exposure in manufacturing is 12%, up from 5%.
Legacy Windows operating systems are most prevalent in retail (39%), healthcare (35%), and financial services (29%).
Routers account for one-third of the most critical vulnerabilities in organizational networks.
Telnet exposure in financial services is 12%, up from 3%.
Routers and switches average nearly 32 vulnerabilities per device.
11 device types appear on the riskiest devices list for the first time: Serial-to-IP Converters and Workstations (IT) Printers, Time Clocks, and RFID Readers (IoT) Power Distribution Units (PDUs), I/O Modules, and BACnet Routers (OT) Medication Dispensing Systems, Medical Image Printers, and DICOM Gateways (IoMT)
SSH is the second most common protocol observed, with rising usage in nearly every sector except retail.
Financial services organizations have 35% of their devices classified as extended IoT.
65% of devices across organizations are classified as non-traditional IT.
There are 380 unique device functions observed across organizations, averaging 164 functions per organization.
There are over 1,400 unique vulnerabilities affecting IP cameras in the dataset.
40% of IP cameras in the dataset have at least one vulnerability.
Healthcare organizations have 35% of their devices classified as extended IoT.
62% of breaches in H1 2025 involved data stored on network servers.
9% of threat actor updates in H1 2025 were attributed to hacktivists.
76% of breaches in H1 2025 stemmed from hacking or IT incidents.
There were 3,649 documented ransomware attacks in H1 2025.
Ransomware attacks grew in frequency to 608 per month, or roughly 20 per day.
Zero-day exploits increased 46% in H1 2025.
Modbus accounted for 57% of OT protocol traffic in Forescout honeypots in H1 2025.
The U.S. was the top ransomware target, accounting for 53% of all ransomware incidents, in H1 2025.