Forescout

84 stats8 reports

All Statistics

Only 3% of identified servers running Dropbear – common in embedded devices – support PQC

PQCSSH ServersDropbear

50% of IT devices in enterprise networks use OpenSSH versions that support PQC

PQCOpenSSHEnterprise

In enterprise networks, IT devices most commonly support PQC on TLS (8%), while specialized devices are again left behind (5.6% for IoT and IoMT, 0.8% for OT)

PQCTLSEnterprise

A year ago, 55% of AI models failed basic vulnerability research and 93% failed exploit development tasks

Vulnerability ResearchExploit DevelopmentAI SecurityAI Models

Every model produced at least one false-positive run by hallucinating vulnerable paths in the OpenNDS real-world task

False PositivesVulnerability ResearchOpenNDS

All tested AI models now complete vulnerability research tasks, and 50% generate working exploits autonomously

Vulnerability ResearchExploit DevelopmentAI SecurityAI Models

Telnet exposure in healthcare is 8%, up from 6%.

TelnetHealthcareLegacy Protocols

40% of the riskiest device types are new compared to last year.

Device RiskEnterprise

75% of the riskiest device types are new compared to two years ago.

Device RiskEnterprise

24% of devices across organizations are classified as part of the extended IoT, including IoT, OT, and IoMT.

Device DiversityIoTOTIoMT

11% of devices across organizations are classified as network equipment.

Device DiversityNetwork Equipment

There are 3,200 unique operating system versions observed across organizations, averaging 876 versions per organization.

Operating Systems

Ransomware rose 36% year over year.

Forescout2025H1 Threat Review·1y ago
ThreatsRansomware

40% of threat actor updates in H1 2025 were attributed to state-sponsored groups.

Forescout2025H1 Threat Review·1y ago
ThreatsThreat actorsState sponsored threat actors

Ransomware attacks are averaging 20 incidents per day.

Forescout2025H1 Threat Review·1y ago
ThreatsRansomware

50% of industrial organizations claim that supply chain threats and cybercriminal activity are their top security concern.

Industrial OTSupply chain

8% of industrial organizations claim that nation-state actors are their top security concern.

Industrial OTNation stateAPTs

64% of industrial organizations classify their OT cybersecurity maturity as foundational.

Industrial OTMaturity

18% of hacktivist groups targeted Asia, including the Middle East.

HacktivismAsiaMiddle East

Less than 1% of hacktivist attacks impacted organizations in the Americas.

HacktivismAmericas

NoName057(16) was the most active hacktivist group, accounting for 90% of attacks analyzed. It is also cited as being behind 90% of state-aligned cyberattacks in 2024.

Hacktivism

Four new IoMT device types were added this year to Forescout's riskiest connected devices list: imaging devices, lab equipment, healthcare workstations, and infusion pump controllers.

IoMT devices

Since 2023, network infrastructure, especially routers, has continued to outpace endpoints as the riskiest IT devices.

Network infrastructureEndpointsVulnerabilitiesIT devices

Routers account for over 50% of devices with the most dangerous vulnerabilities.

RoutersVulnerabilities

Nearly 90% of SSH servers remain non-PQC-capable.

PQCSSH Servers

40% of OpenSSH servers on the internet now support PQC by default

PQCSSH Servers

SSH servers supporting PQC increased 72% from 11.5 million to over 19 million.

PQCSSH Servers

Total PQC-capable SSH servers grew from 6.2% to 11.8%.

PQCSSH Servers

Claude Opus 4.6 identified exploitable RCE vulnerabilities in 3 of 5 runs.

Vulnerability ResearchClaude OpusRCE VulnerabilitiesExploitable Vulnerabilities

Telnet exposure in manufacturing is 12%, up from 5%.

TelnetManufacturingLegacy Protocols

Legacy Windows operating systems are most prevalent in retail (39%), healthcare (35%), and financial services (29%).

Legacy SystemsRetailHealthcareLegacy Windows OS

Routers account for one-third of the most critical vulnerabilities in organizational networks.

Network InfrastructureVulnerabilitiesRoutersCritical VulnerabilitiesEnterprise

Telnet exposure in financial services is 12%, up from 3%.

TelnetFinancial ServicesLegacy Protocols

Routers and switches average nearly 32 vulnerabilities per device.

Network InfrastructureVulnerabilitiesSwitchesRoutersEnterprise

11 device types appear on the riskiest devices list for the first time: Serial-to-IP Converters and Workstations (IT) Printers, Time Clocks, and RFID Readers (IoT) Power Distribution Units (PDUs), I/O Modules, and BACnet Routers (OT) Medication Dispensing Systems, Medical Image Printers, and DICOM Gateways (IoMT)

Connected DevicesIoTEnterprise

SSH is the second most common protocol observed, with rising usage in nearly every sector except retail.

Network ProtocolsSSHEnterprise

Financial services organizations have 35% of their devices classified as extended IoT.

Financial ServicesDevice diversityIoT

65% of devices across organizations are classified as non-traditional IT.

Device Diversity

There are 380 unique device functions observed across organizations, averaging 164 functions per organization.

Device Diversity

There are over 1,400 unique vulnerabilities affecting IP cameras in the dataset.

IP camerasVulnerabilities

40% of IP cameras in the dataset have at least one vulnerability.

IP camerasVulnerabilities

Healthcare organizations have 35% of their devices classified as extended IoT.

HealthcareDevice diversityIoT Devices

62% of breaches in H1 2025 involved data stored on network servers.

Forescout2025H1 Threat Review·1y ago
ThreatsBreachNetwork servers

9% of threat actor updates in H1 2025 were attributed to hacktivists.

Forescout2025H1 Threat Review·1y ago
ThreatsThreat actorsHacktivists

76% of breaches in H1 2025 stemmed from hacking or IT incidents.

Forescout2025H1 Threat Review·1y ago
ThreatsBreach

There were 3,649 documented ransomware attacks in H1 2025.

Forescout2025H1 Threat Review·1y ago
ThreatsRansomware

Ransomware attacks grew in frequency to 608 per month, or roughly 20 per day.

Forescout2025H1 Threat Review·1y ago
ThreatsRansomware

Zero-day exploits increased 46% in H1 2025.

Forescout2025H1 Threat Review·1y ago
ThreatsZero-day exploits

Modbus accounted for 57% of OT protocol traffic in Forescout honeypots in H1 2025.

Forescout2025H1 Threat Review·1y ago
ThreatsModbus

The U.S. was the top ransomware target, accounting for 53% of all ransomware incidents, in H1 2025.

Forescout2025H1 Threat Review·1y ago
ThreatsRansomwareUS