The 2026 IBM X-Force Threat Intelligence Index Report highlighted that vulnerability exploitation was the leading cause of cyberattacks in 2025, responsible for 40% of observed incidents, Infosecurity Magazine reports.Researchers found a 44% rise in cyberattacks exploiting public-facing applications, driven by artificial intelligence-enabled vulnerability scanning and missing authentication controls. Many exploited vulnerabilities did not require authentication. IBM's Global Managing Partner for Cybersecurity Services Mark Hughes said attackers are also using AI to speed up exploitation and reconnaissance. AI is also lowering operational barriers, with the technology having been tapped for synthetic identities and translation in North Korean IT worker schemes.IBM also expects multimodal AI to enable more complex automated attacks. Attackers are increasingly targeting software build environments, CI/CD pipelines, and SaaS integrations to exploit trusted relationships, driving a near fourfold rise in supply chain and third-party compromises since 2020. Manufacturing remained the most targeted sector, while North America was the most attacked region. Infostealer malware also exposed over 300,000 ChatGPT credentials in 2025.
Threat Intelligence, Vulnerability Management, AI/ML
Cyberattacks driven by vulnerability exploitation, report finds

An In-Depth Guide to AI
Get essential knowledge and practical strategies to use AI to better your security program.
Related Events
Get daily email updates
SC Media's daily must-read of the most current and pressing daily news
You can skip this ad in 5 seconds



