Summary
The Verizon 2026 Data Breach Investigations Report (DBIR) is out, and its findings paint a sobering picture of the current threat landscape. Based on analysis of over 31,000 security incidents and 22,000 confirmed data breaches across 145 countries, this year’s report reveals a fundamental shift in how attackers are getting in: vulnerability exploitation has overtaken stolen credentials as the #1 initial access vector, accounting for 31% of breaches.
The report highlights that only 26% of critical vulnerabilities listed in CISA’s Known Exploited Vulnerabilities (KEV) catalog were fully remediated during 2025 — down from 38% the previous year. The median time to fully remediate vulnerabilities increased to 43 days, creating a growing window of exposure. Meanwhile, criminals are increasingly leveraging generative AI for target selection, malware development, vulnerability research, and social engineering.
Another major finding is the rise of “Shadow AI” — 67% of users are accessing AI services on corporate devices through non-corporate accounts, creating a massive blind spot for security teams. The report suggests this unmonitored AI usage represents an emerging data exfiltration risk that most organizations aren’t equipped to detect or control.
Source
📰 Help Net Security — Lessons from the Verizon 2026 DBIR
Commentary
The DBIR remains the single most valuable annual cybersecurity report, and this year’s central finding — that vulnerability exploitation has overtaken credential theft — should reshape security budgets. For years, organizations poured money into MFA, password managers, and phishing training. Those investments still matter, but the data now says the biggest bang for your buck is in vulnerability management and attack surface reduction.
The Shadow AI statistic (67% using personal AI accounts on corporate devices) is particularly alarming and likely underreported. Most organizations have no visibility into what employees are pasting into ChatGPT, Claude, or other AI tools. Combined with the finding that patching rates are actually declining despite more vulnerabilities being discovered, the picture is clear: defenders are losing ground on two fronts simultaneously — traditional vulnerability management and a brand-new AI data leakage vector that barely existed two years ago.
