Recent analysis from Rapid7 demonstrates the fallacy of advocates who continue to rely on the way out of problems.
“The second quarter of 2026 was not just another busy quarter in cyberspace. It felt more like a stress test for how we currently manage exposure. Traditional patching cycles have been overwhelmed by the sheer volume of vulnerabilities and the speed and precision of attackers,” Rapid7 wrote in its latest report, titled “The Age of Compression.”
“Vulnerabilities are being disclosed in greater volume, proof-of-concept code is emerging faster, usability is being tested earlier, and attackers are getting better at turning public information into operational access.” Security Week spoke with Christian Beek, Rapid7’s VP of Cyber Intelligence to gain a deeper understanding of the cause and effect of this stress. But let’s be clear from the start: the driving force behind this stress test is artificial intelligence (AI).
Disclosures of high and critical vulnerabilities (CVSS 7 to 10) doubled from 4,268 in Q2 2025 to 8,539 in Q2 2026, notes analysis. During the same period, new exploited vulnerabilities increased by 8% to 40. The huge difference between the number of vulnerabilities discovered and the number exploited comes down to the surrounding context. “Discovery and exploitation are separate issues,” explains Beek. “AI can do both, but an attacker can’t use the exploit if the target is sitting behind multiple firewalls and other defenses.”

However, the volume of vulnerabilities discovered by AI will never decrease. New apps are constantly being released, and usually with new vulnerabilities. And then there’s the growing use of vibe encoding. “I’ve seen research on vibe-coded financial apps that contain the same vulnerabilities; indicating that the AI is using old templates to write new code that still contains the old bugs,” adds Beek. In short, vibe coding introduces vulnerabilities into new code that can then be detected by new AI scans.
The problem this creates for defenders is exacerbated by the oft-cited asymmetry between attack and defence. “Attackers only need one weak point in our environment. We have to protect so much, including the classic endpoints like laptop, computer, server, firewall. But now the landscape is changing rapidly with interactions around APIs and the supply chain. We’ve become so dependent on multiple types of providers that exposing our defenders is much more difficult than it is for an attacker. It’s a game changer,” he continues. It all points to what the report describes as “a widening gap between what is revealed and what any team can realistically sort.”
There has been an increase in what Rapid7 describes as “Holy Grail” vulnerabilities. This is Rapid7’s own term for a vulnerability that does not require credentials or user interaction. They showed a 9-point increase year over year, now accounting for 25 out of 40 exploited vulnerabilities in the second quarter of 2026. “We’ve seen a lot of them being released. As a hacker, I can run close to a device or product without needing any form of authentication – and that’s a serious disadvantage,” he explains.
The continued activity of Axis of Evil nation-states in cybersecurity (China, Russia, Iran and North Korea, often known as CRINK) is also highlighted in the report. Russia is active primarily in Ukraine and against supporters of Ukraine; Iran Targets US and US Allies; China is active against Taiwan; and North Korea is targeting anything it thinks it can monetize.
“It’s not that nation-state APTs are more advanced than financially motivated criminal gangs,” Beek commented, “rather, the motivations and resources are different. Ninety-nine percent of the nation-state’s motivation is persistence for long-term espionage and a small percentage for possible sabotage. They have the skills, the budget, and all the resources you can imagine. So they can develop much more sophisticated things than a cybercriminal would actually need.” The cybercriminal simply demands access, which can be bought. Criminals come in, steal what they can and get out.
Ransomware remains the primary monetization method and the US remains the primary target. Germany is in second place; but the numerical difference is huge. In the second quarter of 2026, there were 881 victims in the US and 91 victims in Germany.

Qilin, The Gentlemen, DragonForce, Akira and LockBit were, in that order, the most active ransomware groups; and business services (23.5%), healthcare (22.0%), manufacturing (21.0%), technology (16.9%), and construction (16.6%) are the targets.
The volume and speed of today’s AI-assisted attacks has shortened the time available for defenders to address issues. This is amply demonstrated by the latest analysis of Rapid7. The solution cannot be found by reaction – the task is to outrun the attackers. This, Beek suggests, requires reducing exposure.
The difference between the number of vulnerabilities discovered and the smaller number exploited shows that this can be effective. Defenders must understand which areas of their network can be reached by attackers and continue to reduce that exposure.
“Traditionally, we’ve looked at vulnerabilities in terms of CVE scores. Those days are gone. If you still believe we have a monthly patch cycle, forget it,” says Beek. “This no longer works. For new vulnerabilities, ignore the severity score, but focus on the exposure. Where is it on my network? What would be the impact if the host was compromised by an exploit?” It is the exposure, not the CVSS score, that is now important in vulnerabilities.
Connected: August 2026 Patch Tuesday: Microsoft fixes 421 CVE, one zero-day exploit
Connected: The Fourth Battlefield: The Growing Role of Cyber Operations in Global Conflict
Connected: Stop using CVSS for risk assessment
Connected: Act Security comes out of Stealth to combat the patch issue