Close Menu
NCIJ Network NCIJ Network
    What's Hot

    Tesla is finally launching the Cybercab — let’s hope it’s ready

    August 18, 2026

    OpenAI president urges enterprises to hasten AI security defences

    August 18, 2026

    Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

    August 18, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Tesla is finally launching the Cybercab — let’s hope it’s ready
    • OpenAI president urges enterprises to hasten AI security defences
    • Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps
    • Trump Family Crypto Firm Tied to Chinese AI Models US Government Called a Security Risk
    • NASA Student Aviation Challenge Focuses on Nation’s Infrastructure
    • On the Great Barrier Reef, management by Traditional Owners is growing
    • Design unveiled for vessel as versatile as ‘Swiss Army knife’
    • The Guardian view on global inequality: extreme wealth threatens democracy | Editorial
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, August 18
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    AI-Driven Vulnerability Surge Breaks the Traditional Patching Model

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 18, 2026 Cybersecurity No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Recent analysis from Rapid7 demonstrates the fallacy of defenders continuing to rely on patching their way out of problems.

    “Q2 2026 was not just another busy quarter in cyber. It felt more like a stress test of the way we currently manage exposure. Traditional patch cycles are being overwhelmed by the sheer volume of vulnerabilities and attacker speed and precision,” writes Rapid7 in its latest report titled ‘the compression era’.

    “Vulnerabilities are being disclosed at higher volume, proof-of-concept code is appearing faster, exploitability is being tested earlier, and attackers are getting better at turning public information into operational access.” SecurityWeek spoke to Christiaan Beek, Rapid7’s VP of cyber intelligence for a deeper understanding of the cause and effect of this stress. But let’s be clear from the start: the compressive force behind this stress test is artificial intelligence (AI).

    Disclosures of high and critical vulnerabilities (CVSS 7 to 10) doubled from 4,268 in Q2 2025 to 8,539 in Q2 2026, notes the analysis. In the same period, new exploited vulnerabilities increased 8% to 40. The huge difference between the number of vulnerabilities found and the number exploited is down to the surrounding context. “Discovery and exploitation are separate issues,” explains Beek. “AI can do both, but an attacker cannot use the exploit if the target is sitting behind multiple firewalls and other defensive mechanisms.”

    (Image Credit: Rapid7)

    The volume of vulnerabilities found by AI is, however, never likely to decrease. New apps are continually being released, and usually with new vulnerabilities. And then there’s the growing use of vibe coding. “I’ve seen research on vibe-coded financial apps that all contained the same vulnerabilities; indicating that AI is using old templates to write new code still containing the old mistakes,” adds Beek. In short, vibe coding introduces vulnerabilities into new code that can then be found by new AI scans.

    The problem this creates for defenders is worsened by the oft-quoted asymmetry between attack and defense. “Attackers only need one weak spot in our environment. We need to defend so much, including the classic endpoints like a laptop, a computer, a server, a firewall. But now, the landscape is changing fast with interactions around APIs and the supply chain. We have become so dependent on multiple types of vendors that the exposure to visibility for our defenders is way more difficult than that for the attacker. This is changing the game,” he continues. It all points toward what the report describes as ‘a widening gap between what’s disclosed and what any team can realistically triage’.

    There has been an increase in what Rapid7 describes as ‘Holy Grail’ vulnerabilities. This is Rapid7’s own term for a vulnerability that doesn’t require credentials, or user interaction. These have shown a 9-point year over year increase, now accounting for 25 of 40 exploited vulnerabilities in Q2 2026. “We’ve seen a lot of those being released. As an attacker, I can execute close to a device or product without needing any form of authentication – and that’s a serious flaw,” he explains. 

    Advertisement. Scroll to continue reading.

    Persistent nation-state activity from the cybersecurity axis of evil (China, Russia, Iran and North Korea, often known as CRINK) is also highlighted in the report. Russia is active primarily in Ukraine and against Ukraine’s supporters; Iran is targeting the US and US allies; China is active against Taiwan; and North Korea targets anything it thinks it can monetize.

    “It’s not that nation-state APTs are any more advanced than financially motivated criminal gangs,” comments Beek, “it’s more that motivations and resources are different. Ninety-nine percent of nation-state motivation requires persistence for long term espionage and a small percentage for possible sabotage. They have the skills, the budget, and all the resources you can imagine. So, they can develop far more sophisticated stuff than a cybercriminal would actually need.” The cybercriminal just requires access, which can be bought. Criminals get in, steal what they can, and get out.

    Ransomware remains a major method of monetization, and the US remains by far the primary target. Germany comes second; but the numerical difference is stark. In Q2 2026, there were 881 victims in the US, and 91 victims in Germany.

    Ransomware Incidents by Region
    (Image Credit: Rapid7)

    Qilin, The Gentlemen, DragonForce, Akira and LockBit were, in that order, the most active ransomware groups; and business services (23.5%), healthcare (22.0%), manufacturing (21.0%), technology (16.9%), and construction (16.6%) were the targets.

    The volume and speed of today’s AI-assisted attacks has compressed the time available for defenders to patch their way out of trouble. This is amply demonstrated by Rapid7’s latest analysis. The solution cannot be found by reaction – the task is to get ahead of the attackers. This, suggests Beek, requires reducing exposure.

    The difference between the number of vulnerabilities discovered and the smaller number of those exploited demonstrates that this can be effective. Defenders need to understand what areas of their network can be reached by attackers, and continue to reduce that exposure.

    “Traditionally, we’ve been looking at vulnerabilities from a CVE scores perspective. Those times are over. If you still believe we have a monthly patch cycle, forget it,” says Beek. “That doesn’t work anymore. For new vulnerabilities, ignore the severity score but focus on the exposure. Where is it in my network? What would be the impact if the host is compromised by an exploit?” It’s the exposure rather than the CVSS score that is now important in vulnerabilities.

    Related: August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-Day

    Related: The Fourth Battlefield: The Growing Role of Cyber Operations in Global Conflict

    Related: Stop Using CVSS to Score Risk

    Related: Act Security Emerges from Stealth to Fight the Patch Problem

    AIDriven breaks model Patching surge traditional Vulnerability
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

    On the Great Barrier Reef, management by Traditional Owners is growing

    Cartesia Ships Sonic-3.6: A Streaming TTS Model That Now Leads Both Artificial Analysis Speech Arenas

    CISO Conversations: Nico Waisman – From Self-Taught Hacker to AI-Driven Offensive Security at XBOW

    TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks

    ‘Ransom Busters’: Ransomware Actor Poses as Recovery Service

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    Tesla is finally launching the Cybercab — let’s hope it’s ready

    August 18, 2026

    OpenAI president urges enterprises to hasten AI security defences

    August 18, 2026

    Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

    August 18, 2026

    Trump Family Crypto Firm Tied to Chinese AI Models US Government Called a Security Risk

    August 18, 2026
    Latest Posts

    Tether’s XAUT Gains Shariah Certification for Islamic Finance

    July 27, 2026

    Nvidia and Tech Giants Launch AI Security Alliance

    July 27, 2026

    Perplexity Releases pplx, a Single-Binary CLI That Puts Its Search API in the Terminal for Coding Agents

    July 27, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    Tesla is finally launching the Cybercab — let’s hope it’s ready

    August 18, 2026

    OpenAI president urges enterprises to hasten AI security defences

    August 18, 2026

    Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

    August 18, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.