Recent analysis from Rapid7 demonstrates the fallacy of defenders continuing to rely on patching their way out of problems. The report, titled 'the compression era', highlights the stress test of the way we currently manage exposure, with traditional patch cycles being overwhelmed by the sheer volume of vulnerabilities and attacker speed and precision.
Vulnerability Surge
The disclosures of high and critical vulnerabilities (CVSS 7 to 10) doubled from 4,268 in Q2 2025 to 8,539 in Q2 2026, notes the analysis. In the same period, new exploited vulnerabilities increased 8% to 40. The huge difference between the number of vulnerabilities found and the number exploited is down to the surrounding context.
Christiaan Beek, Rapid7's VP of cyber intelligence, explains that discovery and exploitation are separate issues. "AI can do both, but an attacker cannot use the exploit if the target is sitting behind multiple firewalls and other defensive mechanisms."
Vibe Coding and Vulnerabilities
The volume of vulnerabilities found by AI is, however, never likely to decrease. New apps are continually being released, and usually with new vulnerabilities. And then there's the growing use of vibe coding. Beek adds, "I've seen research on vibe-coded financial apps that all contained the same vulnerabilities; indicating that AI is using old templates to write new code still containing the old mistakes."
Vibe coding introduces vulnerabilities into new code that can then be found by new AI scans. The problem this creates for defenders is worsened by the oft-quoted asymmetry between attack and defense. "Attackers only need one weak spot in our environment. We need to defend so much, including the classic endpoints like a laptop, a computer, a server, a firewall. But now, the landscape is changing fast with interactions around APIs and the supply chain."
Nation-State Activity
Persistent nation-state activity from the cybersecurity axis of evil (China, Russia, Iran, and North Korea, often known as CRINK) is also highlighted in the report. Russia is active primarily in Ukraine and against Ukraine's supporters; Iran is targeting the US and US allies; China is active against Taiwan; and North Korea targets anything it thinks it can monetize.
Beek comments, "It's not that nation-state APTs are any more advanced than financially motivated criminal gangs, it's more that motivations and resources are different. Ninety-nine percent of nation-state motivation requires persistence for long-term espionage and a small percentage for possible sabotage. They have the skills, the budget, and all the resources you can imagine. So, they can develop far more sophisticated stuff than a cybercriminal would actually need."
Ransomware
Ransomware remains a major method of monetization, and the US remains by far the primary target. Germany comes second; but the numerical difference is stark. In Q2 2026, there were 881 victims in the US, and 91 victims in Germany.
The most active ransomware groups were Qilin, The Gentlemen, DragonForce, Akira, and LockBit. Business services (23.5%), healthcare (22.0%), manufacturing (21.0%), technology (16.9%), and construction (16.6%) were the targets.
Solution
The solution cannot be found by reaction – the task is to get ahead of the attackers. This requires reducing exposure. The difference between the number of vulnerabilities discovered and the smaller number of those exploited demonstrates that this can be effective. Defenders need to understand what areas of their network can be reached by attackers, and continue to reduce that exposure.
Beek says, "Traditionally, we've been looking at vulnerabilities from a CVE scores perspective. Those times are over. If you still believe we have a monthly patch cycle, forget it. That doesn't work anymore. For new vulnerabilities, ignore the severity score but focus on the exposure. Where is it in my network? What would be the impact if the host is compromised by an exploit?"
It's the exposure rather than the CVSS score that is now important in vulnerabilities. By understanding the exposure, defenders can prioritize their patching efforts and reduce the risk of exploitation.
Source: SecurityWeek