Skip to main content

AI Overwhelms Patching: Rapid7 Warns of Exposure Crisis

4 min read Runtime Rebel Intel
Primary source: securityweek.com

This article was written by a language model from the source above and was not reviewed by a human before publication. Verify anything operational against the original. Editorial policy

Key points
  • Immediate impact: AI-driven vulnerability surge overwhelms traditional patching cycles, increasing attacker precision.
  • Affected systems: All digital assets, especially those with "Holy Grail" vulnerabilities requiring no credentials.
  • Remediation: Prioritise reducing network exposure and potential impact over solely relying on CVSS scores.

Advertisement

AI-Driven Vulnerability Surge Breaks Traditional Patching Model

Recent analysis from Rapid7 highlights a critical shift in the cybersecurity landscape, demonstrating that traditional patching models are increasingly ineffective against an escalating tide of vulnerabilities. The report, titled ‘the compression era’, underscores how artificial intelligence (AI) is fundamentally altering the attack surface, creating a scenario where defenders are overwhelmed by both the volume and speed of new threats, according to SecurityWeek.

This “compression era” signifies a period where vulnerabilities are disclosed at higher volumes, proof-of-concept (PoC) code appears faster, and exploitability is tested earlier. Threat actors are rapidly converting public information into operational access, outpacing traditional defensive mechanisms. The AI-driven vulnerability surge impact is profound, fundamentally challenging established security practices.

The “Compression Era” and AI’s Role

Rapid7’s analysis revealed a stark increase in high and critical vulnerabilities (CVSS 7 to 10), which doubled from 4,268 in Q2 2025 to 8,539 in Q2 2026. Simultaneously, newly exploited vulnerabilities rose by 8% to 40 during the same period. This widening gap between discovery and exploitation indicates that while many flaws exist, attackers are becoming more discerning and efficient in identifying the most impactful ones.

Christiaan Beek, Rapid7’s VP of cyber intelligence, notes that AI contributes to this surge in multiple ways. AI can both discover and facilitate exploitation, with the increasing use of “vibe coding”—where AI generates new code using old templates—leading to the reintroduction of known vulnerabilities into novel applications. This cycle creates a continuous influx of flaws, exacerbating the defender’s challenge.

Adding to this complexity is the rise of “Holy Grail” vulnerabilities, Rapid7’s term for flaws that require no credentials or user interaction for exploitation. These highly potent vulnerabilities accounted for 25 out of the 40 exploited vulnerabilities in Q2 2026, marking a significant year-over-year increase. These critical weaknesses allow attackers to achieve close-to-device or product execution without any form of authentication, representing a severe operational risk.

Understanding the Attack Surface: Beyond CVSS Scores

The traditional focus on CVSS scores for vulnerability prioritization is no longer sufficient. Beek argues that the sheer volume of vulnerabilities renders a monthly patch cycle obsolete. Instead, organisations must pivot to an exposure management in AI era mindset. This means understanding where a vulnerability exists within the network, its potential impact if exploited, and how accessible it is to attackers, rather than solely relying on a severity score.

The asymmetry between attack and defense has grown. Attackers only need one weak spot, while defenders must secure an expanding perimeter encompassing classic endpoints, APIs, and complex supply chains. This reliance on multiple vendors and interconnected systems creates a far more difficult visibility challenge for defenders.

Persistent Threats: Nation-States and Ransomware Operations

The report also highlights persistent nation-state activity from the cybersecurity axis of evil, often referred to as CRINK (China, Russia, Iran, and North Korea). These actors, with their extensive resources and long-term espionage objectives, develop highly sophisticated attack capabilities. While their motivations differ from financially driven cybercriminals, their operations contribute significantly to the overall threat landscape.

Ransomware remains a primary monetization method for criminal groups. In Q2 2026, the US was by far the most targeted country, with 881 victims compared to Germany’s 91. The most active ransomware groups Q2 2026 targeting operations included Qilin, The Gentlemen, DragonForce, Akira, and LockBit. Key sectors targeted were business services (23.5%), healthcare (22.0%), manufacturing (21.0%), technology (16.9%), and construction (16.6%).

Recommendations for Exposure Management

Given the current threat landscape, defenders must move from reactive patching to proactive exposure reduction. The significant difference between discovered and exploited vulnerabilities suggests that effective exposure management can indeed reduce risk. Prioritising based on network exposure and potential impact rather than just CVSS scores is paramount.

  • Prioritise Exposure: Identify which parts of your network are reachable by attackers and focus efforts on reducing that exposure. Understand the potential impact if a host is compromised, regardless of its raw CVSS score.
  • Beyond Patching: Acknowledge that traditional monthly patch cycles are inadequate. Implement more agile and continuous vulnerability management processes.
  • Understand “Holy Grail” Flaws: Give extreme priority to vulnerabilities that do not require credentials or user interaction, as these represent immediate and severe threats.
  • Supply Chain Visibility: Improve visibility and control over third-party dependencies and API interactions, which are increasingly targeted by attackers.
  • Resource Allocation: Allocate resources based on real-world exploitability and network impact, rather than a generic severity rating that may not reflect an organisation’s unique risk profile.

Related: Apple’s Accelerated Patch Policy: Responding to AI Exploit Generation, Iran Cyber Focus Expands: Securing Internet-Facing Vulnerabilities

Advertisement

Advertisement