Rapid7 says AI is compressing the time between vulnerability disclosure and exploitation, making traditional patch cycles too slow to keep up. The report highlights rising βHoly Grailβ vulnerabilities, active CRINK nation-state operations, and ransomware groups like Qilin, The Gentlemen, DragonForce, Akira, and LockBit, while urging defenders to focus on exposure rather than CVSS scores. #Rapid7 #Qilin #TheGentlemen #DragonForce #Akira #LockBit #CRINK
Keypoints
- AI is accelerating both vulnerability discovery and exploitation.
- High and critical vulnerabilities doubled year over year in Q2 2026.
- βHoly Grailβ vulnerabilities now make up a large share of exploited flaws.
- Defenders should prioritize exposure reduction over monthly patch cycles.
- Qilin, The Gentlemen, DragonForce, Akira, and LockBit remained highly active.
Read More: https://www.securityweek.com/ai-driven-vulnerability-surge-breaks-the-traditional-patching-model/