Rapid7 reported that AI-driven vulnerability discovery and faster attacker operationalization are outpacing traditional patch management, with high and critical vulnerability disclosures rising from 4,268 in Q2 2025 to 8,539 in Q2 2026. Newly exploited vulnerabilities also increased 8% to 40, and 25 of those were so-called "Holy Grail" flaws requiring neither credentials nor user interaction, underscoring how quickly attackers can capitalize on high-impact exposures. The report also linked the pressure to persistent nation-state activity from China, Russia, Iran, and North Korea, alongside continued ransomware operations by groups including Qilin, The Gentlemen, DragonForce, Akira, and LockBit.
Health-ISAC said the problem is especially acute in healthcare, where patching delays are often built into clinical operations because updates may require vendor validation, hospital testing, scheduled downtime, change-control approval, and sometimes regulatory review. Systems such as MRI platforms can remain exposed while those processes play out, giving attackers time to exploit weaknesses that AI helps identify and weaponize faster. Both reports said organizations should move beyond monthly patch cycles and CVSS-only prioritization, and instead focus on reducing reachable, high-impact exposure during the window when patches cannot yet be deployed.

Track how attackers are adapting to this technology.
7 events from the most recent confirmed update back to the earliest known activity.
In an article published on August 19, 2026, Health-ISAC said healthcare organizations face structural patching delays due to vendor validation, hospital testing, downtime scheduling, and possible regulatory review. It recommended reducing attacker reach and managing exposure while patches cannot yet be applied.
Rapid7 reported that the United States had 881 ransomware victims in Q2 2026, with Germany second at 91. It named Qilin, The Gentlemen, DragonForce, Akira, and LockBit as the most active ransomware groups.
Rapid7's Q2 2026 Threat Landscape Report said newly disclosed vulnerabilities with publicly available proof-of-concept code increased 76% compared with Q2 2025. The report warned that attackers can rapidly weaponize newly disclosed flaws using public information and tools.
Rapid7 said disclosures of high and critical vulnerabilities increased to 8,539 in Q2 2026, arguing that AI-driven discovery and faster attacker operationalization are compressing defenders' response windows.
Rapid7 reported that newly exploited vulnerabilities rose 8% year over year to 40 in Q2 2026. It also found that 25 of those 40 exploited flaws required neither credentials nor user interaction.
Rapid7 said 4,268 high and critical vulnerabilities with CVSS scores from 7 to 10 were disclosed in Q2 2025, providing the baseline for its later year-over-year comparison.
Rapid7 published analysis arguing that traditional monthly patch cycles and CVSS-based prioritization cannot keep pace with AI-driven vulnerability discovery and attacker speed. The report recommended prioritizing exposure, reachability, and impact instead.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
3 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcehealth-isac.org
Open sourcesecurityweek.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.