Rapid7 Q2 2026 Threat Landscape Report: Vulnerability Disclosures Double, AI-Assisted Exploitation Compresses Patch Timelines
Rapid7 Q2 2026 Threat Landscape Report (TL-2026-2058) is a high-severity tracked intrusion set, first published 2026-08-18. It is attributed to APT28 with medium confidence, affects Rockwell Automation Allen-Bradley Programmable Logic Controllers, maps to 10 MITRE ATT&CK techniques (T1003.001, T1027, T1071.001), and is covered by 9 detection rules and 17 indicators of compromise.
Key facts for TL-2026-2058
- Threat ID
- TL-2026-2058
- Severity
- HIGH
- Status
- ACTIVE
- Category
- THREAT_INTEL
- First published
- 2026-08-18
- Last reviewed
- 2026-08-18
- Attribution
- APT28
- Attribution confidence
- MEDIUM
- Motivation
- UNKNOWN
- Target sectors
- government administration, finance, health, manufacturing, energy, telecoms, technology, water and wastewater, business services, defense, education
- Target regions
- North America, Europe, Africa, South Asia, Southeast Asia
- Detection rules
- 9
- Indicators of compromise
- 17
Malware and tooling in Rapid7 Q2 2026 Threat Landscape Report
Malware and tooling: AgendaCrypt, Akira, DragonForce, LockBit, RALord, coinbase cartel, inc ransom, krybit, safepay, the gentlemen, Mimikatz, Rapid7
Rapid7 Labs' Q2 2026 Threat Landscape Report finds high/critical CVE disclosures nearly doubled year-over-year (8,539 vs 4,268) while missing-authentication (CWE-306) exploitation surged 247% YoY and 62% of newly exploited flaws required no user interaction. The quarter's active-exploitation backdrop includes an APT28 (Forest Blizzard/Storm-2754) SOHO router DNS-hijacking campaign, a CyberAv3ngers (IRGC-linked) intrusion campaign against internet-exposed Rockwell Automation/Allen-Bradley PLCs, and Qilin leading ransomware activity with 263 victims, prompting Rapid7 to argue that blanket patch-cycle strategies can no longer keep pace with exposure-based risk.
How Rapid7 Q2 2026 Threat Landscape Report works
Rapid7 Labs' Q2 2026 (April-June) Threat Landscape Report documents a structural shift in the vulnerability-exploitation relationship: 8,539 new high/critical (CVSS 7.0-10.0) CVEs were disclosed, nearly double the 4,268 disclosed in Q2 2025, while the count of vulnerabilities that actually saw new exploitation held roughly flat at 40. Of those 40 actively exploited flaws, 62% (25 of 40) required no user interaction to trigger, up from 53% a year earlier, and CWE-306 (Missing Authentication for Critical Function) exploitation rose 247% YoY (45 to 156 tracked instances), alongside a 50% YoY rise in CWE-89 (SQL Injection) exploitation (318 to 476). Public PoC availability for tracked flaws grew 76% YoY (153 to 270 instances), and Rapid7's dark-web monitoring found 124 exploit/access listings across 20 underground sources covering 23 actively traded CVEs, 87% of which had public PoCs and 39% of which were confirmed exploited in the wild. Rapid7 attributes the compression between disclosure and exploitation to attacker use of automation and AI-assisted tooling, and argues that traditional blanket patch-cycle strategies can no longer keep pace, urging defenders toward exposure-based prioritization instead.
The report's nation-state section names three concurrent, still-active campaigns from the quarter. Russian actor APT28 (tracked by Microsoft as Forest Blizzard/Storm-2754, and long known as Fancy Bear/Sofacy) compromised small office/home office (SOHO) edge routers, including TP-Link consumer/small-business models, to perform DNS hijacking and adversary-in-the-middle traffic interception, enabling credential and authentication-token theft; Microsoft and the UK NCSC jointly disclosed the campaign on 2026-04-07, reporting more than 200 organizations and roughly 5,000 consumer devices affected across government, IT, telecommunications and energy sectors, with confirmed adversary-in-the-middle activity against at least three African government organizations. Separately, Iranian IRGC Cyber Electronic Command (CEC)-linked actors tracked as CyberAv3ngers (aka Shahid Kaveh Group, Storm-0784, Bauxite, UNC5691) have, since at least March 2026, been directly accessing internet-exposed Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs) using the legitimate Rockwell Studio 5000 Logix Designer engineering software -- no zero-day exploitation was required -- to alter project-file logic and manipulate HMI/SCADA displays, overriding safe-operating-parameter instruction sets and causing operational disruption and financial loss across U.S. government-facilities, water/wastewater, and energy-sector victims. CISA/FBI/NSA/EPA/DOE/US Cyber Command issued advisory AA26-097A on this campaign on 2026-04-07 and updated it on 2026-07-22 to add Siemens and Schneider Electric PLCs to the warning; Censys separately catalogued 5,219 internet-exposed Rockwell/Allen-Bradley EtherNet/IP hosts globally, 74.6% of them in the United States. A North Korean APT cluster is referenced by Rapid7 alongside the Russian and Iranian activity as a third persistent nation-state threat this quarter, though the report does not attribute a specific named campaign to it.
On the ransomware side, Qilin led Q2 2026 activity with 263 listed victims, ahead of The Gentlemen (230), DragonForce (141), Akira (116) and LockBit (107), with INC Ransom, SafePay, RALord, KryBit and Coinbase Cartel also tracked. Business services (23.5%), healthcare (22.0%) and manufacturing (21.0%) were the hardest-hit ransomware sectors; the United States accounted for 881 of the quarter's listed ransomware victims (74.2%), roughly nine times Germany's 99 (8.3%), with the UK, Canada and Italy rounding out the top five and India and Thailand emerging as new affiliate targets. Initial-access telemetry across incident-response engagements shows fake-CAPTCHA/ClickFix paste-and-run social engineering behind 31.8% of incidents, alongside device-code phishing and authentication-broker abuse and social engineering delivered via trusted platforms such as Microsoft Teams. Post-exploitation, Rapid7 observed LSASS credential dumping (commonly via Mimikatz) as a recurring technique, and reported MITRE ATT&CK technique frequency counts of T1071.001 (Application Layer Protocol: Web Protocols, 90 observations), T1027 (Obfuscated Files or Information, 86 observations) and T1105 (Ingress Tool Transfer, 70 observations) across tracked intrusions.
MITRE ATT&CK techniques used in TL-2026-2058
Credential Access
T1003.001 OS Credential Dumping: LSASS Memory; T1528 Steal Application Access Token; T1557 Adversary-in-the-Middle
Defense Evasion
T1027 Obfuscated Files or Information
Command and Control
T1071.001 Application Layer Protocol: Web Protocols
Initial Access
T1078 Valid Accounts; T1566 Phishing
Execution
T1204.001 User Execution: Malicious Link; T1204.004 User Execution: Malicious Copy and Paste
Resource Development
Affected products and versions in Rapid7 Q2 2026 Threat Landscape Report
- Rockwell Automation — Allen-Bradley Programmable Logic Controllers (PLCs)
Vulnerable versions: Internet-exposed EtherNet/IP-enabled units accessible via Studio 5000 Logix Designer - Siemens — Industrial control system PLCs
Vulnerable versions: Internet-connected OT devices added to CISA AA26-097A in the 2026-07-22 update - Schneider Electric — Industrial control system PLCs
Vulnerable versions: Internet-connected OT devices added to CISA AA26-097A in the 2026-07-22 update - TP-Link — SOHO home/small-office routers
Vulnerable versions: Internet-exposed consumer/small-office router models compromised for DNS hijacking and AiTM
Remediation for Rapid7 Q2 2026 Threat Landscape Report
Patches
- Apply vendor firmware updates to internet-exposed SOHO/edge routers (TP-Link and similar consumer/small-business models)
- Apply Rockwell Automation, Siemens and Schneider Electric PLC firmware and configuration hardening guidance issued with CISA AA26-097A
Immediate actions
- Remove internet-facing PLCs (Rockwell/Allen-Bradley, Siemens, Schneider Electric) from direct internet exposure per CISA AA26-097A
- Patch or replace vulnerable/EOL SOHO routers used for remote or hybrid work, and rotate credentials/tokens on any device suspected of DNS hijacking
- Prioritize patching for CVEs matching this quarter's exploited profile: no-user-interaction, missing-authentication (CWE-306) and SQL injection (CWE-89) flaws with public PoC
- Train users to recognize ClickFix/fake-CAPTCHA paste-and-run lures and device-code phishing prompts, especially via Microsoft Teams
Workarounds
- Disable remote/internet-facing management interfaces on PLCs and SOHO routers where patching is not immediately possible
- Block or monitor unsolicited clipboard-paste-into-Run-dialog and terminal execution patterns associated with ClickFix
Longer-term hardening
- Shift from calendar-based blanket patch cycles to exposure-based vulnerability prioritization as Rapid7 recommends
- Segment OT/ICS networks from IT and the public internet; restrict engineering software (e.g., Studio 5000 Logix Designer) access to trusted management networks
- Deploy phishing-resistant MFA (FIDO2/WebAuthn) to blunt AiTM and device-code-phishing credential theft
- Expand EDR coverage for LSASS access/credential-dumping detection given continued Mimikatz use in incident response engagements
Weaknesses (CWE) in Rapid7 Q2 2026 Threat Landscape Report
CWE-306, CWE-89
Timeline of Rapid7 Q2 2026 Threat Landscape Report
- CyberAv3ngers (Iranian IRGC CEC-linked actors) begin directly accessing internet-exposed Rockwell Automation/Allen-Bradley PLCs via Studio 5000 Logix Designer, per CISA advisory AA26-097A ('since at least March 2026').
- Start of the Q2 2026 quarter covered by Rapid7's Threat Landscape Report.
- Microsoft and the UK NCSC jointly disclose the APT28 (Forest Blizzard/Storm-2754) SOHO router DNS-hijacking and adversary-in-the-middle campaign, reporting 200+ organizations and ~5,000 consumer devices affected.
- CISA, FBI, NSA, EPA, DOE and US Cyber Command jointly publish advisory AA26-097A on Iranian-affiliated exploitation of internet-facing Rockwell/Allen-Bradley PLCs.
- End of the Q2 2026 quarter covered by Rapid7's Threat Landscape Report.
- FBI, CISA, NSA, EPA, DOE, US Cyber Command-CNMF and Treasury update advisory AA26-097A to add Siemens and Schneider Electric PLCs to the ongoing Iranian ICS/OT exploitation warning.
- Rapid7 Labs publishes the Q2 2026 Threat Landscape Report, arguing traditional blanket patch-cycle strategies can no longer keep pace with exposure-based risk.
Sources cited for Rapid7 Q2 2026 Threat Landscape Report
- New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles
- Quarterly Threat Landscape Report
- Rapid7 Finds Nearly Two-Thirds of Vulnerabilities Exploited in Q2 2026 Required No User Interaction to Initiate
- Iranian-Affiliated Cyber Actors Exploit Programmable Logic Controllers Across US Critical Infrastructure (AA26-097A)
- SOHO router compromise leads to DNS hijacking and adversary-in-the-middle attacks
- Russian State-Linked APT28 Exploits SOHO Routers in Global DNS Hijacking Campaign
- US agencies update advisory on Iranian cyber campaign targeting internet-connected PLCs in critical infrastructure
Threats related to Rapid7 Q2 2026 Threat Landscape Report
- ThreatsDay Bulletin: Iran-Linked CyberAv3ngers PLC Intrusion Campaign (AA26-097A) and OctagonPanel/Ward RAT 'BH Alert' Android Spyware Targeting Bahrain
- Iran-Linked CyberAv3ngers (BAUXITE) Exploiting Internet-Exposed Rockwell, Schneider Electric, and Siemens PLCs Across US Water, Energy, and Government Infrastructure (CISA AA26-097A)
- Forest Blizzard (Russian GRU Unit 26165) SOHO Router DNS-Hijacking Campaign Enables AitM Credential Theft Against Outlook Web Access — Operation Masquerade
- Sage Water Resources Utah saltwater disposal facility PLC intrusion — Iranian IRGC-CEC (CyberAv3ngers) logic manipulation bypasses pump safeguards
Detection coverage for TL-2026-2058
As of 2026-08-18, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2058 across Splunk SPL, Microsoft KQL and Sigma, covering 17 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.