Rapid7 Q2 2026 Threat Landscape Report: Vulnerability Disclosures Double, AI-Assisted Exploitation Compresses Patch Timelines — Threadlinqs Intelligence
As of 2026-08-18, Rapid7 Q2 2026 Threat Landscape Report: Vulnerability Disclosures Double, AI-Assisted Exploitation Compresses Patch Timelines is a high-severity threat intel threat attributed to Multiple nation-state APT clusters (Multiple (Russia, Iran, North Korea)), tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 17 indicators of compromise.
Threat ID: TL-2026-2058 · Severity: HIGH · Status: ACTIVE · Category: THREAT_INTEL
Attribution: Multiple nation-state APT clusters · Multiple (Russia, Iran, North Korea) · UNKNOWN
Rapid7 Labs' Q2 2026 Threat Landscape Report finds high/critical CVE disclosures nearly doubled year-over-year (8,539 vs 4,268) while missing-authentication (CWE-306) exploitation surged 247% YoY and
Rapid7 Labs' Q2 2026 (April-June) Threat Landscape Report documents a structural shift in the vulnerability-exploitation relationship: 8,539 new high/critical (CVSS 7.0-10.0) CVEs were disclosed, nearly double the 4,268 disclosed in Q2 2025, while the count of vulnerabilities that actually saw new exploitation held roughly flat at 40. Of those 40 actively exploited flaws, 62% (25 of 40) required no user interaction to trigger, up from 53% a year earlier, and CWE-306 (Missing Authentication for Critical Function) exploitation rose 247% YoY (45 to 156 tracked instances), alongside a 50% YoY rise in CWE-89 (SQL Injection) exploitation (318 to 476). Public PoC availability for tracked flaws grew 76% YoY (153 to 270 instances), and Rapid7's dark-web monitoring found 124 exploit/access listings across 20 underground sources covering 23 actively traded CVEs, 87% of which had public PoCs and 39% of which were confirmed exploited in the wild. Rapid7 attributes the compression between disclosure and exploitation to attacker use of automation and AI-assisted tooling, and argues that traditional blanket patch-cycle strategies can no longer keep pace, urging defenders toward exposure-based prioritization instead.
The report's nation-state section names three concurrent, still-active campaigns from the quarter. Russian actor APT28 (tracked by Microsoft as Forest Blizzard/Storm-2754, and long known as Fancy Bear/Sofacy) compromised small office/home office (SOHO) edge routers, including TP-Link consumer/small-business models, to perform DNS hijacking and adversary-in-the-middle traffic interception, enabling credential and authentication-token theft; Microsoft and the UK NCSC jointly disclosed the campaign on 2026-04-07, reporting more than 200 organizations and roughly 5,000 consumer devices affected across government, IT, telecommunications and energy sectors, with confirmed adversary-in-the-middle activity against at least three African government organizations. Separately, Iranian IRGC Cyber Electronic Command (CEC)-linked actors tracked as CyberAv3ngers (aka Shahid Kaveh Group, Storm-0784, Bauxite, UNC5691) have, since at least March 2026, been directly accessing internet-exposed Rockwell Automation/Allen-Bradley programmable logic controllers (PLCs) using the legitimate Rockwell Studio 5000 Logix Designer engineering software -- no zero-day exploitation was required -- to alter project-file logic and manipulate HMI/SCADA displays, overriding safe-operating-parameter instruction sets and causing operational disruption and financial loss across U.S. government-facilities, water/wastewater, and energy-sector victims. CISA/FBI/NSA/EPA/DOE/US Cyber Command issued advisory AA26-097A on this campaign on 2026-04-07 and updated it on 2026-07-22 to add Siemens and Schneider Electric PLCs to the warning; Censys separately catalogued 5,219 internet-exposed Rockwell/Allen-Bradley EtherNet/IP hosts globally, 74.6% of them in the United States. A North Korean APT cluster is referenced by Rapid7 alongside the Russian and Iranian activity as a third persistent nation-state threat this quarter, though the report does not attribute a specific named campaign to it.
On the ransomware side, Qilin led Q2 2026 activity with 263 listed victims, ahead of The Gentlemen (230), DragonForce (141), Akira (116) and LockBit (107), with INC Ransom, SafePay, RALord, KryBit and Coinbase Cartel also tracked. Business services (23.5%), healthcare (22.0%) and manufacturing (21.0%) were the hardest-hit ransomware sectors; the United States accounted for 881 of the quarter's listed ransomware victims (74.2%), roughly nine times Germany's 99 (8.3%), with the UK, Canada and Italy rounding out the top five and India and Thailand emerging as new affiliate targets. Initial-access telemetry across incident-response engagements shows fake-CAPTCHA/ClickFix paste-and-run social engineering behind 31.8% of incidents, alongside device-code phishing and authentication-broker abuse and
Weaknesses (CWE)
CWE-306, CWE-89
Target sectors: government administration, finance, health, manufacturing, energy, telecoms, technology, water and wastewater, business services, defense, education
Target regions: North America, Europe, Africa, South Asia, Southeast Asia
Timeline
- CyberAv3ngers (Iranian IRGC CEC-linked actors) begin directly accessing internet-exposed Rockwell Automation/Allen-Bradley PLCs via Studio 5000 Logix Designer, per CISA advisory AA26-097A ('since at least March 2026').
- Start of the Q2 2026 quarter covered by Rapid7's Threat Landscape Report.
- CISA, FBI, NSA, EPA, DOE and US Cyber Command jointly publish advisory AA26-097A on Iranian-affiliated exploitation of internet-facing Rockwell/Allen-Bradley PLCs.
- Microsoft and the UK NCSC jointly disclose the APT28 (Forest Blizzard/Storm-2754) SOHO router DNS-hijacking and adversary-in-the-middle campaign, reporting 200+ organizations and ~5,000 consumer devices affected.
- End of the Q2 2026 quarter covered by Rapid7's Threat Landscape Report.
- FBI, CISA, NSA, EPA, DOE, US Cyber Command-CNMF and Treasury update advisory AA26-097A to add Siemens and Schneider Electric PLCs to the ongoing Iranian ICS/OT exploitation warning.
- Rapid7 Labs publishes the Q2 2026 Threat Landscape Report, arguing traditional blanket patch-cycle strategies can no longer keep pace with exposure-based risk.
Detections & IOCs
As of 2026-09-06, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 17 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_INTEL, HIGH, threat intelligence, cybersecurity, T1584.008, T1566, T1078, T1204.004, T1204.001, T1027, T1557, T1003.001, T1528, T1071.001