2026-08-24NOTABLEexploitedRapid7 Q2 2026: disclosure volume doubled, exploitation did not, and missing-authentication disclosures rose 247%
Rapid7 Labs Quarterly Threat Landscape Report, Q2 2026
report · report:rapid7-quarterly-threat-landscape-q2-2026 single-source
Rapid7 Labs quarterly telemetry report for Q2 2026, published 2026-08-18: 8,539 new high- and critical-severity CVEs against 4,268 a year earlier while newly exploited vulnerabilities held roughly steady at 40; 62% of exploited flaws required no user interaction, up from 53%; missing-authentication (CWE-306) disclosures up 247% year on year; Qilin led leak-site activity with 263 victims; ClickFix, fake-CAPTCHA and collaboration-platform social engineering accounted for 31.8% of Rapid7 incident-response engagements. Its argument is that disclosure volume has outpaced any team's triage capacity, so prioritisation must run on reachable exposure (Rapid7 Labs, 2026-08-18).
Coverage
1
first 2026-08-24 → last 2026-08-24
Latest activity
2026-08-24
Rapid7 Q2 2026: disclosure volume doubled, exploitation did not, and missing-authentication disclosures rose…
Peak priority
notable
1 notable
Targets
public-sector
sectors: public-sector, healthcare, energy · regions: europe
Sources cited
1
1 hosts
Defender insights
What each entry about Rapid7 Labs Quarterly Threat Landscape Report, Q2 2026 tells a defender to do, newest first.
Story timeline
Hunting pivots
ATT&CK techniques (5 across 4 tactics)
5 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExternal Remote Services · Exploit Public-Facing Application · Phishing: Spearphishing via Service
- ExecutionUser Execution: Malicious Copy and Paste
- PersistenceExternal Remote Services
- ImpactData Encrypted for Impact
Initial Access TA0001
T1133External Remote Services×1
Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.
Evidence: 2026-08-24/rapid7-q2-2026-disclosure-volume-outpaces-triage · ATT&CK page ↗
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-08-24/rapid7-q2-2026-disclosure-volume-outpaces-triage · ATT&CK page ↗
T1566.003Phishing: Spearphishing via Service×1
Adversaries may send spearphishing messages via third-party services in an attempt to gain access to victim systems. Spearphishing via service is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of third party services rather than directly via enterprise email channels.
Evidence: 2026-08-24/rapid7-q2-2026-disclosure-volume-outpaces-triage · ATT&CK page ↗
Execution TA0002
T1204.004User Execution: Malicious Copy and Paste×1
An adversary may rely upon a user copying and pasting code in order to gain execution. Users may be subjected to social engineering to get them to copy and paste code directly into a Command and Scripting Interpreter. One such strategy is "ClickFix," in which adversaries present users with seemingly helpful solutions (such as prompts to fix errors or complete CAPTCHAs) that instead instruct the user to copy and paste malicious code.
Evidence: 2026-08-24/rapid7-q2-2026-disclosure-volume-outpaces-triage · ATT&CK page ↗
Persistence TA0003
T1133External Remote Services×1
Adversaries may leverage external-facing remote services to initially access and/or persist within a network. Remote services such as VPNs, Citrix, and other access mechanisms allow users to connect to internal enterprise network resources from external locations. There are often remote service gateways that manage connections and credential authentication for these services. Services such as Windows Remote Management and VNC can also be used externally.
Evidence: 2026-08-24/rapid7-q2-2026-disclosure-volume-outpaces-triage · ATT&CK page ↗
Impact TA0040
T1486Data Encrypted for Impact×1
Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources. They can attempt to render stored data inaccessible by encrypting files or data on local and remote drives and withholding access to a decryption key. This may be done in order to extract monetary compensation from a victim in exchange for decryption or a decryption key (ransomware) or to render data permanently inaccessible in cases where the key is not saved or transmitted.
Evidence: 2026-08-24/rapid7-q2-2026-disclosure-volume-outpaces-triage · ATT&CK page ↗
Entries about Rapid7 Labs Quarterly Threat Landscape Report, Q2 2026 (1)
Where this entity is cited
Source distribution
- rapid7.com1 (100%)