The podcast discusses findings from the Volchek State of Exploitation 1H 2026 report, focusing on trends in vulnerability exploitation and the evolving role of AI in cybersecurity. The report analyzes over 5,000 known exploited vulnerabilities (KEVs), a significantly broader dataset than CISA's KEV list, incorporating data from public disclosures, honeypots, and real-world canary systems. It highlights that while the total number of CVEs is rising sharply, only a small fraction are actively exploited, with exploitation rates increasing modestly by 5 - 10%. Despite claims about accelerating exploit speeds, the median time to exploit remains around 80 days, though pre-disclosure exploits still occur in over 20% of cases. Defenders are urged to focus on patching high-risk technologies like CMS platforms and using mitigations such as Web Application Firewalls.
A key theme is skepticism toward the narrative that AI is dramatically accelerating vulnerability discovery and exploitation. While AI tools are increasingly identifying flaws, the greater risk lies in the vulnerabilities present within AI products themselves - such as LangFlow, Gradio, and N8N - which are often deployed without sufficient hardening. These tools pose serious risks due to their integration with core systems, enabling credential harvesting and crypto mining. Additionally, concerns are raised about transparency and coordination in AI-driven vulnerability reporting, with examples like Anthropic's under-maintained vulnerability ledger showing major gaps between claimed discoveries and actual disclosures. The discussion underscores the need for better coordination, concise reporting, and human-led processes to manage the influx of AI-generated findings, warning against hype and emphasizing data-driven, practical approaches to security.