Vulnerability Management Dataminr report: attackers exploit vulnerabilities faster than organizations patch August 4, 2026 Share By SC Staff As noted by Channel Insider, a new report from Dataminr highlights a growing disparity in cybersecurity, where attackers are breaching networks in minutes while organizations take weeks to patch vulnerabilities, especially in the face of AI-powered threats. Dataminr's 2026 Mid-Year Threat Landscape Report reveals that the median time to patch vulnerabilities has increased to 43 days, contrasting sharply with the average attacker breakout time of just 29 minutes. This widening gap is exacerbated by AI, which, while aiding in vulnerability detection, also creates a triage problem by increasing the volume of findings. The report questions the effectiveness of traditional Common Vulnerability Scoring System (CVSS) scores for prioritization, arguing they don't account for exploitability or business impact. Instead, Dataminr recommends a targeted approach, prioritizing remediation based on whether a vulnerability is actively targeted in a specific sector and if attackers can reach critical assets. Key findings also include a rise in phishing campaigns and significant cyber-loss events, with ransomware accounting for 25% of confirmed 2026 losses. The report concludes that organizations that prioritize patching the most critical vulnerabilities based on exploitability, exposure, and business impact, rather than solely CVSS scores, will be better positioned to stay ahead of attackers. Source: Channel Insider SC Staff Related Vulnerability Management Critical vulnerability in DNA forensic software could compromise 30 years of evidence SC Staff August 4, 2026 A group of forensic and computer scientists discovered that an AI model can be used to undetectably alter digital scans of DNA evidence created since 1995. Vulnerability Management N-able addresses critical N-central vulnerabilities exploited by attackers SC Staff August 3, 2026 Attackers leveraged an authentication bypass vulnerability, identified as CVE-2026-18556 and later expanded by CVE-2026-18577, to achieve remote administrative access to N-central servers. Vulnerability Management Critical vulnerability in Rails Active Storage could lead to RCE SC Staff August 3, 2026 The vulnerability specifically affects Active Storage versions prior to 7.2.3.2, 8.0.x before 8.0.5.1, and 8.1.x before 8.1.3.1, particularly when the libvips image processing library is in use. Related Events Cybercast State of Vulnerability Management Thu Sep 10 Cybercast Why Mythos is the cybersecurity crisis we need On-Demand Event Get daily email updates SC Media's daily must-read of the most current and pressing daily news Business Email By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy . Subscribe Related Terms Bug Buffer Overflow Disassembly You can skip this ad in 5 seconds