Particle.news
Download on the App Store

Exploited Vulnerabilities Overtake Stolen Credentials as Top Breach Entry, Verizon DBIR Shows

AI is compressing the time from bug discovery to exploit, overwhelming patch programs, forcing a shift to risk‑based fixes alongside AI‑enabled defenses.

Overview

  • Verizon’s 2026 Data Breach Investigations Report, published Tuesday, analyzed more than 31,000 incidents and found exploited software vulnerabilities caused about 31% of breaches, the highest share in the report’s 19‑year history.
  • Organizations are failing to keep up with known‑exploited flaws, with only 26% of CISA’s KEV items fully remediated and the median time to fully patch rising to 43 days.
  • The report shows attackers use generative AI across many steps of an attack, with the median threat actor using AI in about 15 techniques and threat actors able to shrink exploit timelines from months to hours.
  • Internal and supply‑chain risks have grown sharply, as employee use of unapproved ‘shadow AI’ rose to roughly 45% and breaches involving a third party increased about 60% to roughly 48% of all incidents.
  • Security leaders are urging faster, risk‑driven patching that prioritizes reachable CISA KEV flaws, wider use of defensive AI with human oversight, and elevating basic hygiene and third‑party oversight to reduce the expanding attack surface.