The Attack Cycle is Accelerating: Announcing the Rapid7 2026 Global Threat Landscape Report

2026-03-18T19:23:49Z1f37c457135a9a2e4cf668fd73424b9494a041e9d516a8f26f8eae629588c489
ai-driven-tradecraftcisa-kevcvss-7-10identity-abuseleakixmdrmetasploitmicrosoft-teams-phishingpatch-managementpodcastquick-assistransomwarerapid7rc4-packerremote-accesssecurity-awarenesssocial-engineeringspipthreat-landscapevulnerability-exploitationvulnerability-management

What happened

Rapid7 published its 2026 Global Threat Landscape findings showing exploitation of newly disclosed high-severity (CVSS 7–10) vulnerabilities doubled year-over-year and that the median time from disclosure to inclusion on CISA’s Known Exploited Vulnerabilities list dropped to ~5 days — emphasizing that adversaries are weaponizing exposure at machine speed. Rapid7 MDR is tracking an uptick in Microsoft Teams phishing where attackers impersonate internal IT to coerce users into launching Quick Assist, granting remote access for malware deployment, data exfiltration, and lateral movement. The Meta

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
rapid7_blog
Record identifier
1f37c457135a9a2e4cf668fd73424b9494a041e9d516a8f26f8eae629588c489
Enrichment time
2026-03-18T19:23:49Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · The Attack Cycle is Accelerating: Announcing the Rapid7 2026 Global Threat Landscape Report · Baitaphish