https://lawrence.video/
Patrick Garrity of @vulncheck joins me to break down their State of
Exploitation 1H-2026 report: how fast vulnerabilities are actually being
exploited, whether AI-assisted discovery lived up to the hype, and what is genuinely getting hit in the wild.
Full report: https://www.vulncheck.com/blog/state-of-exploitation-1h-2026
Connect With Us
---------------------------------------------------
+ Hire Us for a project: https://lawrencesystems.com/hire-us/
+ Toms' Twitter π¦ https://twitter.com/TomLawrenceTech
+ Our Website https://www.lawrencesystems.com/
+ Our Forums https://forums.lawrencesystems.com/
+ Instagram https://www.instagram.com/lawrencesystems/
+ Facebook https://www.facebook.com/Lawrencesystems/
+ GitHub https://github.com/lawrencesystems/
Lawrence Systems Shirts and Swag
---------------------------------------------------
βΊπ https://lawrence.video/swag/
AFFILIATES & REFERRAL LINKS
---------------------------------------------------
Amazon Affiliate Store
π https://www.amazon.com/shop/lawrencesystemspcpickup
UniFi Affiliate Link
π https://lawrence.video/unifi-affiliate
All Of Our Affiliates help us out and can get you discounts!
π https://lawrencesystems.com/partners-we-love/
Gear we use on Kit
π https://kit.co/lawrencesystems
Use OfferCode LTSERVICES to get 10% off your order at
π https://www.techsupplydirect.com?aff=2
Digital Ocean Offer Code
π https://m.do.co/c/85de8d181725
HostiFi UniFi Cloud Hosting Service
π https://hostifi.net/?via=lawrencesystems
Protect your privacy with a VPN from Private Internet Access
π https://www.privateinternetaccess.com/pages/buy-vpn/LRNSYS
Patreon
π° https://www.patreon.com/lawrencesystems
Transcripts
00:00 - Intro: Where's the Vulnpocalypse?
01:19 - What VulnCheck set out to test
03:11 - Time to look at the numbers
03:41 - Finding a vulnerability isn't a path to exploitation
04:46 - CVE volume is way up, exploitation isn't
05:47 - Reactive patching vs. finding bugs first
06:49 - Developers build for working, not secure
08:23 - LangFlow, leaked API keys, and Docker Compose on GitHub
10:57 - Default configs and the CVSS 10.0 nobody turns on
12:50 - CMS, ClickFix, and the cybercrime supply chain
13:38 - Default passwords and exploits that sit unused
14:26 - Keep patching. It's not doom and gloom.