AI Is Great at Finding Vulnerabilities. So Where's the Vulnpocalypse? [YouTube Release]

Additional Resources:

Patrick Garrity of @vulncheck joins me to break down their State of
Exploitation 1H-2026 report: how fast vulnerabilities are actually being
exploited, whether AI-assisted discovery lived up to the hype, and what is genuinely getting hit in the wild.

Full report: VulnCheck State of Exploitation 1H-2026 | Blog | VulnCheck

Connect With Us

Lawrence Systems Shirts and Swag

:t_shirt: Lawrence Systems

AFFILIATES & REFERRAL LINKS

Amazon Affiliate Store
:shopping_cart: Lawrence Systems's Amazon Page

UniFi Affiliate Link
:shopping_cart: Ubiquiti Store

All Of Our Affiliates help us out and can get you discounts!
:shopping_cart: Partners We Love – Lawrence Systems

Gear we use on Kit
:shopping_cart: https://kit.co/lawrencesystems

Use OfferCode LTSERVICES to get 10% off your order at
:shopping_cart: Tech Supply Direct - Premium Refurbished Servers & Workstations at Unbeatable Prices

Digital Ocean Offer Code
:shopping_cart: AI-Native Cloud | DigitalOcean

HostiFi UniFi Cloud Hosting Service
:shopping_cart: HostiFi - Fast and Reliable UniFi in the Cloud

Protect your privacy with a VPN from Private Internet Access
:shopping_cart: https://www.privateinternetaccess.com/pages/buy-vpn/LRNSYS

Patreon
:money_bag: https://www.patreon.com/lawrencesystems

Transcripts
00:00 - Intro: Where’s the Vulnpocalypse?
01:19 - What VulnCheck set out to test
03:11 - Time to look at the numbers
03:41 - Finding a vulnerability isn’t a path to exploitation
04:46 - CVE volume is way up, exploitation isn’t
05:47 - Reactive patching vs. finding bugs first
06:49 - Developers build for working, not secure
08:23 - LangFlow, leaked API keys, and Docker Compose on GitHub
10:57 - Default configs and the CVSS 10.0 nobody turns on
12:50 - CMS, ClickFix, and the cybercrime supply chain
13:38 - Default passwords and exploits that sit unused
14:26 - Keep patching. It’s not doom and gloom.