Uploaded August 2026 | Updated September 2026, 1 week ago
lawrence.video
Patrick Garrity of @vulncheck joins me to break down their State of
Exploitation 1H-2026 report: how fast vulnerabilities are actually being
exploited, whether AI-assisted discovery lived up to the hype, and what is genuinely getting hit in the wild.
Full report: vulncheck.com/blog/state-of-exploitation-1h-2026
Connect With Us
---------------------------------------------------
+ Hire Us for a project: lawrencesystems.com/hire-us
+ Toms' Twitter π¦ twitter.com/TomLawrenceTech
+ Our Website lawrencesystems.com
+ Our Forums forums.lawrencesystems.com
+ Instagram instagram.com/lawrencesystems
+ Facebook facebook.com/Lawrencesystems
+ GitHub github.com/lawrencesystems
Lawrence Systems Shirts and Swag
---------------------------------------------------
βΊπ lawrence.video/swag
AFFILIATES & REFERRAL LINKS
---------------------------------------------------
Amazon Affiliate Store
π amazon.com/shop/lawrencesystemspcpickup
UniFi Affiliate Link
π lawrence.video/unifi-affiliate
All Of Our Affiliates help us out and can get you discounts!
π lawrencesystems.com/partners-we-love
Gear we use on Kit
π kit.co/lawrencesystems
Use OfferCode LTSERVICES to get 10% off your order at
π https://www.techsupplydirect.com?aff=2
Digital Ocean Offer Code
π https://m.do.co/c/85de8d181725
HostiFi UniFi Cloud Hosting Service
π hostifi.net/?via=lawrencesystems
Protect your privacy with a VPN from Private Internet Access
π privateinternetaccess.com/pages/buy-vpn/LRNSYS
Patreon
π° patreon.com/lawrencesystems
Transcripts
00:00 - Intro: Where's the Vulnpocalypse?
01:19 - What VulnCheck set out to test
03:11 - Time to look at the numbers
03:41 - Finding a vulnerability isn't a path to exploitation
04:46 - CVE volume is way up, exploitation isn't
05:47 - Reactive patching vs. finding bugs first
06:49 - Developers build for working, not secure
08:23 - LangFlow, leaked API keys, and Docker Compose on GitHub
10:57 - Default configs and the CVSS 10.0 nobody turns on
12:50 - CMS, ClickFix, and the cybercrime supply chain
13:38 - Default passwords and exploits that sit unused
14:26 - Keep patching. It's not doom and gloom.
lawrence.video
Patrick Garrity of @vulncheck joins me to break down their State of
Exploitation 1H-2026 report: how fast vulnerabilities are actually being
exploited, whether AI-assisted discovery lived up to the hype, and what is genuinely getting hit in the wild.
Full report: vulncheck.com/blog/state-of-exploitation-1h-2026
Connect With Us
---------------------------------------------------
+ Hire Us for a project: lawrencesystems.com/hire-us
+ Toms' Twitter π¦ twitter.com/TomLawrenceTech
+ Our Website lawrencesystems.com
+ Our Forums forums.lawrencesystems.com
+ Instagram instagram.com/lawrencesystems
+ Facebook facebook.com/Lawrencesystems
+ GitHub github.com/lawrencesystems
Lawrence Systems Shirts and Swag
---------------------------------------------------
βΊπ lawrence.video/swag
AFFILIATES & REFERRAL LINKS
---------------------------------------------------
Amazon Affiliate Store
π amazon.com/shop/lawrencesystemspcpickup
UniFi Affiliate Link
π lawrence.video/unifi-affiliate
All Of Our Affiliates help us out and can get you discounts!
π lawrencesystems.com/partners-we-love
Gear we use on Kit
π kit.co/lawrencesystems
Use OfferCode LTSERVICES to get 10% off your order at
π https://www.techsupplydirect.com?aff=2
Digital Ocean Offer Code
π https://m.do.co/c/85de8d181725
HostiFi UniFi Cloud Hosting Service
π hostifi.net/?via=lawrencesystems
Protect your privacy with a VPN from Private Internet Access
π privateinternetaccess.com/pages/buy-vpn/LRNSYS
Patreon
π° patreon.com/lawrencesystems
Transcripts
00:00 - Intro: Where's the Vulnpocalypse?
01:19 - What VulnCheck set out to test
03:11 - Time to look at the numbers
03:41 - Finding a vulnerability isn't a path to exploitation
04:46 - CVE volume is way up, exploitation isn't
05:47 - Reactive patching vs. finding bugs first
06:49 - Developers build for working, not secure
08:23 - LangFlow, leaked API keys, and Docker Compose on GitHub
10:57 - Default configs and the CVSS 10.0 nobody turns on
12:50 - CMS, ClickFix, and the cybercrime supply chain
13:38 - Default passwords and exploits that sit unused
14:26 - Keep patching. It's not doom and gloom.










