AI-powered attacks are overwhelming security teams
Check Point’s «Exposure Gap Report 2026» shows that the proportion of critical security vulnerabilities has more than doubled within a year. At the same time, fewer than one in eight alerts actually require immediate action—a sign that prioritization is becoming more important than mere detection.
Automated and AI-powered attack tools are fundamentally changing both the scale and pace of cyberattacks. This is highlighted in the report «Under Pressure: The 2026 Exposure Gap Report,» published today by Check Point Software Technologies. Attackers can use these tools to test exposed systems, login credentials, phishing infrastructures, and known vulnerabilities across more organizations and at a speed that manual triage can no longer handle. The result is a growing «exposure gap»—the gap between visibility, prioritization, and secure remediation.
Security vulnerabilities have doubled
The figures speak for themselves: 42.6 percent of all risks rated as critical were vulnerabilities. Their share has more than doubled compared to the previous year’s figure of 18.7 percent, making them the largest single category of critical risks in 2026. At the same time, the report highlights a significant prioritization gap: Only 7.8 percent of vulnerability alerts warranted a «Critical» or «High» rating after an exploitability assessment. More than 90 percent, therefore, did not require increased attention for remediation.
76 percent of all critical risks stemmed from just two categories: «security vulnerabilities» and «disclosure of internal information.» The share of phishing websites among critical risks rose to 10.5 percent—a significant increase from 1 percent the previous year, making it one of the fastest-growing types of threats of the year.
A quick fix is possible—but it depends on the industry
Despite the tense situation, the report shows that vulnerabilities can be addressed quickly and securely. Across all industries, companies implemented 85.9 percent of the recommended corrective measures. A significant proportion of companies even resolved critical vulnerabilities within an hour, led by the energy sector at 30 percent. The fastest average resolution time was just 12.6 hours.
However, the risk structure varies significantly by industry. In the utilities sector and the public sector, vulnerabilities dominated, accounting for 78.2 percent and 56.4 percent of critical security vulnerabilities, respectively. In the healthcare and financial services sectors, however, the disclosure of internal information ranked first, at 63.6 percent and 42.7 percent, respectively. Despite a high remediation rate, the healthcare sector had the slowest average remediation time of 158.8 hours—due to legacy systems, availability requirements in hospitals, and strict change controls.
Exposure Management as the Key Solution
«Attackers are now testing more security vulnerabilities across more companies at a pace that security experts can no longer keep up with manually. Companies that stay one step ahead can quickly filter out the small group of truly exploitable risks from the mass of vulnerabilities and then securely remediate them without disrupting operations. That is exactly what Exposure Management does, and it is rapidly becoming a key metric for operational readiness,» says Yochai Corem, VP and General Manager of Exposure Management at Check Point Software Technologies.
Check Point Exposure Management combines detection, evidence-based prioritization, exploitability validation, control assessment, and secure remediation into a single workflow. The full report, «Under Pressure: The 2026 Exposure Gap Report,» is available for download at the following link: https://intelligence.checkpoint.com/exposure-management-gap-report/
Source: www.checkpoint.com
This article originally appeared on m-q.ch - https://www.m-q.ch/de/ki-gestuetzte-angriffe-ueberfordern-sicherheitsteams/
