A new report from the IT security company Check Point Software shows that the proportion of critical vulnerabilities has more than doubled in the past year. At the same time, fewer than one in twelve vulnerability alerts require immediate action. The report shows that the big challenge is no longer detecting threats, but quickly determining which ones can actually be exploited by attackers.

As AI is increasingly used by cybercriminals, both the pace and scope of attacks are increasing. Automated tools can quickly identify exposed systems, stolen credentials, and known vulnerabilities on a much larger scale than manual security teams can handle. This means that the gap between detecting a risk and fixing it is growing, while the time before a breach can occur is getting shorter.
The report's main conclusions:
- Vulnerabilities are increasing sharply: 42.6 percent of all critical exposures consisted of vulnerabilities, compared to 18.7 percent the previous year.
- Few alarms require immediate action: Only 7.8 percent of all vulnerability alerts were deemed so serious that they needed to be handled immediately after verification.
- The risks are concentrated: Vulnerabilities and internal information leaks together accounted for 76 percent of all critical exposures.
- Net fishing is increasing rapidly: The share of phishing sites among critical exposures rose from 1 percent to 10.5 percent in one year.
- Faster actions are possible: The organizations in the survey implemented 85.9 percent of the recommended security measures, showing that the right prioritization is effective.
The report also shows that effective prioritization processes produce results. In the energy sector, nearly a third of critical exposures were resolved within an hour, while healthcare had the longest response times, partly due to older IT systems and high accessibility requirements. This shows that different industries have different conditions and need to adapt their security work accordingly.

– AI allows attackers to identify and test security vulnerabilities at a pace that is difficult for security teams to handle manually, says Oscar Rodin, security expert at Check Point Software. Therefore, being able to prioritize the risks that can actually be exploited and address them quickly without disrupting operations will be crucial. It is this ability that will separate the most resilient organizations from the rest.
Read the full report here








