news.mlab.sh
Back to the feed
threat-intel

Mythos Didn't Break Your Security Program. Your Exposure Window Could.

High
Summary

The vulnerability landscape is exploding, with a projected 66,000 new CVEs in 2026, and many organizations struggle to remediate them due to slow mobilization processes. The gap between vulnerability disclosure and actual patching – the ‘exposure window’ – is now a critical issue, allowing attackers to exploit vulnerabilities for weeks or months while organizations are still processing them. The article argues that proactive security teams need to shift to speed-based metrics, traditionally used by SOC teams, to effectively close the exposure window and reduce the blast radius of potential attacks. The core problem isn't the number of vulnerabilities, but the organization's ability to quickly address them.

The vulnerability landscape is exploding, with a projected 66,000 new CVEs listed in 2026. Many security teams are already drowning in a remediation backlog, struggling to keep pace with the sheer volume of new vulnerabilities. The central issue is the ‘exposure window’ – the time between a vulnerability’s disclosure and when it’s actually patched. This window is currently far too wide, allowing attackers to exploit vulnerabilities for weeks or months while organizations are still processing them.

Gartner’s CTEM framework highlights a disparity: the first three stages (scoping, discovery, prioritization, and validation) operate at machine speed, while mobilization – the final step – remains tied to organizational processes. Recent policy moves, such as CISA's BOD 26-04, acknowledge this by shifting federal agencies away from CVSS-first patching toward exploitability and asset context, but it doesn’t address the speed of mobilization.

Organizations are struggling to remediate high and critical application vulnerabilities, with an average remediation time of 55 days, and nearly half of all enterprise vulnerabilities remain unpatched after a full year. Legacy systems, OT environments, and production infrastructure are particularly vulnerable due to the potential for significant business impact if they go offline. Many findings simply land in a queue with no single team responsible for resolving them.

Traditionally, security teams operate in two distinct modes: SOC teams – the reactive side – track dwell time, mean time to respond, and containment speed, limiting damage from existing threats. VM teams, cloud security teams, and network security teams – the proactive side – track patch coverage by severity level or time to fix misconfigurations. However, AI-driven discovery is forcing both teams to operate on the same clock, highlighting the inadequacy of traditional metrics.

Attackers are now weaponizing vulnerabilities in hours, with breakout times measured in minutes. A quarterly patch rate of 90% means little if critical assets remained exploitable for weeks. The key is to understand the ‘blast radius’ – the set of reachable assets – and prioritize remediation efforts based on the paths connecting exploitable vulnerabilities to critical assets. Attack path analysis, as highlighted in the Verizon DBIR, helps visualize these paths and narrow the scope of mobilization, moving it from an unfinishable backlog to a finite set of prioritized actions.

Ultimately, the article argues that organizations need to shift their focus from simply patching vulnerabilities to actively closing the exposure window, recognizing that it will never fully close, and focusing on minimizing the potential damage if an attacker does manage to exploit a gap.

Read the full article at The Hacker News