Discussion about this post

User's avatar
Mykola Kondratuk's avatar

The exploitation velocity point lands hard. The window is not just shrinking - for some CVEs it is now measured in hours, not days. That breaks the prioritization models most security teams still run.

From a PM angle: most teams are tracking the wrong metric. Time-to-patch as the SLA sounds right until exploitation happens at hour 6 and your patch cycle is day 3. The actual signal is mean time between disclosure and active exploitation, and almost nobody has that instrumented.

The AI and agentic threads in this M-Trends are worth a separate read. Attack surface changes fundamentally when the agent can act on its own.

No posts

Ready for more?