logo

2023 Threat Landscape Year in Review: If Everything Is Critical, Nothing Is

ID: 5c9bd7ed-4b20-5072-8c5b-1106f0b3f242

STIX ID: report--5c9bd7ed-4b20-5072-8c5b-1106f0b3f242

Feed Name: Qualys Blog

Threat Score
80/100

Date Published: 2023-12-19

Date Updated: 2026-04-28

Author: Saeed Abbasi

...
...

Qualys TRU’s 2023 threat landscape review analyzes 26,447 disclosed CVEs and focuses on 206 high-risk, weaponized vulnerabilities—many exploited in the wild and used by actors like CL0P/TA505 and LockBit—highlighting that less than 1% of vulnerabilities drive the highest risk, 25% of high-risk CVEs were exploited the same day as disclosure, the mean time-to-exploit is 44 days, and that network devices and web applications account for a large share of high-risk findings; the report recommends multi-sensor vulnerability management, prioritizing known-exploited CVEs and weaponized exploits, and rapid patching and inventory of public-facing services.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.