logo

Analysis of one billion CISA KEV remediation records exposes limits of human-scale security

ID: c70bffdf-1a80-5b71-a491-8d2458286ece

STIX ID: report--c70bffdf-1a80-5b71-a491-8d2458286ece

Feed Name: Bleeping Computer

Threat Score
70/100

Date Published: 2026-04-10

Date Updated: 2026-04-20

Author: Sponsored by Qualys

...
...

Qualys Threat Research Unit analysis of over one billion CISA KEV remediation records finds Time-to-Exploit has collapsed to negative seven days and the percentage of critical vulnerabilities still open at Day 7 rose from 56% to 63%. Of 52 tracked weaponized vulnerabilities, 88% were exploited faster than they were remediated—some before patches or disclosure (examples cited: Spring4Shell, Cisco IOS XE, Follina). The report argues the existing scan-and-report operational model hits a human-imposed ceiling (the "Manual Tax"), proposes new metrics (Risk Mass, Average Window of Exposure), and recommends adopting autonomous, closed-loop Risk Operations Centers to remove human latency from the remediation critical path.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.