Urgent.News

What's breaking now, across thousands of outlets.

Science

Drowning in CVEs and thirsty for answers? Try CTEM

Boards want to know if they're less exposed than last quarter. Patching metrics aren't the solution

Drowning in CVEs and thirsty for answers? Try CTEM

For years, board executives have been asking about cybersecurity, starting with patching vulnerabilities and eventually demanding proof of security. Traditional vulnerability management and patching won't be enough to satisfy this level of scrutiny. This is where Continuous Threat Exposure Management (CTEM) comes in.

The current system relies on Common Vulnerabilities and Exposures (CVEs) and Common Vulnerability Scoring System (CVSS) scores, but there are three issues with this approach. First, there's an overwhelming number of CVEs. Second, CVSS scores are not helpful when triaging them. And third, artificial intelligence (AI) is set to make the situation even worse.

CISOs are overwhelmed with CVEs, and the industry's tools often fail to tell organizations which vulnerabilities an attacker could exploit in their environment. The number of CVEs created each year has been increasing, putting pressure on the National Vulnerability Database, which has been backed up for years.

AI is making vulnerability management more challenging. Frontier Language Models like Claude's Mythos can discover and weaponize bugs at a scale that makes it difficult for organizations to keep up. This creates an asymmetric vulnerability cycle where attackers can exploit vulnerabilities faster than organizations can patch them.

Continuous Threat Exposure Management (CTEM) is a new approach that aims to address these issues. It involves scoping, discovery, prioritization, validation, and mobilization. Automated penetration testing tools like Horizon3's NodeZero can help manage vulnerabilities by running tests across an organization's infrastructure and identifying exploitable paths.

NodeZero's deterministic machine learning approach ensures that the output is accurate and focused on the most critical vulnerabilities. By following the CTEM framework, organizations can better protect themselves from emerging threats.

Written by urgent.news from The Register Science's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

This story

This is one outlet's version. Read the fullest account.

Read the original at theregister.com →

More in Science

More from Thursday 3 September →