{
  "id": 5351826,
  "title": "Drowning in CVEs and thirsty for answers? Try CTEM",
  "url": "https://urgent.news/2026/09/03/drowning-in-cves-and-thirsty-for-answers-try-ctem",
  "topic": "tech",
  "section": "Tech",
  "published": "2026-09-03T15:00:00.000Z",
  "source": {
    "name": "The Register",
    "slug": "the-register",
    "url": "https://www.theregister.com/security/2026/09/03/sponsored-drowning-in-cves-and-thirsty-for-answers-try-ctem/5293906"
  },
  "original_language": "en",
  "account": "Board executives are now asking whether organizations are truly secure, moving beyond simple yes or no responses. Traditional vulnerability management and patching are insufficient for this new level of scrutiny. This is where Continuous Threat Exposure Management (CTEM) comes in. Traditional vulnerability management relies on Common Vulnerabilities and Exposures (CVEs) and Common Vulnerability Scoring System (CVSS) scores, which have three main issues: an overwhelming number of CVEs, CVSS scores being unhelpful for triaging, and AI making the situation worse. CISOs are overwhelmed by CVEs, with Microsoft's recent patch release containing over 500 fixes. The number of CVEs created annually has been increasing, putting strain on the National Vulnerability Database. AI is exacerbating the problem by surfacing zero-days at scale and creating and weaponizing exploits more quickly than humans. Continuous Threat Exposure Management (CTEM) offers a solution by triaging vulnerabilities based on business impact and understanding the real-world consequences. CTEM involves five steps: scoping, discovery, prioritization, validation, and mobilization. Automated pen testing tools like Horizon3's NodeZero can help manage vulnerabilities by focusing on exploitable paths and providing a shorter list of exposures for security teams and developers to address. NodeZero uses deterministic machine learning rather than general AI to avoid hallucinations and ensure accurate results.",
  "summary": "Boards want to know if they're less exposed than last quarter. Patching metrics aren't the solution",
  "key_points": [
    "Organizations are questioning true security levels beyond simple yes/no answers.",
    "Traditional vulnerability management struggles with too many CVEs and unhelpful CVSS scores."
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register Science",
        "title": "Drowning in CVEs and thirsty for answers? Try CTEM",
        "url": "https://urgent.news/2026/09/03/drowning-in-cves-and-thirsty-for-answers-try-ctem-5355566",
        "published": "2026-09-03T15:00:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}