{
  "id": 5355566,
  "title": "Drowning in CVEs and thirsty for answers? Try CTEM",
  "url": "https://urgent.news/2026/09/03/drowning-in-cves-and-thirsty-for-answers-try-ctem-5355566",
  "topic": "science",
  "section": "Science",
  "published": "2026-09-03T15:00:00.000Z",
  "source": {
    "name": "The Register Science",
    "slug": "the-register-science",
    "url": "https://www.theregister.com/security/2026/09/03/sponsored-drowning-in-cves-and-thirsty-for-answers-try-ctem/5293906"
  },
  "original_language": "en",
  "account": "For years, board executives have been asking about cybersecurity, starting with patching vulnerabilities and eventually demanding proof of security. Traditional vulnerability management and patching won't be enough to satisfy this level of scrutiny. This is where Continuous Threat Exposure Management (CTEM) comes in.\n\nThe current system relies on Common Vulnerabilities and Exposures (CVEs) and Common Vulnerability Scoring System (CVSS) scores, but there are three issues with this approach. First, there's an overwhelming number of CVEs. Second, CVSS scores are not helpful when triaging them. And third, artificial intelligence (AI) is set to make the situation even worse.\n\nCISOs are overwhelmed with CVEs, and the industry's tools often fail to tell organizations which vulnerabilities an attacker could exploit in their environment. The number of CVEs created each year has been increasing, putting pressure on the National Vulnerability Database, which has been backed up for years.\n\nAI is making vulnerability management more challenging. Frontier Language Models like Claude's Mythos can discover and weaponize bugs at a scale that makes it difficult for organizations to keep up. This creates an asymmetric vulnerability cycle where attackers can exploit vulnerabilities faster than organizations can patch them.\n\nContinuous Threat Exposure Management (CTEM) is a new approach that aims to address these issues. It involves scoping, discovery, prioritization, validation, and mobilization. Automated penetration testing tools like Horizon3's NodeZero can help manage vulnerabilities by running tests across an organization's infrastructure and identifying exploitable paths. NodeZero's deterministic machine learning approach ensures that the output is accurate and focused on the most critical vulnerabilities. By following the CTEM framework, organizations can better protect themselves from emerging threats.",
  "summary": "Boards want to know if they're less exposed than last quarter. Patching metrics aren't the solution",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 2,
    "also_reported_by": [
      {
        "outlet": "The Register",
        "title": "Drowning in CVEs and thirsty for answers? Try CTEM",
        "url": "https://urgent.news/2026/09/03/drowning-in-cves-and-thirsty-for-answers-try-ctem",
        "published": "2026-09-03T15:00:00.000Z"
      }
    ]
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}