This is the second episode from Bishop Fox's Managed Security Services team, where they uncover three problems every practitioner is running into right now: patch volume that no longer fits inside a normal cycle, threat intelligence with no real standard for prioritization, and the question of how to actually scope a vulnerability and intel program instead of drowning in both. Sergio Villegas, Richard Brown, and Kendrick Urbaniak break down what's changed since their last conversation, and what actually holds up from the operator chair.
A single month with 108 critical CVEs breaks the patching math, not just the patching schedule. August's Patch Tuesday brought Microsoft alone more than 400 CVEs, 108 of them rated critical, against a 12-month average closer to 18. At that volume, teams end up applying patches blindly and hoping nothing breaks, then rolling back whatever does and moving to the next one in line. AI has accelerated the CVE count faster than any internal team can track its own attack surface, especially once a vulnerable version sits behind SSO or JWT and can't be fingerprinted from outside. The 30-day patch window built for non-critical issues assumed teams had time to test for breakage. That assumption is gone. Fingerprinting actual exposure, not just scanning for a CVE match, is what decides whether 400 new vulnerabilities are a triage problem or a guessing game.
There's no CVSS for threat actors, and that gap is exactly the problem. Security teams have a standardized way to score a vulnerability's severity, but nothing comparable for scoring which threat actor or indicator actually deserves attention. The Pyramid of Pain still holds up: blocking an IP or a hash is trivial and low value, while understanding a group's TTPs is hard and where the real signal lives. Whether ShinyHunters or a state sponsored APT is the bigger risk depends entirely on who you are, a distinction a flat threat feed can't make. Without defined intelligence requirements telling you which actors matter to your business, an alert feed is just noise with a timestamp.
EPSS and KEV are supposed to tell you what to patch first. Right now, both tell you after it's too late. The scores meant to prioritize vulnerabilities are lagging reality: EPSS hasn't kept pace with AI accelerated exploit development, and KEV counts failed exploitation attempts caught by honeypots alongside real compromises, muddying the signal further. Scoping a program comes down to knowing your own infrastructure: on-prem carries higher risk because a breach means lateral movement inside your own network, while cloud assets mostly put your data at risk, and vendors often patch cloud instances before the CVE is even public. When the standard scoring systems can't keep up, the fallback is knowing your infrastructure well enough to make that on-prem versus cloud call yourself.
Subscribe to our PODCAST
Real talk on the threats, trends, and tactics shaping security today
Recommened Resources
Download
Your download is starting in a new tab. If it does not start automatically, use the button below.