Image
Episode 34  •  Sep 11, 2026  •  44 Min

Patch Tuesday Overload, Broken Threat Feeds & the Scoping Problem

This is the second episode from Bishop Fox's Managed Security Services team, where they uncover three problems every practitioner is running into right now: patch volume that no longer fits inside a normal cycle, threat intelligence with no real standard for prioritization, and the question of how to actually scope a vulnerability and intel program instead of drowning in both. Sergio Villegas, Richard Brown, and Kendrick Urbaniak break down what's changed since their last conversation, and what actually holds up from the operator chair.

A single month with 108 critical CVEs breaks the patching math, not just the patching schedule. August's Patch Tuesday brought Microsoft alone more than 400 CVEs, 108 of them rated critical, against a 12-month average closer to 18. At that volume, teams end up applying patches blindly and hoping nothing breaks, then rolling back whatever does and moving to the next one in line. AI has accelerated the CVE count faster than any internal team can track its own attack surface, especially once a vulnerable version sits behind SSO or JWT and can't be fingerprinted from outside. The 30-day patch window built for non-critical issues assumed teams had time to test for breakage. That assumption is gone. Fingerprinting actual exposure, not just scanning for a CVE match, is what decides whether 400 new vulnerabilities are a triage problem or a guessing game.

There's no CVSS for threat actors, and that gap is exactly the problem. Security teams have a standardized way to score a vulnerability's severity, but nothing comparable for scoring which threat actor or indicator actually deserves attention. The Pyramid of Pain still holds up: blocking an IP or a hash is trivial and low value, while understanding a group's TTPs is hard and where the real signal lives. Whether ShinyHunters or a state sponsored APT is the bigger risk depends entirely on who you are, a distinction a flat threat feed can't make. Without defined intelligence requirements telling you which actors matter to your business, an alert feed is just noise with a timestamp.

EPSS and KEV are supposed to tell you what to patch first. Right now, both tell you after it's too late. The scores meant to prioritize vulnerabilities are lagging reality: EPSS hasn't kept pace with AI accelerated exploit development, and KEV counts failed exploitation attempts caught by honeypots alongside real compromises, muddying the signal further. Scoping a program comes down to knowing your own infrastructure: on-prem carries higher risk because a breach means lateral movement inside your own network, while cloud assets mostly put your data at risk, and vendors often patch cloud instances before the CVE is even public. When the standard scoring systems can't keep up, the fallback is knowing your infrastructure well enough to make that on-prem versus cloud call yourself.


Sergio Villegas BF Headshot

Sergio Villegas

Senior Managing Analyst

Sergio Villegas is a Senior Managing Analyst in the Attack Surface Intelligence team at Bishop Fox where he is one of the lead researchers. His main areas of focus are emerging threats, attack surface mapping, and tactical lead generation. Sergio has over 11 years of experience in cybersecurity during which he has worked as a researcher and consultant to help companies improve their procedures, technologies, and techniques around threat intelligence and threat hunting.


Richard Brown headshot

Richard Brown

Senior Managing Operator

Richard Brown is a Senior Managing Operator at Bishop Fox, where he leads a team focused on emerging threats, customer notification, exploit development, automation, and operational innovation. He partners across the organization to enhance attack surface intelligence capabilities and deliver actionable security insights to customers.

With more than 15 years of experience in cybersecurity, consulting, and law enforcement, Richard has specialized in threat intelligence, offensive security, and investigative analysis. His background as a detective in the Intelligence Division of the St. Louis Metropolitan Police Department helps shape his attacker-focused approach to identifying and understanding threats.


Ku image

Kendrick Urbaniak

Senior Operator

Kendrick Urbaniak is a Senior Operator at Bishop Fox, serving on the Threat Research Team with a focus on exploit development, vulnerability research, and offensive security innovation. He leverages extensive experience in exploit engineering, adversary tradecraft, and security research to uncover emerging threats and help organizations better understand and reduce real-world risk across modern software and infrastructure ecosystems.


Subscribe to our PODCAST

Real talk on the threats, trends, and tactics shaping security today

Listen Anywhere