LIVE · cybersecurity feed
Live wire
CVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical InfrastructureShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group MembersChina-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM PhishingCVE-2026-7273 · Zyxel GS1900 Switch Flaw Exploited, Now in EU CatalogueCVE-2026-102489 · Zammad Session Fixation Vulnerability Exploited Same Day as DisclosureCVE-2026-102490 · Zammad GmbH Zammad Vulnerability Exploited Same Day as Publication
breachcritical

Most open critical and high flaws are over 90 days old

A recent analysis of internet-facing systems across 1,293 organizations in the US, UK, and Nordics revealed that the vast majority of critical and high-severity vulnerabilities remain unaddressed for over 90 days. Specifically, 97% of such flaws in the Nordics, 92% in the UK, and 86% in the US had been exposed for more than three months at the time of the study.

ZeroDay News ·

Source: Help Net Security

A recent analysis of internet-facing systems across 1,293 organizations in the US, UK, and Nordics revealed that the vast majority of critical and high-severity vulnerabilities remain unaddressed for over 90 days. Specifically, 97% of such flaws in the Nordics, 92% in the UK, and 86% in the US had been exposed for more than three months at the time of the study.

The findings, based on payload-based testing that confirms exploitability, indicate that these organizations are generally aware of the vulnerabilities. While a long-lived flaw might be deliberately left open due to low asset value, existing compensating controls, or planned system retirement, the prevalence of such old vulnerabilities suggests a broader issue of "risk tolerance drift," where unaddressed flaws become implicitly accepted.

Among various sectors, public-sector organizations demonstrated the lowest remediation rate, resolving only 8.3% of their critical and high-severity findings within 90 days of detection. This contrasts sharply with consumer packaged goods and brand companies, which resolved 46.2%, followed by technology at 37.4%, financial and banking at 30.6%, and manufacturing at 23.9%. Across all severities, public bodies in the Nordics resolved 4.3% of vulnerabilities, and in the US, 2.3%.

Several factors likely contribute to the public sector's slower remediation, including extensive legacy infrastructure, fragmented ownership of systems, lengthy procurement and change-management processes, limited specialist cybersecurity capacity, and systems that cannot easily be taken offline for maintenance. Effective remediation in these environments often requires clearer asset ownership, better prioritization based on risk, and streamlined processes for addressing critical vulnerabilities.

Geographically, UK organizations actively monitor 72.4% of their verified internet-facing domains, significantly higher than the Nordics (31.9%) and the US (28.9%). However, UK customers have historically closed the lowest percentage of critical and high findings ever raised (18.6%), compared to the US (20.7%) and the Nordics (31.9%). The Nordics, despite having the highest percentage of old vulnerabilities in the snapshot, also show the highest overall closure rate, suggesting they address more issues but leave a persistent backlog.

The US has the largest measured attack surface, with its verified domains growing approximately 20% in the last year, adding over 100,000 new domains. UK domains grew 14%, and Nordic domains 3.4%.

A growing concern is the increasing number of publicly exposed AI platforms, such as Lovable and Base44, on customer estates. Early data indicates that organizations with exposed AI tooling resolve critical and high-severity flaws at less than half the rate of the general customer base. While this may not necessarily be "shadow AI," as much of it could be known and approved, it highlights a potential gap in asset visibility and governance.

Tools like Open WebUI or LibreChat can be deployed rapidly by individual teams, sometimes bypassing standard inventory, ownership, and security review processes. The challenge lies in ensuring that AI infrastructure is visible, governable, and subject to the same vulnerability management and remediation protocols as all other internet-facing assets, rather than allowing experimentation to create invisible infrastructure.

breachvulnerabilitycloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Frontline Education Breach Impacts K-12 School District Staff

Frontline Education, a prominent software provider for K-12 school districts in the United States, has confirmed a data breach that exposed the personal information of school staff. The incident, which was discovered on August 14, 2026, stemmed from a vulnerability in a third-party software product utilized by the company.

vulnerability

Google halts open-source bug bounty program amid AI spam surge

Google has temporarily suspended submissions for product vulnerabilities to its Open Source Software Vulnerability Rewards Program (OSS VRP), effective October 1, 2026. The company cited a significant increase in automated submissions, most of which were deemed invalid, as the reason for the pause.

ai

Apple tightens macOS disk access as AI agents become more powerful

Apple is implementing stricter controls for Full Disk Access in macOS, citing an increased risk to user privacy from increasingly capable and autonomous AI agents. The company indicated that future macOS versions will require users to take explicit steps to grant applications this permission. A specific rollout date and the precise mechanics of these new controls have not yet been detailed.

nation-state

doxx.net opens Agentic Defined Networking public beta, raises $38 million

doxx.net has launched the public beta of its Agentic Defined Networking (ADN) platform, which enables users and their AI agents to establish private, secure networks and communicate without intermediary servers. The company also announced it has secured $38 million in Series A funding, led by Andreessen Horowitz, with additional participation from Animo Ventures and Focal.vc. As part of the…

vulnerability

AI slop submissions force Google to freeze its open-source bug bounty

Google has temporarily halted its Open Source Software Vulnerability Reward Program (OSS VRP) for new product vulnerability submissions, effective October 1, 2026. The company cited a substantial increase in automated, AI-generated reports, most of which were invalid, as the reason for the pause. This influx of low-quality submissions overwhelmed the engineers and open-source maintainers…

nation-state

Another OpenAI Safety Expert Quits and Raises New AI Safety Concerns

David Robinson, a veteran safety expert at OpenAI, has resigned from the company, citing concerns about its culture and rapid AI development model. Robinson, who was instrumental in authoring safety reports accompanying major product launches during his three-and-a-half-year tenure, stated that he believes the company's current trajectory is unacceptable.