Pontos principais
- O rápido aumento no número de vulnerabilidades e a detecção baseada em IA estão reduzindo o tempo entre a divulgação da vulnerabilidade e sua exploração ativa.
- Ciclos regulares e disciplinados de aplicação de patches ajudam a reduzir a exposição geral e a se preparar para novas vulnerabilidades (CVEs).
- A recuperação é essencial para a resiliência, mas deve ser acompanhada da aplicação oportuna de patches para corrigir vulnerabilidades.
- As organizações devem utilizar a IA para acelerar a detecção e a correção de vulnerabilidades, em vez de permitir que os problemas se acumulem nas listas de pendências.
- Os fornecedores que desempenham um papel fundamental divulgam as vulnerabilidades de forma rápida e transparente e oferecem orientações claras sobre as medidas corretivas aos clientes.
No ano passado,relatórios do setorestimaram o volume anual de CVEs na casa das dezenas de milhares, tendo o NIST posteriormente observado um crescimento recorde de CVEs e umaumento de 263% no número de registros between 2020 and 2025.
I hear what that does to a security team in real time, because I am on the calls when it happens. The old questions – what is our exposure, and how fast can we close it? – used to have room to breathe. Now they arrive faster than most teams can staff for them.
Most organizations have vulnerability response processes. Fewer have processes designed for this speed.
For years, the industry organized its response around individual vulnerabilities. A CVE would publish, severity scores would follow, enrichment would catch up, and teams would triage with some margin for judgment. That rhythm assumed a human pace of discovery, but that assumption no longer holds.
That volume is already outrunning the infrastructure built to track it. NIST has said the National Vulnerability Database is moving to a risk-based enrichment model because CVE submissions have grown faster than the program can fully process them.
AI is likely compounding pressure by helping threat actors exploit vulnerabilities, and defenders identify and validate vulnerabilities faster than legacy cataloging workflows can absorb. The window between when a vulnerability is discovered and when it is exploited is closing, and working exploit code can appear before a patch is widely deployed.
That breaks the old model. Structured vulnerability management still matters, but many programs are calibrated for a slower era: gather signal, rank risk, assign owners, then remediate. When discovery accelerates this sharply, even disciplined teams fall behind because the operating model cannot absorb the volume fast enough.
So, the unit of work must change. It no longer matters whether you patched a specific vulnerability but whether your organization can apply, verify, and recover at the speed the threat environment now demands.
Remendo em um relógio
Comece pela cadência. As operações mais resilientes que observo deixaram de tratar a aplicação de patches como uma interrupção e passaram a considerá-la uma manutenção de rotina: programada semanalmente, com responsabilidade clara e avaliada como qualquer outro compromisso operacional. Uma cadência previsível ajuda a reduzir o período de exposição em todo o ambiente de TI e a eliminar o “prêmio do pânico” associado a qualquer divulgação isolada. Quando as correções são aplicadas semanalmente, as organizações estão preparadas para lidar com as vulnerabilidades (CVEs).
A cadência não significa tratar tudo da mesma forma. Uma vulnerabilidade que está sendo explorada ativamente — do tipo que é incluída noCISA’s Known Exploited Vulnerabilities Catalog— ainda merece uma resposta imediata e fora da rotina. A programação semanal lida com o grande volume de incidentes como parte da rotina, de modo que as verdadeiras emergências recebam a atenção devida, em vez de terem que competir com o ruído de fundo.
Elimine a vulnerabilidade, não apenas a lacuna
Esta é a parte que a Recovery não consegue resolver sozinha. Se uma vulnerabilidade coloca um ativo em risco, restaurar esse ativo sem corrigir a vulnerabilidade apenas reinicia o relógio. A vulnerabilidade ainda está lá, aguardando a próxima tentativa. A Recovery é importante, mas não substitui o fechamento da brecha que permitiu a entrada do agente de ameaça.
Isso significa que o trabalho real precisa ocorrer mais cedo, no momento em que as vulnerabilidades são encontradas e corrigidas. A IA está mudando essa equação em ambos os lados. Os mesmos modelos que ajudam um agente mal-intencionado a identificar uma exploração podem ajudar um fornecedor a encontrá-la primeiro. A equipe de engenharia da Commvault utiliza IA em nossa própria base de código para identificar vulnerabilidades antes que elas sejam lançadas, e aplicamos a IA para ajudar a resolver o que encontramos, em vez de encaminhá-las para uma lista de pendências. Uma vulnerabilidade que fica na fila por semanas porque uma equipe ficou sem capacidade disponível continua sendo uma vulnerabilidade. A rapidez na detecção não significa nada sem a rapidez na resolução.
Exija mais dos seus fornecedores
When the window between discovery and exploit is measured in hours, customers cannot afford to learn about a vulnerability in their vendor’s product from a third party.
They need to hear it from the vendor, early, in plain language, with a direct answer to “Am I affected?” and “What do I do first?” Ask every critical vendor how quickly they disclose, how they notify affected customers, what evidence they provide for remediation, and how customers can validate that the exposure is closed. Vulnerability transparency is part of resilience.
The frontier AI era will not be won by whoever ships the fewest vulnerabilities. Every serious software company will disclose more. The advantage goes to whoever treats patching as a standing discipline and treats recovery as the discipline that makes a missed window survivable.
Perguntas frequentes
Q: Why is the window between vulnerability discovery and exploitation getting shorter?
A: AI is likely compounding pressure by helping threat actors exploit vulnerabilities, and defenders identify and validate vulnerabilities faster than legacy cataloging workflows can absorb. As a result, exploit code can become available before many organizations have had time to deploy patches.
Q: Why are weekly patching cycles becoming more important?
A: A consistent weekly patching schedule helps reduce the organization’s exposure to known vulnerabilities. It also allows security teams to focus immediate attention on actively exploited threats and prepare new CVEs.
Q: Is disaster recovery enough to protect against cyberattacks?
A: No. Recovery helps organizations restore operations after an incident, but restoring systems without addressing the underlying vulnerability leaves them exposed to future attacks. Effective resilience requires both rapid remediation and reliable recovery.
Q: How can AI help improve vulnerability management?
A: AI can help identify vulnerabilities earlier, prioritize remediation efforts, and accelerate the resolution process. This helps security and engineering teams respond more quickly instead of allowing vulnerabilities to remain unresolved in lengthy backlogs.
Q: What should organizations ask their software vendors about vulnerability management?
A: Organizations should ask how quickly vendors disclose vulnerabilities, how affected customers are notified, what remediation guidance is provided, and how customers can verify that the issue has been fully addressed. Transparent communication is an important part of cyber resilience.
Rajiv Kottomtharayil is Chief Products Officer at Commvault.
