Trending Topics

CISA issues guidance on how organisations can handle the “Patch Apocalypse”
The US Cybersecurity and Infrastructure Security Agency (CISA) has released two vital pieces of guidance for organisations facing the fallout from the so-called patch apocalypse.
The first is a vulnerability review across the 2024/2025 fiscal years. It provides the practical steps organisations should be taking to address the kind of flaws that threat actors continue to exploit at scale.
The second offers guidance from the perspective of internet exposure reduction. This uses red-team assessments to show how differences in visibility, logging, network segmentation and incident response can determine whether defenders quickly detect an intrusion or allow attackers to move through an environment largely unnoticed.
But first, what do we mean by the patch apocalypse? “It used to be that the big players dumped a few dozen patches per month,” wrote IT manager Michael Dear earlier this month for TechFinitive. “We, as an IT team, would sort through them and apply them. Now, Google and Adobe have moved to weekly or bi-weekly patching. Others, notably Microsoft, are dropping a thousand patches a month.”
And there’s one thing to credit for this: AI. (By the way, note I don’t say “blame”.)
Both in-house security teams and bug bounty hunters are increasingly using AI to uncover often long-hidden vulnerabilities in codebases.
“The ebb and flow of the ‘Patch Apocalypse’ continues with no sign of slowing yet,” Todd Schell, Principal Product Manager at Ivanti, told me. This matters, as it makes the triaging of Common Vulnerabilities and Exposures more essential than ever; it’s not just a matter of high-severity first, as risk assessment doesn’t work like that.
“The patches need to be triaged to identify those CVEs that require immediate attention, including those tied to known exploitation or disclosure, known malware, CISA’s KEV list, or internet-facing or unauthenticated vulnerabilities,” Schell advised.
CISA guidance on the Patch Apocalypse
Which brings us nicely to the latest CISA guidance.
The CISA Vulnerability Review helps organisations to establish a baseline understanding of the current vulnerability landscape before Al-enabled vulnerability discovery becomes even more widespread.
And this unstoppable tide of vulnerability discovery won’t slow down until all flaws have been uncovered. “A long vulnerability list doesn’t tell defenders what an attacker can reach,” Piyush Sharma, CEO at Tuskira said, arguing that CISA is absolutely right to push teams beyond severity scores to focus on exposure, active exploitation, automation, and technical impact.
“The next step is validating those signals in the deployed environment: which flaws create a real path to critical systems, which controls can interrupt that path, and whether remediation actually closes it,” he said.
Al can help, Sharma concluded, but only when it’s grounded in live security context across assets, identities, exposures, controls, and detections.
What can also help is the guidance offered by the August 26 CISA ‘A Tale of Two SOCs: Insights From Two Red Team Assessments’ advisory.
“One SOC caught the intrusion early and contained it,” said Nick Tausek, Lead Security Automation Architect at Swimlane, outlining the results of the analysis. “[The] other had security controls in place too, but weak detection tuning and disconnected processes gave the red team much more room to move.”
This is where the guidance comes into play.
CISA said that it “encourages organisations to routinely assess their internet-accessible assets, verify third-party remote access, remove unnecessary exposure, and secure required access using strong passwords, multifactor authentication, security patching, traffic monitoring, and a secure gateway, firewall, VPN, or other centrally managed access solution”.
AI can help again, according to Tausek: “An AI SOC can bring those signals into one investigation, preserve context as the incident develops and help determine what needs attention first.”
