"Credentials are the everyday zero-day." — Todd Beebe, Freeport LNG
That line, lifted from a practitioner quoted in CyberScoop, captures the central warning of a recent argument for an offense-driven federal cyber posture: possession of valid credentials, misconfigurations and chained low-severity weaknesses often let attackers bypass months of hard work devoted to high-severity CVE patching. The piece says federal agencies are "drowning in cybersecurity data" and that raw, static outputs — long CVE lists and high Common Vulnerability Scoring System (CVSS) numbers — are poor proxies for real, immediate risk.
CISA’s BOD 26-04 and the shift from patch lists to exploitability
The author frames CISA’s issuance of BOD 26-04 as "a long-overdue pivot," arguing the directive codifies what frontline defenders already know: agencies cannot win 90‑day patch races against adversaries moving at machine speed. Static CVSS scores, the piece argues, "cannot reveal whether a flaw is reachable today, chainable with other weaknesses or capable of causing immediate mission damage." The takeaway is a call to prioritize remediation by validated exploitability and mission impact rather than by theoretical severity alone.
Why CVEs, scanners and the McNamara Fallacy mislead defenders
The author recounts decades in IT and military cyber roles and a recurring audit-day conversation: high-severity CVEs that turn out to be false positives because the vulnerable module is not running or has layers of mitigation. Vulnerability scanners, the piece warns, hand teams "thousand-page laundry lists" and force a top-down work model that exhausts time and budget before lower‑severity but chainable findings are addressed.
The article explicitly frames this problem as a modern McNamara Fallacy: measuring what is easy to count — patches applied, tickets closed, average CVSS scores — while missing operational reality. A red-team anecdote about a compliant, audited defense unit that still had immediate attack paths underscores the point: compliance does not equal security.

Your scanner finds 4,000 vulns. Which 12 matter?
Nubivance is a Rapid7 Registered Partner delivering vulnerability management as a service - scanning, risk-based prioritization, and remediation follow-through across IT and OT.
Fix the backlogAttack paths, AI acceleration, and what scanners miss
The author stresses that "vulnerable does not mean exploitable," noting teams the author and colleagues have validated "thousands of attack paths across thousands of organizations that led to critical impact without leveraging a single CVE." Attackers, the piece emphasizes, often exploit misconfigurations, weak trust relationships and stolen credentials rather than burning zero-days; AI, the author adds, "collapses the window between vulnerability disclosure and exploit execution."
NSA’s CAPT: hard numbers for continuous autonomous testing
The article points to the NSA’s Continuous Autonomous Penetration Testing (CAPT) program as operational evidence that continuous testing scales. CAPT has logged 223,833 hours of operations across 28,282 completed pentests, spanning more than 3.7 million endpoints across 822 Defense Industrial Base organizations. According to the piece, the program accelerated remediation, saved more than 340,000 labor hours and enabled lean security teams to verify and close 71% of critical findings within 30 days — an asserted contrast to annual, human-led tests that the author says yield "24 hours of confidence and 364 days of guesswork."
Operational verification: "verify the fix, not the activity"
Across standards and mandates — NIST SP 800‑53 Rev. 5, NIST CSF 2.0, federal zero trust requirements, FedRAMP and Continuous Threat Exposure Management (CTEM) — the author argues the market is shifting "from static attestation toward validation and verification." Compliance, the piece quotes Horizon3’s Director of Federal Operations Corey Brunkow saying, "is the baseline, not the finish line." The prescription is clear: agencies must safely and continuously test controls in production from multiple perspectives, and tickets should close only after targeted retests confirm the exploitable attack path is gone.
What this means for federal CISOs, CISA, and the Defense Industrial Base
- Federal CISOs and security teams: Expect pressure to move from list‑driven patch programs to continuous, exploitability‑focused testing and retesting in production; prioritize remediation by validated attack paths and mission impact.
- CISA and federal leaders: BOD 26‑04 formalizes a pivot toward real‑time prioritization; agencies will be asked to operationalize verification and to allocate resources to continuous testing that can keep pace with AI‑accelerated exploitation windows.
- Defense Industrial Base organizations: NSA’s CAPT statistics provide a model and a benchmark — continuous autonomous testing can reduce labor hours and accelerate closure of critical findings, but it requires changes in process, tooling and assumptions about what "closed" means.
The central proposition is simple and consequential: vulnerable is not synonymous with exploitable, and compliance is not a substitute for active verification. The author urges federal leaders to "turn the map around, view their networks through the eyes of the adversary and continuously validate their security posture before an opponent does." With AI compressing the time between disclosure and exploitation, the piece closes on a pointed operational demand — verify defenses in production, retest fixes, and let exploitability and mission impact drive remediation priorities.




