"Think about the last patch release that Microsoft put out," Drew Vanover, principal security strategist at Horizon3, told the author. "There were over 500 fixes in one patch cycle. That is incomprehensible. Nobody is going to be able to go through, vet, prioritize, and deploy all of those in a way that is truly considered safe."
The CVE firehose, CVSS limits, and NIST's April decision
The mechanics of vulnerability management are under strain. The number of Common Vulnerabilities and Exposures (CVEs) created each year has soared to the point that the National Institute for Standards and Technology's National Vulnerability Database (NVD) is backlogged and, as the piece puts it, "NIST threw up its hands in April and effectively declared CVE bankruptcy." The U.S. Department of Commerce's May report also criticized the NVD's handling and recommended stopping the assignment of Common Vulnerability Scoring System (CVSS) scores because they are "highly subjective" and dependent on local context.
AI and frontier LLMs: speeding discovery and weaponization
Artificial intelligence is amplifying the problem. The article cites frontier large language models such as Claude's Mythos as already surfacing zero-days at scale and accelerating the creation and weaponization of exploits. The Cloud Security Alliance is quoted describing an "asymmetric vulnerability cycle" where attackers using AI can discover and exploit vulnerabilities faster—often before patches exist—while organizations take longer to remediate.

This site is the portfolio.
OSINTSights runs on Cloudflare Workers, D1, R2, and Vectorize, with an AI pipeline on Hetzner ARM. Nubivance designed, built, and operates it. We do the same for clients.
See what we buildGartner's CTEM framework: five steps from scoping to mobilization
Gartner named Continuous Threat Exposure Management (CTEM) a top cybersecurity trend in 2023. CTEM reframes assurance from counting patched items to proving exploitable paths have been closed. Gartner's five-step CTEM sequence in the story is:
- Scoping — identify high-business-impact assets and prioritize them.
- Discovery — analyze how those assets are exposed and by what weaknesses.
- Prioritization — rank exposures based on real business risk, not raw CVSS alone.
- Validation — test vulnerabilities to determine exploitability.
- Mobilization — fix the validated, high-risk exposures and follow an incident response plan.
The argument is that CTEM produces outcome-focused metrics—fewer exploitable paths and a smaller blast radius—that boards can read as real security progress, rather than activity metrics such as "number of patches applied."
Horizon3's NodeZero: automated pen testing and 'test in production'
Horizon3 positions its NodeZero platform as automation tailored to the CTEM loop's hardest parts: business-impact prioritization and mobilization. NodeZero runs penetration tests across an organization's infrastructure, documents exploitable attack paths with evidence, and retests after remediation so teams can close tickets when an attack chain no longer traverses the environment. The product emphasizes "chain-of-attack" behavior—probing, exploiting, and pivoting—so the testing adapts to what it finds.
Vanover explains NodeZero uses a deterministic machine-learning expert system rather than a general LLM, and that generative AI is used only for specific tasks (for example, parsing large S3 data stores inside a customer's boundary via AWS Bedrock), not for spawning autonomous agents. Horizon3 says it has run more than 320,000 production tests across customer organizations, including the National Security Agency and "the largest medical records processor on the planet," alongside other large healthcare providers.
What this means for CISOs, boards, and security teams
- CISOs: Expect increased pressure to present outcome-based evidence that exploitable paths have been closed. The story advises starting CTEM by "picking one thing and doing it well" rather than attempting wholesale change in a year.
- Boards: The traditional metric of patch counts will be less persuasive. The piece argues boards will demand proof—validated, evidence-backed closure of attack chains—rather than activity reports.
- Security teams and developers: Automated, validated penetration testing can shorten a prioritized list of exposures to those that are demonstrably exploitable, then close the loop by retesting. The article warns against tool sprawl and suggests a single integrated service can reduce handoff blind spots.
The central claim of the reporting is clear: rising CVE volume, contested severity scoring, and AI-accelerated discovery make the status quo untenable. CTEM shifts the conversation from "Did we patch X?" to "Can anyone still walk an attacker through an exploitable path?" As the piece closes, the new goal is framed plainly: "prove that a security control worked, not just that you paid for it." For organizations facing boardroom demands for proof, Gartner's CTEM loop and automated validation platforms like NodeZero offer one practical path forward.




