n-day reality

The Zero-Day Rate is now just under 87%, with a median time to exploit at just one day . . . but projected to reach 1 minute sometime next year.

Via a16z: Charts of the Week, cyber game done changed. Zero Day Clock charts toward the bottom.

I have been commenting a lot on n-day reality lately. this is not to say that n-day dev is the same thing as operationalizing and pivoting with an exploit. that mentality heavily influences my thoughts below.

where i am hopeful:

  • active defense is going to play a larger role as it’s (1) (for the mean time) high signal high impact against agents, (2) inexpensive with low business risk to deploy
  • ai that augments existing defensive technologies quickly. we already see waf/soc/etc rules written and deployed faster than ever. literally as the bug comes out, tech that is enterprise wide deployed can compensate in many areas. if you are paying attention to enterprise product features, you see this already.
  • tangible unavoidable inference cost to attackers operating at scale but that isn’t going to last forever. good enough inference is getting faster/cheaper.

where i am most concerned:

  • we aren’t ready to support updating software at the speed we will need to in the future. enterprise companies have a hard enough time setting patch cycles, this will get much worse. the canary i look at: ai first companies are pushing production updates multiple times per day even for consumer tools. this was unheard of a few years ago and most enterprises and consumer products will need to move at that speed
  • the stragglers with their head in the sand. i feel for them
  • disclosures and cve process. i fear there is too much bureaucracy to change what exists. i think an upstart will get first mover advantage and everyone else will follow. wherever the money is in that.