Unit 42: hackers typically scan for vulnerabilities within 15 minutes of a new CVE disclosure; the first active exploitation attempts are observed within hours
Bill Toulas / BleepingComputer : Source: Unit 42 .
Context & Ripple Effects
Unit 42's finding quantifies a race that earlier coverage only showed anecdotally: [[a:938742|CrowdStrike measured Russian state hackers moving laterally within 20 minutes of an initial breach]], and now Palo Alto's researchers put the scan-for-CVE window at roughly 15 minutes after disclosure. The defensive side of that race is visibly slower — Microsoft took nearly two months to patch Exchange Server flaws while a mass-hack unfolded, and as recently as June 2022 an actively exploited Windows RCE reported in April still had no fix.
The gap between hours-scale attacker response and weeks-scale vendor response is the story's real subject; the 15-minute figure turns it from impression into a measurable benchmark.
First-order effects
- Organizations relying on patch cycles now face exploitation attempts within hours of any new CVE, making the window between disclosure and their own deployment effectively zero for internet-facing systems.
Second-order effects
- Vendors with slow remediation records — Microsoft's months-long Exchange and Windows RCE timelines are the corpus's clearest examples — face mounting pressure to compress patch turnaround or accept that disclosed-but-unpatched flaws are functionally zero-days.
Third-order effects
- If scanning is this fast by default, defense shifts from reactive patching toward compensating controls — exposure reduction, virtual patching, faster triage of CISA-flagged bug classes like the F5/Citrix/Pulse/Exchange set — because the patch race cannot be won on attacker timescales.
The trend: Vulnerability exploitation is converging on near-real-time response to disclosures while vendor and enterprise patching stays on weekly-to-monthly cadences, widening a structural gap defenders must close with automation rather than speed alone.