/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

Unit 42: hackers typically scan for vulnerabilities within 15 minutes of a new CVE disclosure; the first active exploitation attempts are observed within hours

Bill Toulas / BleepingComputer : Source: Unit 42 .

BleepingComputer Bill Toulas

Context & Ripple Effects

Unit 42's finding quantifies a race that earlier coverage only showed anecdotally: [[a:938742|CrowdStrike measured Russian state hackers moving laterally within 20 minutes of an initial breach]], and now Palo Alto's researchers put the scan-for-CVE window at roughly 15 minutes after disclosure. The defensive side of that race is visibly slower — Microsoft took nearly two months to patch Exchange Server flaws while a mass-hack unfolded, and as recently as June 2022 an actively exploited Windows RCE reported in April still had no fix.

The gap between hours-scale attacker response and weeks-scale vendor response is the story's real subject; the 15-minute figure turns it from impression into a measurable benchmark.

First-order effects

  • Organizations relying on patch cycles now face exploitation attempts within hours of any new CVE, making the window between disclosure and their own deployment effectively zero for internet-facing systems.

Second-order effects

  • Vendors with slow remediation records — Microsoft's months-long Exchange and Windows RCE timelines are the corpus's clearest examples — face mounting pressure to compress patch turnaround or accept that disclosed-but-unpatched flaws are functionally zero-days.

Third-order effects

  • If scanning is this fast by default, defense shifts from reactive patching toward compensating controls — exposure reduction, virtual patching, faster triage of CISA-flagged bug classes like the F5/Citrix/Pulse/Exchange set — because the patch race cannot be won on attacker timescales.

The trend: Vulnerability exploitation is converging on near-real-time response to disclosures while vendor and enterprise patching stays on weekly-to-monthly cadences, widening a structural gap defenders must close with automation rather than speed alone.

Discussion

  • @kaynemcgladrey @kaynemcgladrey on x
    “Since scanning isn't particularly demanding, even low-skilled attackers can scan the internet for vulnerable endpoints and sell their findings on dark web markets where more capable hackers know how to exploit them.” https://www.bleepingcomputer.com/ ... #cybersecurity
  • @jorune00 Johnny Heintz on x
    System administrators have even less time to patch disclosed security vulnerabilities than previously thought. #CyberSecurity #infosec #cyberattacks #patchmanagement #security https://www.bleepingcomputer.com/ ...
  • @naderzaveri Nader Zaveri on x
    From my own personal experience on the frontlines, this is very likely. ⁦@Mandiant⁩'s recent M-Trends report showed that Vulnerabilities was the #1 initial access vector. Also, if a PoC has been published, this becomes even more realistic https://www.bleepingcomputer.com/ ...
  • @nuitking @nuitking on x
    This is why patching is important and apparently it needs to be done even quicker than perceived #hackers #vulnerabilities https://www.bleepingcomputer.com/ ...
  • @wendiwhitmore Wendi Whitmore on x
    @PaloAltoNtwks @Unit42_Intel is pleased to share our 2022 Incident Response Threat Report. We cover findings of most common incident types, how attackers gain initial access, what vulnerabilities they exploit, and which industries they target: https://unit42.paloaltonetworks.com/…