www.lesswrong.com/posts/gutiw8MBrYDiD2u5z/models-finding-software-vulnerabilitie...
1 correction found
The lag time between "patch shipped" and "patch reverse engineered and weaponized by a criminal organization" was so long that most people didn't notice new bugs when they came out.
This overstates how much time defenders historically had after patches shipped. Threat-intelligence studies found many vulnerabilities were exploited before a patch existed or within hours to days after a patch was released.
Full reasoning
Multiple published threat-intelligence analyses contradict the idea that the historical lag after a patch was generally "so long."
- In a Google Cloud / Mandiant analysis of vulnerabilities exploited in 2018–2019, the researchers wrote that "the majority of exploitation in the wild occurs before patch issuance or within a few days of a patch becoming available." They further reported that for vulnerabilities first exploited after a patch, the window was often "only hours or a few days".
- Palo Alto Networks' Unit 42 separately analyzed public exploit data and found that among sampled high-severity exploits, 23% were published within the first week after the patch release and 50% within the first month. The same report states that "most exploits are developed and published in the first week of patch release."
Those findings do not support a characterization that patch-to-weaponization lag was broadly long enough that "most people didn't notice new bugs when they came out." At least by the late 2010s, authoritative industry research was already documenting very short post-patch exploitation windows.
2 sources
- Think Fast: Time Between Disclosure, Patch Release and Vulnerability Exploitation - Intelligence for Vulnerability Management, Part Two | Google Cloud Blog
FireEye Mandiant Threat Intelligence research into vulnerabilities exploited in 2018 and 2019 suggests that the majority of exploitation in the wild occurs before patch issuance or within a few days of a patch becoming available... For these non-zero-day vulnerabilities, there was a very small window (often only hours or a few days) between when the patch was released and the first observed instance of attacker exploitation.
- State of Exploit Development: 80% of Exploits Publish Faster Than CVEs
Because vulnerability patch dates are not available in Exploit Database or a CVE database, we sampled 500 high-severity exploits since 2015 and manually identified their patch dates from the vendor sites. 14% of the exploits we studied were published before the patches, 23% of the exploits were published in the first week and 50% in the first month... most exploits are developed and published in the first week of patch release.