Latest InsightsIssuesImpressionsStories 

futuristic skyscrapers in chongqing at night

The CVE Is a Distraction: Why Attackers Are Hunting Vendors, Not Vulnerabilities

For years, enterprise security has run on a simple, almost comforting logic: a vulnerability is disclosed, a CVE number is assigned, a patch is issued, and defenders race to close the gap before attackers exploit it. It is a model built around the individual flaw as the fundamental unit of risk.

New joint research from SentinelOne and Tenable argues that this model no longer matches how attackers actually operate — and that the mismatch is getting more dangerous as AI accelerates both sides of the equation.

Two Datasets, One Uncomfortable Pattern

The study is unusual in its construction. SentinelOne contributed endpoint telemetry and post-exploitation detection data — evidence of what attackers actually do once they’re inside a network. Tenable contributed exposure data drawn from thousands of organizations, along with remediation timelines showing how long known flaws stay open. Layered together, the two independent vantage points converged on the same conclusion: it isn’t the specific vulnerability that persists as a target over time, it’s the vendor ecosystem around it.

The numbers make the case starkly. Exposure data and real-world runtime detection lined up on the same edge-device vendor surfaces in 79% of cases, while overlap at the level of individual CVEs was just 21%. In other words, defenders watching for particular flaws are tracking a moving target, while the vendor product lines those flaws live in stay remarkably constant.

Tenable has given this pattern a name: the “Persistently Targeted Vendor.” The idea is that a small cluster of vendor product lines functions as durable, high-value terrain — attractive to state-sponsored operators and financially motivated ransomware crews alike, regardless of which specific bug happens to be exploitable this month.

When Nation-States and Ransomware Gangs Share a Target List

Perhaps the most striking finding is what the report calls “multi-nexus” attribution: twelve vulnerabilities in the dataset were independently exploited by threat actors across five distinct categories — Chinese, Russian, North Korean, and Iran-linked state-sponsored groups, alongside financially motivated criminal operators. Different motives, different objectives, same flaw. That convergence is itself evidence for the vendor-surface thesis: if adversaries with no coordination and no shared incentive structure keep arriving at the same doorstep, the doorstep — not the specific lock on it — is the thing worth studying.

The research also names names. More than half of organizations running F5 products — 54% — carry at least one exposed, actively exploited vulnerability. Citrix customers, meanwhile, post the slowest remediation of any vendor studied, with a median fix time of 461 days — well over a year of exposure after a patch already exists. These aren’t abstractions; they are concrete illustrations of how certain product lines stay dangerously open long after the fix is available, simply because organizational patching processes can’t keep pace.

AI Has Broken the Old Clock

The report’s most consequential claim may be about timing rather than targeting. Frontier AI models, it argues, are compressing vulnerability discovery from a process that once took months down to hours, and shrinking the gap between public disclosure and working exploit code to roughly a week. Set against that backdrop, the industry’s current median remediation time of five months looks less like a lag and more like an open door.

Adding to the pressure, the study found that remediation complexity on high-priority vulnerabilities introduces a statistically significant 24-day gap — extra time attackers gain simply because complex environments are harder to patch cleanly. As Steve Stone, SentinelOne’s Chief Customer Officer, put it, by the time a vulnerability reaches a remediation queue, adversaries are often already iterating on the exploit. Static, signature-based defenses run on human timelines; the threat does not.

What This Means for Defenders

The practical implication is a shift in where security teams should point their attention. Instead of chasing every new CVE as it’s published, the research suggests organizations get more defensive value from understanding which vendor ecosystems in their own stack have a track record of being persistently targeted — and treating those as standing priorities for attack-surface reduction, hardened detection, and faster patch cycles, independent of whatever the current headline vulnerability happens to be.

Tenable’s Chief Technology Officer, Vlad Korsunsky, frames it as a return to fundamentals: seeing exposures clearly, prioritizing by real business risk, and fixing what matters most — rather than reacting bug by bug. As both nation-state actors and criminal groups increasingly weaponize AI to move faster, that shift from vulnerability-chasing to exposure management may be less a best practice than a necessity.

The uncomfortable truth underneath the data is this: attackers have already stopped thinking in terms of individual CVEs. The question the research leaves open is how long it will take defenders — and the vendors whose products keep showing up in these findings — to do the same.


Source: Joint research release by SentinelOne (NYSE: S) and Tenable Holdings, Inc. (NASDAQ: TENB), August 27, 2026.

Tags:

No responses yet

Leave a Reply