Attackers Don't Need Your Password Anymore. They Just Need the Software You Haven't Patched.
In this week's "Strike a Nerve" update, I want to talk about a shift that just showed up in the data, and it changes how every business should be prioritizing security work.
Exploiting software vulnerabilities has overtaken stolen credentials as the leading way attackers get into a network, according to Verizon's 2026 Data Breach Investigations Report. This is the first time vulnerability exploitation has taken the top spot. The median time it takes a business to patch a known vulnerability has climbed to 43 days. Attackers are not waiting that long. Many are weaponizing a newly disclosed flaw within hours of it becoming public.
That window between disclosure and patch is exactly where breaches are happening. Most businesses patch in whatever order is convenient, often oldest issues first. Attackers do not care about your patch calendar. They are actively scanning for the vulnerabilities being exploited right now, which is a shorter and very different list than everything sitting in your backlog.
For small and mid-sized businesses, this changes what staying current actually means. It is not enough to patch eventually. It is about patching the right things first, based on what is being exploited in the wild rather than by ticket age.
Three steps to take right now:
- Check whether your patch management process references CISA's Known Exploited Vulnerabilities catalog, not just vendor release notes.
- Ask your IT provider how long vulnerabilities typically sit unpatched in your environment and whether that number is improving or getting worse.
- Prioritize patches for internet facing systems and remote access tools first, since those are the doors attackers try first.
Do you know how many known, actively exploited vulnerabilities are sitting unpatched in your environment right now? Let us help you find out.
— Steve, "Strike a Nerve" Weekly Cyber Threat Update