AI Glossary

Time to Exploit

Time to exploit measures when a vulnerability is first known to be exploited relative to a reference date, such as public disclosure or patch release. A negative value means exploitation happened before that reference date.

Also known as: time-to-exploit

· Chain of Thought

AI Security

The calculation is the exploitation date minus the chosen reference date. If a patch arrives on September 10 and exploitation began on September 8, patch-relative time to exploit is minus two days. Mandiant’s analysis of 2023 exploitation uses patch release as its reference and explains that the first reported exploitation may be later than the actual first attack.

Compare reports only after checking their reference dates, which vulnerabilities they include, and how they handle outliers. An average from observed exploited vulnerabilities does not describe every disclosed flaw or guarantee a safe patching window. In the episode below, Dan Lorenc connects compressed exploitation timelines to the need for faster remediation. Keep that operational argument separate from any claim about a universal average or what caused it to change.

From the conversation