Live alertsSource: CISA
OCT 4ExploitedCitrix NetScaler is under active attackCVE-2026-88779. CISA orders federal agencies to patch by Oct 7.OCT 2ExploitedZammad GmbH Zammad is under active attackCVE-2026-102490. CISA orders federal agencies to patch by Oct 5.OCT 2ExploitedZammad GmbH Zammad is under active attackCVE-2026-102489. CISA orders federal agencies to patch by Oct 5.OCT 1AdvisoryCISA MalcolmCISA advisoryOCT 1AdvisoryJohnson Controls EasyIO Neo Series EC and CW ControllersCISA advisoryOCT 1AdvisoryABB Protection and Control IED Manager PCM600CISA advisoryOCT 1AdvisoryArmatura LLC Armatura OneCISA advisoryOCT 1AdvisoryMonta monta.appCISA advisoryOCT 1AdvisoryMeari IoT Cloud Platform OpenAPI ServiceCISA advisoryOCT 1AdvisoryJohnson Controls EasyIO Neo Series EC and CW ControllersCISA advisoryOCT 1ExploitedFortinet FortiMail is under active attackCVE-2026-104286. CISA orders federal agencies to patch by Oct 4.SEP 30ExploitedCisco Catalyst SD-WAN Manager is under active attackCVE-2026-76504. CISA orders federal agencies to patch by Oct 3.SEP 29AdvisoryViidure Dashcam Android ApplicationCISA advisorySEP 29AdvisoryToptech TMS7 and TopHATCISA advisorySEP 29AdvisoryLantronix G520 Series Cellular GatewayCISA advisorySEP 29ExploitedApple Multiple Products is under active attackCVE-2026-86950. CISA orders federal agencies to patch by Oct 2.SEP 27ExploitedCitrix NetScaler is under active attackCVE-2026-88772. CISA orders federal agencies to patch by Sep 30.SEP 27ExploitedCitrix NetScaler is under active attackCVE-2026-88771. CISA orders federal agencies to patch by Sep 30.SEP 25ExploitedMikroTik RouterOS is under active attackCVE-2026-67279. CISA orders federal agencies to patch by Sep 28.SEP 25ExploitedMicrosoft SharePoint is under active attackCVE-2026-65660. CISA orders federal agencies to patch by Sep 28.OCT 4ExploitedCitrix NetScaler is under active attackCVE-2026-88779. CISA orders federal agencies to patch by Oct 7.OCT 2ExploitedZammad GmbH Zammad is under active attackCVE-2026-102490. CISA orders federal agencies to patch by Oct 5.OCT 2ExploitedZammad GmbH Zammad is under active attackCVE-2026-102489. CISA orders federal agencies to patch by Oct 5.OCT 1AdvisoryCISA MalcolmCISA advisoryOCT 1AdvisoryJohnson Controls EasyIO Neo Series EC and CW ControllersCISA advisoryOCT 1AdvisoryABB Protection and Control IED Manager PCM600CISA advisoryOCT 1AdvisoryArmatura LLC Armatura OneCISA advisoryOCT 1AdvisoryMonta monta.appCISA advisoryOCT 1AdvisoryMeari IoT Cloud Platform OpenAPI ServiceCISA advisoryOCT 1AdvisoryJohnson Controls EasyIO Neo Series EC and CW ControllersCISA advisoryOCT 1ExploitedFortinet FortiMail is under active attackCVE-2026-104286. CISA orders federal agencies to patch by Oct 4.SEP 30ExploitedCisco Catalyst SD-WAN Manager is under active attackCVE-2026-76504. CISA orders federal agencies to patch by Oct 3.SEP 29AdvisoryViidure Dashcam Android ApplicationCISA advisorySEP 29AdvisoryToptech TMS7 and TopHATCISA advisorySEP 29AdvisoryLantronix G520 Series Cellular GatewayCISA advisorySEP 29ExploitedApple Multiple Products is under active attackCVE-2026-86950. CISA orders federal agencies to patch by Oct 2.SEP 27ExploitedCitrix NetScaler is under active attackCVE-2026-88772. CISA orders federal agencies to patch by Sep 30.SEP 27ExploitedCitrix NetScaler is under active attackCVE-2026-88771. CISA orders federal agencies to patch by Sep 30.SEP 25ExploitedMikroTik RouterOS is under active attackCVE-2026-67279. CISA orders federal agencies to patch by Sep 28.SEP 25ExploitedMicrosoft SharePoint is under active attackCVE-2026-65660. CISA orders federal agencies to patch by Sep 28.
Exposure Window · Method v2.1 T = 24 months Floor = 1 day · passed 53 standards
Tech Signal IQ
Method v2.1 · Published in full

The
Exposure
Window™ How long a company's externally visible cybersecurity weaknesses are likely to remain unexploited — and what it costs them if that window closes.

METHOD_VERSION v2.1 HALVING_MONTHS (T) 24 FLOOR_DAYS 1 · passed

Time from disclosure to exploitation

Days · average
v2.1 model · T=24 Published figures 1-day floorAverage crosses zero
EW(t) = EW0 × 2−((t − t0) / T)
§ 01 The premise

“How bad” is
the wrong
first question.

Security scoring usually answers how bad is this? It rarely answers how soon? — which is the question that decides whether anyone acts.

The Exposure Window exists because the interval between a weakness becoming known and being exploited has collapsed from years to days, and that collapse is measurable rather than rhetorical.

When
Exposure Window

How long the weakness is likely to sit there before someone uses it. Measured in days, banded, and driven by the strongest single piece of evidence on the company.

How bad
Business Impact

What it costs if the window closes — expressed by mechanism rather than a single dollar figure, because the mechanisms differ enormously in severity.

×

The two readings are published together and never blended into one number. This is the standard decomposition of risk into likelihood and consequence used by NIST SP 800-30 and ISO 27005, and it aligns with FAIR (Factor Analysis of Information Risk, The Open Group), which separates Loss Event Frequency from Loss Magnitude. Multiplying them into a single figure would destroy the ability to name the driver — and the driver is the only part a buyer can act on.

§ 02 Why a law, and why Moore's

Moore's Law
is not a law
of physics.

It was an observation. Gordon Moore counted components on a chip in 1965, saw a doubling roughly every year, and said so. In 1975 he revised the period to roughly two years.

It became a planning instrument for an entire industry not because it was exact, but because it was simple, checkable, and revised in public when the data moved.

That precedent matters here in two ways. First, it legitimises stating a rate constant and re-fitting it as evidence accumulates: a versioned constant is normal practice for an empirical law, not a weakness in one. Second, it sets the bar for adoption. A number people cite has to be auditable.

Gordon Moore photographed in 1978, reproduced as a red duotone halftone.
Gordon Moore · 1929–2023 Counted components per die in Electronics, April 1965. Predicted annual doubling. Revised to roughly two years in 1975 — the revision, not the original, is what made it durable.

The fastest way to kill a measure like this is to hide its arithmetic.

1965
The observation

Components per integrated circuit doubling roughly every year. Published as a counted trend, not a theory.

1975
The revision

Period revised to roughly two years. Revised in public, with the data that forced it.

Transistors per processor · 1971–2025 · log scale. Dashed line is a two-year doubling; dots are landmark parts, red dot once a “chip” became a multi-die package.
§ 03 The Exposure Window Law

The interval between a vulnerability becoming known and being exploited in the wild is cut in half approximately every 24 months — until it reaches zero, after which exploitation begins to precede disclosure.

EW(t) = EW0 × 2−((t − t0) / T) · T = 24 months · EW0 = baseline window for the exposure class at t0 · floor = 1 day, reached 2026

The second clause is not a refinement — it is a terminus. An exponential approaching zero never arrives, so the curve needs an arbitrary floor to stay sensible. The observed series did arrive, in 2026, and then continued: the average vulnerability is now exploited before it is disclosed. Past that point the curve stops describing anything, because the quantity it models — days of window remaining — no longer exists. The law is retained for the interval it governed and is not extrapolated beyond it. See §6.

The empirical basis

The published series on time-to-exploit — average days from disclosure to observed exploitation, on one consistent measure.

PeriodTime-to-exploit
2018–19~63 days
2020–21~44 days
2021–22~32 days
2023~5 days
2026~24 hours
2026 · the inversionbefore disclosure
2026 · AI capability
measured exploit build time
11 min

Sources, row by row. 2018–19 through 2023: Mandiant time-to-exploit research. 2026 observed: Zero Day Clock, with Mandiant M-Trends 2026 reporting 28.3% of vulnerabilities exploited inside 24 hours of disclosure. The inversion row is that same distribution once its tail is included — the average crosses zero because a growing share is exploited before the advisory exists. The bar grows leftward for that reason: it is not a very short window, it is the absence of one.

The final row is a capability measurement and is deliberately set apart. 11 minutes and $2.83 is the median cost and time for autonomous agents to produce a verified working exploit from a disclosed vulnerability in a controlled harness — 72% success across 3,029 CVEs. It is not an observed attack time, and reading it as one merges two different metrics. It explains why the window is not reopening; it is not a point on the series above it.

On the 2023 figure. Mandiant published ~5 days after excluding 15 statistical outliers; the same dataset, untrimmed, averages ~47 days. Same authors, same study — one is the trimmed headline, the other the raw mean. This paper quotes the ~5 days Mandiant led with, and records the untrimmed figure here rather than in the chart, so the series stays one consistent measure while a reader who knows the ~47 finds it acknowledged rather than omitted.

Mandiant does not attribute the 2023 shift to AI. Their stated cause is a change in sample composition: 97 of the 138 vulnerabilities exploited in 2023 — 70.3% — were used as zero-days, moving the n-day/zero-day ratio from roughly 4:6 to 3:7. A zero-day is exploited before a patch exists, so as its share of the sample grows, measured time-to-exploit falls toward zero regardless of how fast exploits are written. They further note that improved zero-day detection may mean 2023 reflects earlier years more accurately rather than a real acceleration. See §10, Limitations.

Since 2023 — the measure inverts

These readings are not the same measurement as the series above and are deliberately not plotted on the same curve. They count different things, and conflating them is the single easiest way to lose a technical audience. Each is named with what it measures.

ReadingWhat it measuresSource
28.3%Share of CVEs exploited within 24 hours of disclosure. Time-to-exploit has effectively gone negative.Mandiant, M-Trends 2026
~24 hoursAverage disclosure-to-exploitation in 2026, down from ~53 days in 2024.Zero Day Clock
80 daysCVE publication to CISA KEV inclusion, H1 2026 — down from 120 days in 2025. A much larger number because it counts catalogue entry, not exploitation.VulnCheck, H1 2026
11 min · $2.83Capability, not observed timing. Median cost and time for autonomous AI agents to turn a disclosed vulnerability into a verified working exploit in a controlled harness — 72% success across 3,029 CVEs. Work that took a skilled researcher days or weeks.Controlled study, July 2026

The first three measure exploitation as observed in the wild. The fourth measures what an attacker can build, in a harness, and says nothing about how quickly attacks occur. Stating it as “attacks now happen in 11 minutes” merges two different metrics and is the one error a technical reader will catch. Stated as capability it is unarguable — and it is the reason the window is not reopening, not the reason it closed.

Counter-evidence held on the record: VulnCheck’s H1 2026 report found that of 1,061 vulnerabilities attributed to AI-assisted discovery, only 14 — 1.3% — were confirmed exploited in the wild, roughly the baseline rate. That measures AI-discovered bugs, not AI-written exploits, so it does not contradict the capability figure above. It is recorded here because a reader who knows it should find it already answered.


§ 04 The two-track split

The law applies
to one track only.

This is the constraint that keeps the model honest, and the one most easily got wrong.

Time-to-exploit measures the gap between disclosure and exploitation. A spoofable domain has no disclosure date — nobody publishes an advisory saying a company left DMARC at p=none. Applying exponential compression to it is a category error.

The cost of getting this wrong is measurable. Run the compression across every class and, at three years elapsed, the factor of roughly 0.35 drags a hygiene-only company from a 180-day baseline to about 64 days. Every company scored becomes critical — and a measure that says “critical” about everyone is ignored by everyone.

Track A · Compressed

Vulnerability-driven

Exposure with a disclosure date behind it. The underlying interval genuinely is compressing, so the law applies.

CISA KEV listingEPSS scoreCVE + NVD record
Treatment: compressed by EW(t)
Track B · Flat

Opportunity-driven

Exposure with no disclosure event. Governed by attacker volume rather than disclosure cycles, so bands stay flat.

Spoofable domainBreached credentialsExposed admin service
Treatment: flat bands, no decay
§ 05 Bands

Set by the strongest
single finding.

An attacker needs only one way in. Averaging across findings would let good hygiene mask a live exposure — so the band is never an average.
Shut
Pre-disclosure
Already closed
Exploitation is already under way. Triggered by an EPSS score at or above 0.50 — better than even odds of exploitation within 30 days, which is not a window, it is a coin toss already in the air. Without a band for it, such a lead reads as “Critical, 0–30 days” — which overstates the time remaining by all of it. A KEV listing whose known-exploitation date precedes disclosure also belongs here; capturing that date is planned for a future revision and is not yet wired, so those leads currently report as Critical.
Critical
CVE-driven
0–30 days
A vulnerability listed in CISA KEV — confirmed exploited in the wild — where exploitation is not known to predate disclosure, an EPSS score between 0.10 and 0.50, or a high-risk administrative service exposed alongside a known vulnerability.
High
Mixed
30–90 days
EPSS between 0.01 and 0.10, a remote-access service exposed without a known vulnerability, or credential-bearing breach history within 24 months combined with a spoofable domain.
Elevated
Opportunity-driven
90–180 days
A spoofable domain on its own (DMARC absent or set to p=none), vulnerabilities present but all scoring below 0.01 on EPSS, or weak transport security.
Baseline
Hygiene only
180+ days
Configuration and hygiene findings with no externally exploitable path.
§ 06 The floor was reached, and then passed

Manual patching cannot win on arithmetic.

The curve needs a floor of 1 day, or it predicts sub-hour windows and becomes absurd. On the curve that floor arrives around 2030. In reality it arrived in 2026, four years early — and the measure did not stop there.

More than a quarter of vulnerabilities — 28.3% — are now exploited within 24 hours of disclosure, and across the full distribution the average has gone past zero: the typical vulnerability is exploited before it is disclosed. When exploitation precedes disclosure, “days of window remaining” is no longer a quantity that exists. The thing being counted changed sign.

Metric that mattered
Time to exploit
▶
Metric that matters now
Time to remediate

That is the substantive conclusion of this method rather than a footnote to it, and it is now measured rather than projected. Once exploitation arrives before disclosure, no patch cycle operated by people can be fast enough in principle — the defender is not late, the defender is behind at t = 0. The only remaining levers are continuous monitoring, managed response, and reducing what is externally visible in the first place.

This is also why the window is not reopening. Autonomous agents now produce a verified working exploit from a disclosed vulnerability at a median of 11 minutes and $2.83, work that took a skilled researcher days or weeks. That is a capability measurement, not an observed attack time — but capability of that cost does not un-happen. See §3.

§ 07 Business Impact

What it costs
if the window
closes.

The backbone is the Compliance Gap: a count of detected findings that map to controls the company is actually required to meet, produced by cross-referencing each finding's standards against the regimes governing its industry.

It is countable and auditable rather than rhetorical. Consequence is then expressed by mechanism, not as a single dollar figure — because the mechanisms differ enormously in severity.

Defense supplier

Loss of eligibility

The sharpest exposure is not a fine. A contractor without the required certification cannot be awarded work — and an inaccurate self-attestation carries False Claims Act exposure.

Card-accepting merchant

Loss of processing

Enforced by the card brands through the acquiring bank rather than by government. Losing the ability to accept cards is existential for a retail or hospitality business.

Licensed insurer

The licence itself

Where the regime is licensure-based, the consequence mechanism is suspension or revocation of the authority to operate — not a penalty that can be absorbed.


§ 08 What we assert, and what we do not

Three labels.
Never blurred.

Detected
A fact

Observed on the public internet.

Applicable
An inference

This regime governs this company's industry — inferred from the industry classification.

Potential
A ceiling

The statutory or contractual maximum if a breach occurs. Always cited, never a prediction.

We do not generate company-specific loss estimates. Penalties are quoted as published maxima; averages are quoted as industry averages and named as such. Where no exploitable path is found, the report says so rather than manufacturing urgency — a measure that alarms on every prospect has no information content.

Collection

All collection is passive. Nothing here involves authentication, intrusion, or any interaction beyond what an ordinary visitor or a public database already sees.

§ 09 Data sources

Nine inputs.
All public.

NVD disclosure dates

The date each vulnerability became public — t0 in the law.

Without it the method can say a weakness is dangerous but not how long it has gone unfixed.

Internet Archive

Archived responses retain the origin's original headers, so a missing security header can be dated to the oldest capture that also lacked it.

Reported as “missing since at least” — a lower bound, never a claim about when it appeared.

Passive DNS (optional)

First-seen dates for SPF and DMARC records, which live DNS cannot provide — a TXT record carries no creation timestamp.

Key-gated and dormant by default. Without a key these dates are reported as unknown rather than estimated.

CISA KEV

Catalogue of vulnerabilities confirmed exploited in the wild.

Authoritative and binary. Refreshed daily.

FIRST EPSS

Probability a given vulnerability is exploited within the next 30 days.

Peer-reviewed model; the primitive this method is built on.

NIST NVD

Vulnerability records for software fingerprinted from public responses.

Supplies the identifiers passed to KEV and EPSS.

Shodan InternetDB

Internet-facing ports, hostnames and reported vulnerabilities.

Passive lookup of already-published data.

Have I Been Pwned

Whether the company's own domain appears in a public breach corpus.

Company-level only. No individual accounts are queried.

Certificate Transparency

Subdomains disclosed in public certificate logs.

Establishes the breadth of externally reachable surface.
§ 10 Limitations

Where this
method is weak.

  1. The halving period is fitted to a published series that has not been perfectly exponential — compression accelerated sharply, then the measure inverted entirely. A single constant is retained for legibility over the interval it governed, and is not extrapolated past 2026.
  2. The 2023 figure of ~5 days is outlier-adjusted — 15 outliers removed from a sample whose untrimmed mean is ~47 days. The curve is therefore fitted to a trimmed series, and this method does not claim otherwise.
  3. The published series is not one measurement. Time-to-exploit, share exploited within 24 hours, and CVE-to-KEV-inclusion count different things and produce very different numbers for the same year. §3 names what each reading measures; figures from different measures are never plotted on one curve.
  4. Mandiant attributes the 2023 compression to a rising zero-day share of the sample, not to attacker speed. Composition change and genuine acceleration are not separable in these data, and this method does not claim to separate them.
  5. The AI capability figure — 11 minutes, $2.83 — is measured in a controlled harness, not observed in the wild. It establishes that cheap exploit generation exists; it does not establish how often it is used against any company.
  6. Applicability is inferred from an industry classification. A mislabelled company draws the wrong regimes, which is why every regime is shown rather than silently folded into a score.
  7. Passive collection sees only what is externally visible. Strong internal controls are invisible to it, so a poor result is evidence of exposed weakness, not of overall immaturity.
  8. EPSS is a probability over a population, not a prediction about one organisation. A low score is not safety.
Appendix

Standards
referenced

Every standard this product can cite on a finding — who issues it, who it binds, what it requires, and what non-conformance actually costs. 16 of the 53 carry a caveat, and the caveat says which kind. Varies by state means no single maximum exists — that is a permanent property of the statute, not outstanding work. Adjusts annually means a real published figure that moves each January under the Federal Civil Penalties Inflation Adjustment Act; those are pinned with a date. Only unverified would mean not yet checked against a primary source.

Mechanism