Today's cybersecurity headlines are brought to you by ThreatPerspective


Ethical Hacking News

Drowning in CVEs: The Rise of Continuous Threat Exposure Management (CTEM) as a Solution to Traditional Vulnerability Management


Drowning in CVEs: The Rise of Continuous Threat Exposure Management (CTEM) as a Solution to Traditional Vulnerability Management. As the number of CVEs continues to soar, organizations are looking for new ways to manage their vulnerabilities. CTEM is a relatively new approach that involves triaging vulnerabilities properly, going beyond the technical implications of a security flaw and understanding what it really means for the business. With the rise of AI, CTEM is becoming an increasingly important solution for organizations looking to improve their security posture. Learn more about how CTEM can help your organization stay ahead of the threats.

  • Continuous Threat Exposure Management (CTEM) is a new approach to vulnerability management that focuses on triaging vulnerabilities properly and understanding their business implications.
  • Traditional vulnerability management has several problems, including a firehose of CVEs, CVSS scores that aren't helpful for triaging, and AI making it worse.
  • The volume of CVEs is making traditional vulnerability management less tractable, with the US National Institute for Standards and Technology's National Vulnerability Database being backlogged for years.
  • AI will make vulnerability management harder, with attackers using AI to discover and exploit vulnerabilities more quickly.
  • Gartner recommends five steps for CTEM: Scoping, Discovery, Prioritization, Validation, and Mobilization.
  • Horizon3's NodeZero product provides a solution for CTEM by running penetration tests across an organization's infrastructure and documenting exploitable paths.
  • NodeZero uses a deterministic machine learning expert system to adapt to the environment and extend its attack, making it more accurate than general LLMs.
  • The value of NodeZero lies in proving that a security control worked, with the ability to close the loop by retesting the exploit after it's been dealt with.
  • Horizon3 aims to solve customers' tool sprawl problems with a single product that handles all of the heavy CTEM lifting.
  • Testing in production is the safest way to find bugs, as environments drift frequently in an agile world.
  • CISOs should start by picking one thing and doing it well, rather than trying to implement CTEM in a year, which can lead to failure.
  • The goal of CTEM is to move reporting from activity to outcomes, so that the board sees fewer exploitable paths and a smaller blast radius.



  • Continuous Threat Exposure Management (CTEM) is a relatively new approach to vulnerability management that has gained traction in recent times. CTEM is a way of staying on top of vulnerabilities by triaging them properly, going beyond the technical implications of a security flaw and understanding what it really means for the business. Gartner named CTEM a top cybersecurity trend in 2023, and it's becoming an increasingly important solution for organizations looking to improve their security posture.

    Traditional vulnerability management, which involves defining security flaws using Common Vulnerabilities and Exposures (CVEs) and assigning the Common Vulnerability Scoring System (CVSS) to them, has several problems. There's a firehose of CVEs, the CVSS scores aren't helpful when triaging them, and AI is about to make the whole thing much worse. CISOs are drowning in CVEs, and the industry has spent decades creating tools that churn out vulnerability data and others that consume it. Few if any tell you which vulnerabilities an attacker could use to hurt you in your environment.

    The volume of CVEs is making traditional vulnerability management less tractable every year. The number of CVEs created each year has been soaring, putting more pressure on the US' National Institute for Standards and Technology's National Vulnerability Database, which has now been backlogged for years. NIST threw up its hands in April and effectively declared CVE bankruptcy.

    The US Department of Commerce highlighted the second issue that current severity metrics aren't useful. Aside from launching a zinger at the NIST by saying that the NVD was poorly managed, it also suggested that it stop assigning CVSS scores altogether. These are highly subjective, it said. They also depend on exactly what the exposed system is doing in a particular organization's infrastructure.

    AI will make vulnerability management harder. Frontier LLMs like Claude's Mythos are already surfacing zero-days at scale, heralding a flood of CVEs. They don't just find bugs at scale; they also work much more quickly than their human counterparts to create and weaponize exploits. This makes it even more important that organizations patch the right bugs quickly.

    The Cloud Security Alliance now describes an asymmetric vulnerability cycle in which attackers can use AI to discover and exploit vulnerabilities more quickly, (increasingly before patches are even released), while organizations are taking longer to patch them.

    Gartner lays out five steps to CTEM: Scoping, Discovery, Prioritization, Validation, and Mobilization. Scoping involves finding the assets that carry significant business impact and prioritizing them. Discovery involves finding how they're exposed by analyzing their weaknesses in depth. Prioritization involves ranking those exposures based on real business risk. Validation involves testing out the vulnerabilities to see if they're exploitable. Mobilization involves fixing them with a proper incident response plan.

    Horizon3 is providing a solution for CTEM with its NodeZero product. NodeZero runs penetration tests across an organization's infrastructure and documents the exploitable paths with evidence a defender can follow. The output is the wheat sifted from the chaff; a shorter list of exposures that security teams and developers can focus on.

    The impressive part of NodeZero is the chain-of-attack behavior. NodeZero probes for weaknesses, exploits them, and then pivots based on what it finds. This means it adapts to the environment to extend its attack, just as a real attacker adapts attacks and moves laterally through systems.

    Horizon3 uses a deterministic machine learning expert system rather than a general LLM. This makes it more accurate and less prone to hallucinations and guesses. The company only uses generative AI for specific tasks. Using it to parse a two petabyte S3 blob looking for sensitive data or identifying high-value credentials, with data staying inside the customer's boundary via AWS Bedrock, for example.

    Vanover says the value here is in proving that you've clobbered load-bearing security bugs. "If we say that we can exploit something, it's because we did, and we'll show you the proof in the platform," he says.

    The next step is closing the loop by retesting the exploit after it's been dealt with. Teams get to close tickets because NodeZero can no longer traverse the attack path. That is a testable definition of "fixed" and one that translates into a risk metric a CFO can read.

    Horizon3 also wants to solve customers' tool sprawl problems with a single product that handles all of the heavy CTEM lifting. A common failure mode of enterprise CTEM programs is a stack of vendors whose handoffs create precisely the blind spots the framework was meant to eliminate.

    CISOs might be nervous letting an autonomous penetration testing system loose on production systems. It sounds like something that could break running processes. Why not just test against a digital twin instead?

    Vanover retorts that testing in production is the safest way to find bugs. That's because environments drift frequently, especially in an agile world driven by short development sprints and automated changes to code. If a user changes a password or a team pushes a feature fragment, a digital twin system won't reflect reality.

    So Horizon3 focuses on strong production guardrails instead.

    Gartner's CTEM framework is powerful, but it might also be daunting for CISOs. Vanover advises them to begin by picking one thing and doing it well. "No organization is going to implement CTEM in a year. That is a recipe for failure," he says. "Break it down. Look at places for the low-hanging fruit." You could do worse than look at what systems are actually reachable instead of blindly trusting an asset inventory that might be out of date.

    The race is on to embrace CTEM, because metrics like the number of patches applied won't satisfy the board for much longer. They don't describe how much exploitable surface still exists. The point of running the CTEM loop is to move reporting from activity to outcomes, so that the board gets to see fewer exploitable paths and a smaller blast radius.

    The new goal is to prove that a security control worked, not just that you paid for it.



    Related Information:
  • https://www.ethicalhackingnews.com/articles/Drowning-in-CVEs-The-Rise-of-Continuous-Threat-Exposure-Management-CTEM-as-a-Solution-to-Traditional-Vulnerability-Management-ehn.shtml

  • https://www.theregister.com/security/2026/09/03/sponsored-drowning-in-cves-and-thirsty-for-answers-try-ctem/5293906


  • Published: Thu Sep 3 11:12:22 2026 by llama3.2 3B Q4_K_M













    © Ethical Hacking News . All rights reserved.

    Privacy | Terms of Use | Contact Us