{"id":19746,"date":"2026-08-08T02:39:00","date_gmt":"2026-08-08T02:39:00","guid":{"rendered":"https:\/\/8657085.xyz\/?p=19746"},"modified":"2026-08-08T02:39:00","modified_gmt":"2026-08-08T02:39:00","slug":"op-ed-are-common-vulnerabilities-and-exposures-the-reality-of-chronic-cyber-insecurity","status":"publish","type":"post","link":"https:\/\/8657085.xyz\/?p=19746","title":{"rendered":"Op-Ed: Are \u2018Common Vulnerabilities and Exposures\u2019 the reality of chronic cyber insecurity?"},"content":{"rendered":"<p> <div style=\"display: grid; grid-template-columns: 300px 160px; gap: 2px; width: 460px; background: #eee; padding: 2px;\">\r\n\r\n  <!-- \u6574\u884c\u5bbd\u5e7f\u544a -->\r\n  <div style=\"grid-column: 1\/-1; width: 460px; height: 250px; background: #ccc; display: grid; place-items: center;\">\r\n  <script async type=\"application\/javascript\" src=\"https:\/\/a.magsrv.com\/ad-provider.js\"><\/script> \r\n <ins class=\"eas6a97888e2\" data-zoneid=\"5876674\"><\/ins> \r\n <script>(AdProvider = window.AdProvider || []).push({\"serve\": {}});<\/script>\r\n  <\/div>\r\n  <div style=\"grid-column: 1\/-1; width: 460px; height: 90px; background: #ccc; display: grid; place-items: center;\">\r\n  <script async type=\"application\/javascript\" src=\"https:\/\/a.magsrv.com\/ad-provider.js\"><\/script> \r\n <ins class=\"eas6a97888e2\" data-zoneid=\"5876676\"><\/ins> \r\n <script>(AdProvider = window.AdProvider || []).push({\"serve\": {}});<\/script>\r\n  <\/div>\r\n\r\n  <!-- \u5de6\u4fa7\u7ad6\u6392 -->\r\n  <div style=\"height: 250px; background: #ccc; display: grid; place-items: center;\">\r\n  <script async type=\"application\/javascript\" src=\"https:\/\/a.magsrv.com\/ad-provider.js\"><\/script> \r\n <ins class=\"eas6a97888e2\" data-zoneid=\"5876672\"><\/ins> \r\n <script>(AdProvider = window.AdProvider || []).push({\"serve\": {}});<\/script>\r\n  <\/div>\r\n  <div style=\"height: 500px; background: #ccc; display: grid; place-items: center;\">\r\n  <script async type=\"application\/javascript\" src=\"https:\/\/a.magsrv.com\/ad-provider.js\"><\/script> \r\n <ins class=\"eas6a97888e2\" data-zoneid=\"5876680\"><\/ins> \r\n <script>(AdProvider = window.AdProvider || []).push({\"serve\": {}});<\/script>\r\n  <\/div>\r\n\r\n  <!-- \u53f3\u4fa7\u6469\u5929\u697c\uff08\u548c\u5de6\u4fa7\u5b8c\u5168\u5bf9\u9f50\uff09 -->\r\n  <div style=\"grid-row: 3\/5; height: 750px; background: #ccc; display: grid; place-items: center;\">\r\n  <script async type=\"application\/javascript\" src=\"https:\/\/a.magsrv.com\/ad-provider.js\"><\/script> \r\n <ins class=\"eas6a97888e2\" data-zoneid=\"5876678\"><\/ins> \r\n <script>(AdProvider = window.AdProvider || []).push({\"serve\": {}});<\/script>\r\n  <\/div>\r\n  \r\n  <script async type=\"application\/javascript\" src=\"https:\/\/a.magsrv.com\/ad-provider.js\"><\/script> \r\n <ins class=\"eas6a97888e6\" data-zoneid=\"5876682\"><\/ins> \r\n <script>(AdProvider = window.AdProvider || []).push({\"serve\": {}});<\/script>\r\n<\/div><br \/>\n<\/p>\n<div style=\"padding-right:0;padding-left:0\">\n<p class=\"wp-block-paragraph\">Common Vulnerabilities and Exposures (CVEs) are exactly that. They\u2019re endemic problems for cybersecurity. <strong>Lists of known CVEs<\/strong> are generated in an ongoing litany of risks for systems of all kinds.<\/p>\n<p class=\"wp-block-paragraph\">This is no minor task. The list of CVEs cited by recordedfuture.com for July lists <strong>85 Very Critical Future Risk Score CVEs. <\/strong>That\u2019s not too inspiring.This specific list includes Microsoft, Huawei, Cisco, Apache Tomcat, Oracle, and other major leaguers. It\u2019s that much of a problem. Remember these are \u201cknown\u201d high risks.<\/p>\n<p class=\"wp-block-paragraph\">From this sort of distribution, you\u2019d think that these things were top priorities, instant action matters. This is in fact routine business for cybersecurity. Notifications are given, and someone has to act on them. \u00a0<\/p>\n<h2 id=\"h-so-does-cve-reporting-work-or-doesn-t-it\" class=\"wp-block-heading\">So, does CVE reporting work or doesn\u2019t it?<\/h2>\n<p class=\"wp-block-paragraph\">The <strong>train wreck of cybersecurity breaches in 2026<\/strong> tells another story. Obviously, there <em>were<\/em> vulnerabilities and they <em>weren\u2019t <\/em>fixed, if they were reported.<\/p>\n<p class=\"wp-block-paragraph\">There\u2019s a trick to this. Reporting may come from a variety of sources. It can come from security experts, publishers, and the happy go lucky IT people who find them as a result of a breach of their own systems.<\/p>\n<p class=\"wp-block-paragraph\">Nobody\u2019s saying that CVE reporting is infallible. It can\u2019t be. Some things actually are unknown despite efforts to ensure security. It\u2019s not as though people are in any great hurry to promote news about security risks in their software, either.<\/p>\n<p class=\"wp-block-paragraph\">The commercial fact is that CVEs are like land mines. They blow up when someone triggers them. All reasonable care can be and often is taken, but this is a very fluid environment, particularly when you\u2019ve got <strong>things like Claude looking for vulnerabilities <\/strong>as a sort of raison d\u2019etre.<\/p>\n<p class=\"wp-block-paragraph\">Adding zest to this mess is the fact that risks come in levels. Some risks are basically glitches. Others expose access to entire systems. Any type of CVE reporting is by default a mix of these levels of risk, although prioritized according to relevance and importance.<\/p>\n<h2 id=\"h-generic-case-study-and-managing-the-cve-workload-in-practice\" class=\"wp-block-heading\">Generic case study and managing the CVE workload in practice<\/h2>\n<p class=\"wp-block-paragraph\">There\u2019s an <strong>interesting and painstakingly clear example of what happens in an organization managing risk<\/strong> by Australian Cybersecurity Magazine. If you\u2019ve ever worked in any organization, this article will ring loud and true. The author, Amit Shingala, CEO of Motadata, spells it out.<\/p>\n<p class=\"wp-block-paragraph\">CVE disclosure is the beginning. What happens next is a handling issue. You need to read the article, but it\u2019s plain to see that fixes are more labours of love than defining what\u2019s actually done about CVEs.<\/p>\n<p class=\"wp-block-paragraph\">The scenario is this. The building might burn down. There are known risks, and in the case of CVEs, fire accelerants are all over the place. Someone has the extinguisher, but will it get to the fire if it breaks out? Will the accelerants be removed? Anyone\u2019s guess, and that\u2019s despite all this information going to people who know what they\u2019re doing.<\/p>\n<h2 id=\"h-future-risks-automated-cves-saas-and-what-s-next\" class=\"wp-block-heading\">Future risks, automated CVEs, SaaS, and what\u2019s next?<\/h2>\n<p class=\"wp-block-paragraph\">Now add to this idyllic environment the unquantifiable number of risks, operations, systems, types of systems, and heirloom problems from old software vs AI and dangerous bad actors.<\/p>\n<p class=\"wp-block-paragraph\">Let\u2019s summarize:<\/p>\n<p class=\"wp-block-paragraph\"><em>You get one shot at fixing a CVE before it hits the fan.<\/em><\/p>\n<p class=\"wp-block-paragraph\"><em>In-house IT and SaaS may or may not be able to manage the threats.<\/em><\/p>\n<p class=\"wp-block-paragraph\"><em>SaaS isn\u2019t a synonym for cybersecurity and may not be contracted to do it anyway.<\/em><\/p>\n<p class=\"wp-block-paragraph\"><em>You can automate CVE reporting and fixes with AI, maybe, but you still have to oversight and make sure that the fixes work.<\/em><\/p>\n<p class=\"wp-block-paragraph\"><em>The obvious process is Read CVEs\/List relevance\/Fix\/Check fixes<\/em><\/p>\n<p class=\"wp-block-paragraph\">Questions arise, and none of them are rhetorical:<\/p>\n<p class=\"wp-block-paragraph\"><em>How do you assess risk in dollar terms, as in what could be fatal?<\/em><\/p>\n<p class=\"wp-block-paragraph\"><em>If X project is derailed by a risk, what are your contingency options?<\/em><\/p>\n<p class=\"wp-block-paragraph\"><em>Can you handle any projected volume of CVEs?<\/em><\/p>\n<p class=\"wp-block-paragraph\"><em>How do you actually prioritize risk, even if you can do it in your sleep?<\/em><\/p>\n<p class=\"wp-block-paragraph\"><em>How much of the inevitable obsolete stuff is an inherent risk?<\/em><\/p>\n<p class=\"wp-block-paragraph\"><em>What\u2019s the workload for managing CVEs, and can you do that?<\/em><\/p>\n<p class=\"wp-block-paragraph\"><em>What about timeframes, meaning when do you know you\u2019re secure?<\/em><\/p>\n<h2 id=\"h-you-can-t-bounce-when-you-hit-a-bottom-line\" class=\"wp-block-heading\">You can\u2019t bounce when you hit a bottom line<\/h2>\n<p class=\"wp-block-paragraph\">Earlier this year, the Council on Foreign Relations nailed a critical point. <strong>Claude is just the beginning.<\/strong> As AI rewilds itself, there may be many Claudes, and they\u2019ll be feral.<\/p>\n<p class=\"wp-block-paragraph\">Claude is benign. It has a critical lead in its field. It may be able to predict vulnerabilities as well. It makes sense that new code is made bulletproof, but that\u2019s exactly what Claude\u2019s finding vulnerabilities in previously deemed safe software environments.<\/p>\n<p class=\"wp-block-paragraph\">The expression \u201cbottom line\u201d refers to the bottom line on a balance sheet. When an organization takes a breach hit, the shock from the hit instantly transfers to the bottom line. It may be a hit to confidence, the stock price, or hard money outlays in compensation.<\/p>\n<p class=\"wp-block-paragraph\">Bottom lines can\u2019t be ignored. Nor can CVEs. \u00a0<\/p>\n<\/div>\n<p><!-- \u603b\u5bb9\u5668\uff1a\u6700\u5927\u5bbd908px Grid\u7d27\u51d1\u5e03\u5c40 -->\r\n<div style=\"display: grid; grid-template-columns: 728px 160px; gap:2px; width:908px; background:#eee; padding:2px;\">\r\n\r\n  <!-- \u901a\u680f\u9876\u90e8\uff1a\u6700\u5927\u6a2a\u5e45 908x258 \u8de8\u6574\u884c -->\r\n  <div style=\"grid-column:1\/-1; height:258px; background:#ff6b6b; display:grid; place-items:center;\">\r\n    <!-- JuicyAds v3.0 -->\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async src=\"https:\/\/poweredby.jads.co\/js\/jads.js\"><\/script>\r\n<ins id=\"1114307\" data-width=\"908\" data-height=\"258\"><\/ins>\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async>(adsbyjuicy = window.adsbyjuicy || []).push({'adzone':1114307});<\/script>\r\n<!--JuicyAds END-->\r\n  <\/div>\r\n\r\n  <!-- \u7b2c\u4e8c\u901a\u680f\uff1a728\u00d790 \u901a\u680f -->\r\n  <div style=\"grid-column:1\/-1; height:90px; background:#4ecdc4; display:grid; place-items:center;\">\r\n    <!-- JuicyAds v3.0 -->\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async src=\"https:\/\/poweredby.jads.co\/js\/jads.js\"><\/script>\r\n<ins id=\"1114300\" data-width=\"728\" data-height=\"90\"><\/ins>\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async>(adsbyjuicy = window.adsbyjuicy || []).push({'adzone':1114300});<\/script>\r\n<!--JuicyAds END-->\r\n  <\/div>\r\n\r\n  <!-- \u5de6\u4fa7\u4e3b\u680f\uff1a\u591a\u5e7f\u544a\u5806\u53e0 -->\r\n  <div style=\"display:grid; gap:2px;\">\r\n    <div style=\"height:60px; background:#45b7d1; display:grid; place-items:center;\">\r\n\t<!-- JuicyAds v3.0 -->\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async src=\"https:\/\/poweredby.jads.co\/js\/jads.js\"><\/script>\r\n<ins id=\"1114308\" data-width=\"468\" data-height=\"60\"><\/ins>\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async>(adsbyjuicy = window.adsbyjuicy || []).push({'adzone':1114308});<\/script>\r\n<!--JuicyAds END-->\r\n\t<\/div>\r\n    <div style=\"height:250px; background:#ffe066; display:grid; place-items:center;\">\r\n\t<!-- JuicyAds v3.0 -->\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async src=\"https:\/\/poweredby.jads.co\/js\/jads.js\"><\/script>\r\n<ins id=\"1114299\" data-width=\"300\" data-height=\"250\"><\/ins>\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async>(adsbyjuicy = window.adsbyjuicy || []).push({'adzone':1114299});<\/script>\r\n<!--JuicyAds END-->\r\n\t<\/div>\r\n    <div style=\"height:250px; background:#ff9ecd; display:grid; place-items:center;\">\r\n\t<!-- JuicyAds v3.0 -->\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async src=\"https:\/\/poweredby.jads.co\/js\/jads.js\"><\/script>\r\n<ins id=\"1114305\" data-width=\"250\" data-height=\"250\"><\/ins>\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async>(adsbyjuicy = window.adsbyjuicy || []).push({'adzone':1114305});<\/script>\r\n<!--JuicyAds END-->\r\n\t<\/div>\r\n    <div style=\"height:139px; background:#c792ea; display:grid; place-items:center;\">\r\n\t<!-- JuicyAds v3.0 -->\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async src=\"https:\/\/poweredby.jads.co\/js\/jads.js\"><\/script>\r\n<ins id=\"1114302\" data-width=\"133\" data-height=\"139\"><\/ins>\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async>(adsbyjuicy = window.adsbyjuicy || []).push({'adzone':1114302});<\/script>\r\n<!--JuicyAds END-->\r\n\t<\/div>\r\n    <div style=\"height:125px; background:#91e7ac; display:grid; place-items:center;\">\r\n\t\r\n<!-- JuicyAds v3.0 -->\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async src=\"https:\/\/poweredby.jads.co\/js\/jads.js\"><\/script>\r\n<ins id=\"1114303\" data-width=\"125\" data-height=\"125\"><\/ins>\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async>(adsbyjuicy = window.adsbyjuicy || []).push({'adzone':1114303});<\/script>\r\n<!--JuicyAds END-->\r\n\t<\/div>\r\n  <\/div>\r\n\r\n  <!-- \u53f3\u4fa7\u7ad6\u680f\uff1a160\u00d7600 \u6574\u5217\u9ad8\u5e7f\u544a -->\r\n  <div style=\"grid-row:3\/8; height:600px;  display:grid; place-items:center;\">\r\n    <!-- JuicyAds v3.0 -->\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async src=\"https:\/\/poweredby.jads.co\/js\/jads.js\"><\/script>\r\n<ins id=\"1114301\" data-width=\"160\" data-height=\"600\"><\/ins>\r\n<script type=\"text\/javascript\" data-cfasync=\"false\" async>(adsbyjuicy = window.adsbyjuicy || []).push({'adzone':1114301});<\/script>\r\n<!--JuicyAds END-->\r\n  <\/div>\r\n\r\n<\/div><br \/>\n<br \/> Op-Ed: Are \u2018Common Vulnerabilities and Exposures\u2019 the reality of chronic cyber insecurity?<br \/>\n<br \/>#OpEd #Common #Vulnerabilities #Exposures #reality #chronic #cyber #insecurity<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Common Vulnerabilities and Exposures (CVEs) are exactly that. They\u2019re endemic problems for cybersecurity. Lists of&#8230;<\/p>\n","protected":false},"author":1,"featured_media":18382,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7],"tags":[15131,1057,4183,15130,7714,7300,1169,15129],"class_list":["post-19746","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-stories","tag-chronic","tag-common","tag-cyber","tag-exposures","tag-insecurity","tag-oped","tag-reality","tag-vulnerabilities"],"featured_image_urls":{"full":["https:\/\/8657085.xyz\/wp-content\/uploads\/2026\/07\/e2c272bbe87510fd7b3adb56b8df266525976092-1.jpg",768,512,false],"thumbnail":["https:\/\/8657085.xyz\/wp-content\/uploads\/2026\/07\/e2c272bbe87510fd7b3adb56b8df266525976092-1-150x150.jpg",150,150,true],"medium":["https:\/\/8657085.xyz\/wp-content\/uploads\/2026\/07\/e2c272bbe87510fd7b3adb56b8df266525976092-1-300x200.jpg",300,200,true],"medium_large":["https:\/\/8657085.xyz\/wp-content\/uploads\/2026\/07\/e2c272bbe87510fd7b3adb56b8df266525976092-1.jpg",640,427,false],"large":["https:\/\/8657085.xyz\/wp-content\/uploads\/2026\/07\/e2c272bbe87510fd7b3adb56b8df266525976092-1.jpg",640,427,false],"1536x1536":["https:\/\/8657085.xyz\/wp-content\/uploads\/2026\/07\/e2c272bbe87510fd7b3adb56b8df266525976092-1.jpg",768,512,false],"2048x2048":["https:\/\/8657085.xyz\/wp-content\/uploads\/2026\/07\/e2c272bbe87510fd7b3adb56b8df266525976092-1.jpg",768,512,false],"covernews-slider-full":["https:\/\/8657085.xyz\/wp-content\/uploads\/2026\/07\/e2c272bbe87510fd7b3adb56b8df266525976092-1.jpg",768,512,false],"covernews-slider-center":["https:\/\/8657085.xyz\/wp-content\/uploads\/2026\/07\/e2c272bbe87510fd7b3adb56b8df266525976092-1-768x500.jpg",768,500,true],"covernews-featured":["https:\/\/8657085.xyz\/wp-content\/uploads\/2026\/07\/e2c272bbe87510fd7b3adb56b8df266525976092-1.jpg",768,512,false],"covernews-medium":["https:\/\/8657085.xyz\/wp-content\/uploads\/2026\/07\/e2c272bbe87510fd7b3adb56b8df266525976092-1-540x340.jpg",540,340,true],"covernews-medium-square":["https:\/\/8657085.xyz\/wp-content\/uploads\/2026\/07\/e2c272bbe87510fd7b3adb56b8df266525976092-1-400x250.jpg",400,250,true]},"author_info":{"display_name":"admin","author_link":"https:\/\/8657085.xyz\/?author=1"},"category_info":"<a href=\"https:\/\/8657085.xyz\/?cat=7\" rel=\"category\">Stories<\/a>","tag_info":"Stories","comment_count":"0","_links":{"self":[{"href":"https:\/\/8657085.xyz\/index.php?rest_route=\/wp\/v2\/posts\/19746","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/8657085.xyz\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/8657085.xyz\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/8657085.xyz\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/8657085.xyz\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=19746"}],"version-history":[{"count":0,"href":"https:\/\/8657085.xyz\/index.php?rest_route=\/wp\/v2\/posts\/19746\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/8657085.xyz\/index.php?rest_route=\/wp\/v2\/media\/18382"}],"wp:attachment":[{"href":"https:\/\/8657085.xyz\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=19746"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/8657085.xyz\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=19746"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/8657085.xyz\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=19746"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}