A post at The Hacker News puts published CVEs up roughly 49 percent year over year and observed exploitation at 495. For operators the figure that changes triage is the 116 attacked on the day they went public.
Reality
- Evidence30
- Adoption20
- Hype gap+30
- Incentives85
- Confidence40
PaperCut told NG and MF customers on August 27 that servers were already being exploited, with no CVE and no fix available. A patch that held arrived on September 1, and Picus Security says that gap is now the normal shape of a zero-day.
Reality
- Evidence34
- Adoption22
- Hype gap+45
- Incentives86
- Confidence52
Picus's Blue Report blames performance issues and log-collection gaps for the misses, both of them configuration work, which is why an AI SOC pointed at that pipeline would only get faster at the one action in seven that already alerts.
Reality
- Evidence32
- Adoption28
- Hype gap+45
- Incentives88
- Confidence52
Two years of SIEM ingestion cuts left the data layer that agentic detection will run on, and 24% of security leaders now rank visibility above staffing as their top barrier.
Reality
- Evidence63
- Adoption38
- Hype gap+24
- Incentives76
- Confidence62
Picus says its 338-million-simulation dataset shows prevention recovering. The same dataset shows one credential-dumping tool blocked 94% of the time by one route and 3% by another.
Reality
- Evidence32
- Adoption24
- Hype gap+32
- Incentives86
- Confidence38