Security1 distinct publisher3 min readPublished
Wiz says the disclosure-to-exploitation window has fallen from over two years to 21.5 days, and that more than half of high-priority findings vanish once reachability is applied. Both numbers are its own.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Start with the arithmetic, because it is the part that does not depend on anyone's product. A window of more than two years narrowing to 21.5 days is roughly a 34-fold compression [2][1], and the resulting figure fits inside a single calendar month [2] - the same month that holds change approval, maintenance windows and regression testing. A backlog ordered by severity score assumes you eventually reach the bottom of it. At that average, the ordering no longer decides what waits. It decides what never gets touched.
The measurement worth arguing about is Wiz's own. It took high-priority alerts in enterprise environments and re-scored them against external reachability, toxic permission combinations and access to sensitive data [3], and across four major risk categories more than half of the initial findings did not survive [4]. Turned around, fewer than half of the alerts already escalated as high priority described something an attacker could use [3]. Wiz's framing of why is consistent with that: the severity of an intrusion is set by what an adversary can inherit and pivot to, not by the foothold [8].
The obvious caveat is that this is a vendor measuring the value of the capability it sells, on its own blog, with the full report behind a download [9]. The internal figures at least point the same way. Software remote code execution was 9% of observed findings [6], which leaves 91% sitting elsewhere [4], and Wiz says real-world exploitability favours exposed access pathways, credentials and secrets over software CVEs [11]. That is an awkward result for the way most programmes are staffed, because the queue that gets a weekly meeting is the CVE queue, and the data needed to rank by reachability - IAM relationships, network exposure, data classification - usually belongs to a different team.
Context filtering also does not empty the tray. Thirty per cent of observed environments already contain at least one externally exposed machine tied to a high-impact lateral movement path [5]. In roughly one environment in three, the filter returns a live finding rather than nothing, and that finding is the one that would have been buried in a severity-sorted list next to several hundred theoretical ones. Wiz's own stated failure mode is fatigue: equal urgency for every isolated flaw burns engineering cycles on risk that is not reachable [10].
Which leaves the gap in the post. Its most operationally useful assertion is that a small number of technologies accounts for most critical weaponized exploits [7] - and the supplied text names none of them and attaches no percentage. If weaponization averages 21.5 days [2], the planning question is which handful of technologies you would defend if you could only defend a handful. That list is the one part not printed.
Ranked by verification strength, evidence, and original report placement.
According to data from ZeroDayClock cited by Wiz, the average window between vulnerability disclosure and active in-the-wild exploitation has fallen over the past several years from over two years to 21.5 days.
Wiz Research evaluated high-priority alerts across enterprise environments before and after applying critical risk criteria including external reachability, toxic permission combinations and sensitive data access.
Across four major risk categories, Wiz says contextual analysis eliminated more than half of the initial findings.
Wiz reports that 30% of observed cloud environments already contain at least one externally exposed machine tied to high-impact lateral movement paths.
Wiz argues the true severity of an intrusion is defined not by the initial foothold but by privilege and reachability: what an adversary can inherit, access or pivot to next.
Wiz says real-world exploitability heavily favours exposed access pathways, credentials and secrets over software CVEs, which vulnerability management programmes traditionally prioritise.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single self-published vendor source with the supporting figures withheld
Every number comes from one blog post by the vendor whose product the conclusion favours. The headline 21.5-day figure is attributed to ZeroDayClock with no link, date range or methodology; the 'more than half' reduction is introduced with a colon whose per-category breakdown is absent from the supplied text; the technology concentration claim names no technologies and gives no percentages; and no environment count, alert volume or time window is disclosed for any 'observed' statistic. The claims are internally consistent and the arithmetic derivations hold, which keeps this above the floor, but nothing here is independently verifiable from the supplied material.
No uptake signal beyond the vendor's own publication
The supplied material documents a report release and the vendor's disclosure of its own telemetry aggregates. It contains no evidence that any organisation has adopted the Contextual Risk Prioritization Model, no customer counts, no deployment or usage figures for the approach, and no third-party benchmark or replication. Adoption cannot be scored without inferring facts the source does not provide.
Framing runs ahead of the disclosed data
The post's conclusions -- that severity-score triage should be retired and that remediation should concentrate on a small technology cluster -- are stated with more certainty than the published figures carry. The most decision-relevant details (per-category reduction numbers, the named technologies, the ZeroDayClock methodology, the size of the observed population) are either absent or behind the gated report, while the takeaways are written as settled practice. The gap is moderate rather than severe because the specific numbers presented are precise, plausible and consistent with the argued thesis.
Vendor research promoting the vendor's own product category
Wiz is a cloud security vendor and the conclusion -- that contextual, reachability- and privilege-aware prioritization beats severity-score triage -- describes what its platform sells. The post is self-published, closes with a download call-to-action for the gated report and its 13-tier Contextual Risk Prioritization Model, and is immediately followed by a personalized-demo prompt and three named customer testimonials, including one asserting that Wiz's critical findings are genuinely critical. The alignment between the finding and the seller's commercial interest is close to total.
Low-moderate: internally clear, externally unverified
What Wiz says is unambiguous and the derived arithmetic is sound, so the reading of the claims is high confidence. Confidence in the underlying facts is low: one publisher, one self-interested source, missing methodology and missing supporting figures, and no adoption evidence to triangulate against. Independent measurement of the exploitation window or replication of the reachability filter effect would move this materially.
product
AI writes the Dockerfile, and the pipeline is still checking the app code1 distinct publisher
build
Amazon Q executed code from any repo you opened, and it is not the only one1 distinct publisher
build
A cleanup commit deleted the sanitizer. Five days later a scanner cashed it in.1 distinct publisher
product
The AI-wrote-it claim died in eight hours. The Actions injection pattern did not.1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 26, 2026