Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Monday, 15 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

6% of All Published CVEs Have Been Exploited in the Wild, Report Finds

The move is a critical step towards vulnerability scoring standardisation, according to ACDS

by Guru Writer
July 31, 2024
in Editor's News
6% of All Published CVEs Have Been Exploited in the Wild, Report Finds
Share on FacebookShare on Twitter

Research from earlier this year revealed a worrying uptick in cyberattack volume in the past 24 months, with over a third (36%) of organisations admitting to experiencing three or more data breaches in this time frame. With attack volume increasing, one thing is called into question time and time again: vulnerability prioritisation. The Inaugural Study of EPSS Data and Performance report studies exactly this. 

The report outlines vulnerability exploitation in the wild since 2017. Developed by the Cyentia Institute, the report is a data-driven collaborative effort for estimating the likelihood that a published vulnerability will be exploited in the wild. Its goal is to assist defenders to better prioritise vulnerability remediation efforts, putting focus on assessing risk. EPSS, which data is regularly contributed to by the community, uses current threat information targeting CVEs along with real-world exploit data. The EPSS model produces a daily updated prediction of the probability that a vulnerability will be exploited in the next 30 days. 

The EPSS research found that there were 237,687 published CVEs as of May 31st 2024, with 13,807 being observed with exploitation activity. In the last 12 months, 30,000 CVEs have been published, with the annual rate varying around the average of 16%. Ultimately, the rising amount of vulnerabilities threatens to overwhelm vulnerability management teams if remediation cannot be prioritised. 

Of these near-250k published CVEs, the number of known-exploited vulnerabilities is steadily approaching 15,000. This means that about 6% of all published CVEs have been exploited in the wild – and that rate is holding steady. Such figures show that tracking and predicting known exploits is critical for efficient remediation.  

The EPSS aims to distil data from multiple different sources into evaluated exploit predictions within the next 30 days by focusing on coverage, efficiency and effort. EPSS empowers vulnerability management teams with a simple scoring system that can be used by anyone, regardless of industry or organisation. The system is a big stride for risk-based reporting. However, it is imperative that larger tech, cyber and cloud organisations pool data into independent schemes like EPSS to maximise its impact.

The report is sponsored by Advanced Cyber Defence Systems (ACDS), among other forward thinking organisations. But why is the step important? According to Elliott Wilkes, CTO of ACDS: “EPSS is the logical next step in quantifying the risk of a vulnerability with impact. The EPSS has the potential to be a gamechanger, if it is adopted widely. It’s a move to a much more reliable, data driven system that helps teams understand, predict, and protect future likelihood. The scoring system enables and supports data driven conversations between technical professions and board members. It quantifies risk, agnostic to any one organisation.”

EPSS aims to help leaders prioritise remediation of relevant CVEs that have the potential to cause disruption within their organisations, moving to a more standardised approach to vulnerability management. 

ACDS are active supporters in other independent industry-led schemes and standards. Earlier this year, ACDS became an early supporter of CISA’s Secure by Design Pledge. The scheme aims to encourage developers to build software that’s foundationally secure by design, in essence helping both engineering and security teams. Such schemes bolster the security of the entire industry and broader world. 

Elliott Wilkes dives into this topic more in his bi-weekly LinkedIn newsletter, Hacker Headspace, saying: “Building an open cybersecurity community is vital for resilience, especially when supporting government led schemes where we can cultivate a united front against cyber threats… Why? Because we believe it’s more powerful – and valuable – to stand together as a whole, rather than lead the way with one.”

ShareTweet
Previous Post

HealthEquity Data Breach Compromises Customer Information

Next Post

Addressing communication roadblocks to overcome cybersecurity threats

Recent News

Check Point Expands MSP Platform with AI Security Capabilities and Unified Bundles

From Playbooks to Adaptive Workflows: How MSSPs Are Evolving Security Operations with Agentic AI

June 15, 2026
Nagomi Control Brings CTEM Into Action

2 in 5 Organisations Experienced Cyber Incidents Tied to Suppliers in Past Year

June 12, 2026
Certes Research Warns Legacy Systems Are Biggest Barrier to Quantum Security Readiness

KnowBe4 Expands Gamified Training Library With Launch of “Spot the Vish” Game

June 12, 2026
Swan Song For Infosec’s Most Gripping Awareness Training Series: The Inside Man Goes Out With A Star-Studded Bang

Swan Song For Infosec’s Most Gripping Awareness Training Series: The Inside Man Goes Out With A Star-Studded Bang

June 12, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol