Some 12,723 security vulnerabilities were disclosed during the first half of 2021, indicating slow growth of disclosures but a seemingly insurmountable mountain of work for security personnel seeking to minimize risk, according to a report released in August by Risk Based Security Inc.[1]
That makes focusing on specific threats—those that have a public exploit and also a mitigating solution—more important than a patch-as-many-as-you-can approach, the report concluded.
In the first half of 2021, Risk Based Security’s VulnDB team aggregated an average of 80 new vulnerabilities per day, even as organizations edged toward a return to normal following the disruptions of the COVID-19 pandemic, the report said.
“Organizations may be comfortable returning to their previous processes, but the fundamental problem still remains: there are too many vulnerabilities for many organizations to realistically handle unless they adopt a truly risk-based approach to patching,” the report said.