The gap between a vulnerability being disclosed and being attacked in the wild has collapsed from more than two years to 21.5 days. That figure, from ZeroDayClock data cited by Wiz Research, is the frame for a report the company published on 26 August, and it sets up an uncomfortable argument: defenders cannot patch fast enough to win on speed alone, so most of them are racing on the wrong problem.
Wiz Threat Research's finding is that most high-severity alerts are not real attacker opportunities at all.
An alert on its own is not a way in
The team took high-priority alerts across enterprise environments and re-scored them against what it calls critical risk criteria: whether the affected thing is reachable from the internet, whether it sits next to a toxic combination of permissions, and whether it can touch sensitive data. Across four major risk categories, that contextual analysis eliminated more than half of the initial findings.
The reasoning is the useful part. A vulnerable package or a weak credential only becomes an attacker's opportunity when something downstream connects it to the outside world or to privilege. Without external exposure, a lateral movement path, or an adjacent high-privilege IAM role, an isolated flaw rarely gives anyone a viable route through the environment. Rank by severity score alone and you spend engineering weeks on risks nobody can actually reach.
Reachability beats the perimeter
Two numbers carry the rest of the case. Wiz says 30 percent of observed cloud environments already contain at least one externally exposed machine tied to high-impact lateral movement paths, which is to say the perimeter is already open in roughly a third of them. And software remote code execution made up only 9 percent of observed findings, well behind exposed access pathways, credentials and secrets.
That inverts how most vulnerability management programmes are built. The severity of an intrusion, on this reading, is set less by how an attacker gets the first foothold than by what that foothold inherits and can pivot to next. It is a familiar pattern in real intrusions: earlier this month Wiz documented an extortion crew that worked purely through stolen cloud service account credentials, no software exploit required. The compressed exploitation window shows up on the other side too, in cases like the SharePoint flaw that had two public exploit paths within days.
What this does and does not prove
This is one vendor's telemetry from its own customer base, and it is being used to sell a prioritization model, so read the numbers accordingly. The blog post does not name the four risk categories it aggregates, does not give a sample size or time window, and leaves the per-category figures in the charts of the downloadable report rather than the public write-up. The 21.5-day exploitation window is ZeroDayClock's measurement, not Wiz's own. What the post does support is a direction of travel that several independent datasets have pointed at for a while, and a claim that is testable in your own environment tomorrow.
Re-rank your backlog before you extend it
The practical move is not a new tool. Take the current high-severity backlog and filter it once for internet reachability, once for privilege adjacency, and once for access to sensitive data, then see what survives. If Wiz's ratio holds anywhere close, the surviving list is small enough to actually finish. Wiz Research's post is available as the original report summary, with the full dataset and its 13-tier contextual risk prioritization model behind a download.
Exploitable risk, the report argues, is concentrated rather than evenly spread: a small fraction of technologies accounts for most weaponized exploits. If that is right, the win is not patching more. It is knowing which handful to patch first.
This briefing is provided by IntelFusions for informational and defensive purposes only. It is based on sources assessed to be reliable at the time of writing, and analytic judgments carry the confidence levels indicated. Indicators of compromise are defanged; re-arm them only in controlled environments. IntelFusions is not affiliated with the organizations named and makes no warranty as to completeness or accuracy.