June 26, 2025

The 0.6% That Actually Matters

The 0.6% That Actually Matters

Running short on time but still want to stay in the know? Well, we’ve got you covered! We’ve condensed all the key takeaways into a handy audio summary. Our AI-driven podcasts are fit for on the go. Click right here to hear it all on CAASM & CDMB Inefficiencies!

Your security team is drowning in alerts. Tens of thousands of vulnerabilities. Endless CVSS scores. Patch queues stretching into next quarter.

And 99.4% of it is complete waste.

The Cyber Horizons Report 2025 from HiveForce Labs shares a truth that should reshape everything: only 245 of the 39,983 vulnerabilities disclosed in 2024 were actually exploited in the wild. That's 0.6%.

Less than one percent of vulnerabilities had real-world impact. Yet organizations still treat all 39,000 as equal threats.

The Volume Trap

The cybersecurity industry built a monument to inefficiency. "Patch everything" became gospel. CVSS scores became truth. Alert volume became success metrics.

Meanwhile, attackers ignored 99.4% of your vulnerability management program and focused on what actually worked.

In 2024, only 245 CVEs got exploited. 140 had publicly available proof-of-concepts, accelerating weaponization. 83 were zero-days, and 68% of those were used in active campaigns.

Threat actors don't need 39,000 bugs. They need a few unpatched, high-impact exposures to destroy your business.

CVSS Is Security Theater

CVSS scores rank threats by imaginary math. Threat actors rank threats by real-world results.

They care about exploitability, ease of access, chaining potential, target ubiquity. Some of the most devastating attacks in 2024 stemmed from mid-range CVSS vulnerabilities that were easy to weaponize. Many "critical" CVEs were never exploited at all.

This is where threat-informed prioritization destroys traditional vulnerability management: filtering vulnerabilities by active exploitation, threat actor behavior, and exposure context, not imaginary numeric ratings.

The 0.6% Pattern

Among the vulnerabilities that actually mattered, patterns emerge.

Many had public proof-of-concepts available within hours of disclosure. They were often paired with misconfigurations or stolen credentials to form exploit chains. They disproportionately affected systems like VPNs, CI/CD tools, and cloud identity infrastructure.

Attackers target assets with high blast radius: Ivanti VPNs, ConnectWise RMMs. They use zero-days and proof-of-concepts to gain initial access. They escalate privileges and move laterally via scripting interpreters like PowerShell and Bash.

Methodical. Selective. Effective.

The Exposure Revolution

Moving from reactive patching to precision defense requires abandoning vulnerability management for exposure management.

Focus on exploited CVEs first. If ransomware operators are using a vulnerability, it goes to the top of the list, regardless of CVSS.

Use threat intelligence to guide prioritization. Proof-of-concept availability, dark web chatter, inclusion in attack kits should elevate CVE priority.

Map vulnerabilities to critical business services. Not every CVE deserves equal attention. Focus on exposures affecting revenue-generating, safety-critical, or externally facing systems.

Track exposure debt, not just patch status. Exposure debt equals time a vulnerable system remains exposed after risk is known. That's a metric boards understand.

The Resource Reality

Your resources aren't infinite.
Your patching window isn't endless.
Your team isn't expandable.
So why waste time chasing vulnerabilities that don't matter?

Security isn't about reducing volume. It's about reducing risk. Your job isn't to patch 39,000 CVEs. Your job is to prevent breaches.

That means prioritizing vulnerabilities with real-world exploitability, vulnerabilities in high-value assets, vulnerabilities with chaining potential.

The 0.6% that attackers actually use.

Fix Less. Secure More.

Stop treating vulnerability management as a numbers game. Focus your efforts where attackers focus theirs. Track your exposure, not just your scan results. Secure your infrastructure against threats that are actually happening—not ones that might.

In the war against breach, it's not the thousands of CVEs that matter.

It's the few that do.

And now you know which ones those are.

Recent Resources

Dive into our library of resources for expert insights, guides, and in-depth analysis on maximizing Uni5 Xposure’s capabilities
Enterprise security analysts evaluating threat intelligence signals

Threat Intelligence News: Signal to Action

Learn how security teams evaluate threat intelligence news, validate relevance, and turn credible reporting into prioritized exposure decisions and action.
Read More
Security team connecting vulnerability scan findings to exposure priorities

Nessus vs Tenable: What Security Teams Should Know

Nessus vs Tenable explained for security teams: compare product scope, scanning use cases, prioritization context, and remediation workflows.
Read More
Security team reviewing safeguards for agentic AI workflows

Agentic AI Security: A Practical Guide to Safer Autonomous Workflows

Learn how to secure agentic AI with least-privilege access, guardrails, observability, testing, and human approval for safer enterprise workflows at scale.
Read More
Enterprise security team reviewing AI-assisted threat and exposure signals

AI Threat Detection for Proactive Exposure Management

Learn how AI threat detection supports exposure discovery, risk prioritization, validation, and response while preserving explainability and human oversight.
Read More
Enterprise security team evaluating vulnerability prioritization software through connected attack paths

Vulnerability Prioritization Software: Rank Risk Beyond CVSS

Vulnerability prioritization software ranks exposure using exploit activity, asset criticality, and business context to move beyond CVSS-only queues today.
Read More
Enterprise security team mapping identity attack surface exposure

Identity Attack Surface Management: Enterprise Guide

Learn what identity attack surface management covers, where access risk hides, and how teams can evaluate discovery, prioritization, and remediation.
Read More

What’s new on Hive Pro?

Get through updates and upcoming events, and more directly in your inbox

Reduce real exposure. Not just vulnerability volume.