Separating vulnerability disclosure volume from exploitable risk.

Separating vulnerability disclosure volume from exploitable risk.

🎙 Shira Rubinoff 👥 937K 📅 August 4, 2026 ⏱ 13 min 👁 111K 📄 expert opinion 🧭 2026-08-15
Available in: English (current) Français

Keywords

CVEexploitable riskvirtual patchingCISA KEVAI-driven attacks

Summary

In this interview at Black Hat, Shira Rubinoff talks with Johnny Hand, Global CISO at Trend AI, about the challenge of separating vulnerability disclosure volume from actual exploitable risk. Hand argues that while the total number of disclosed CVEs is rising (from 48,000 in 2025 to a projected 66,000-70,000 in 2026), the number of critical and high-severity CVEs has remained flat or slightly declined. He emphasizes that security teams should focus on the 1% of vulnerabilities that are truly exploitable, rather than being overwhelmed by volume. He recommends three pillars for CISOs: report on actionable metrics, prioritize based on confirmed exploitation (e.g., CISA KEV), and use virtual patching to close the gap between disclosure and patch availability. Hand explains that virtual patching has evolved from a temporary fix to a strategic necessity, especially for critical infrastructure and OT environments where patching is often impossible. He highlights Trend AI’s Vision One platform for exposure management, which correlates vulnerabilities with user behavior and risk factors. The interview concludes with promotional details about Trend AI’s presence at Black Hat.

176 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable insights into the current state of vulnerability management, particularly the distinction between vulnerability volume and actual risk. The argumentation is coherent and well-structured, with concrete examples and references to industry data (e.g., CVE counts, CISA KEV). The expert’s perspective is credible, though the discussion is somewhat high-level and lacks deep technical detail. The promotional nature of the content slightly detracts from its objectivity, but the core advice is practical and actionable.

Scientific Rigor, Source Quality, Title Accuracy

The scientific rigor is moderate. The video cites specific data points (e.g., 48,000 CVEs in 2025, projected 66,000-70,000 in 2026) and references CISA’s KEV database, but does not provide detailed sources or methodology. The title accurately reflects the content. The description includes a link to a Trend Micro research article, which serves as a source for further reading. No comments were provided for analysis.

154 words

Title / Content Match

The title accurately reflects the core discussion about distinguishing vulnerability volume from actual exploitable risk.

Quality & Reliability

7/10

The video features an expert interview with Johnny Hand, Global CISO at Trend AI, providing informed opinions and references to industry data (e.g., CVE counts, CISA KEV). However, it is largely promotional and lacks detailed methodological transparency.

Key Moments

Cited Sources

Concurring Sources

  • CISA Known Exploited Vulnerabilities Catalog — Supports the recommendation to prioritize confirmed exploited vulnerabilities.

Contribution & Novelties

The video offers a practical perspective on vulnerability management, emphasizing the need to focus on exploitable risk rather than raw CVE counts. It provides actionable advice for CISOs, such as using CISA KEV and virtual patching. The discussion is timely given the rise of AI-driven attacks.

Pour aller plus loin :

  • CISA Known Exploited Vulnerabilities Catalog — Official list of vulnerabilities known to be exploited, useful for prioritization.
  • Virtual Patching — Overview of virtual patching techniques and benefits.
  • CVE Program — Official CVE database for tracking vulnerabilities.

87 words

Radar Profile

The radar profile shows a balanced performance across all dimensions, with slightly higher scores in information quantity and quality, reflecting the expert interview format. The technical level is moderate, suitable for a broad security audience.

Reliability 7/10