Two-thirds of breaches don’t start with an unpatched CVE.

That number landed in front of cybersecurity leaders at Tenable’s EXPOSURE 2026 event in Boston last week, courtesy of Chief Product Officer Eric Doerr, and it should be the only stat on your desk this morning. Misconfigurations. Stolen credentials. Exposed secrets. Those are how attackers walk in now. The patch queue you’ve been grinding through covers the other third.

Your Cybersecurity Math Is Broken

Median time to exploit a vulnerability has collapsed from 84 days in 2021 to 1.6 days today, per Zero Day Clock. Median patch time for critical CVEs went the wrong direction, hitting 43 days in 2025, up 34% from the year before.

That gap is the entire attack window.

The race is unwinnable even if you sprint. The 2026 Verizon DBIR puts unpatched CVEs at 31% of breach initial access. Everything else, the 69%, is credentials someone reused, secrets someone hardcoded, S3 buckets someone misconfigured, OAuth tokens someone forgot to rotate.

Lithuania’s Prosecutor General’s Office disclosed on Friday that a foreign actor accessed more than 600,000 records at the Centre of Registers, the state agency that handles property and legal entity data. The vector hasn’t been named publicly. State registries rarely fall to a fresh zero-day. They fall to someone who got access they shouldn’t have, and kept it longer than anyone noticed.

Where The Actual Perimeter Lives Now

Your SaaS tenants. Your identity provider. Your CI/CD runners. Your developers’ extension marketplaces. The dev and staging instances of the same SaaS app where MFA was never enforced. AppOmni’s new Marlin agent for SaaS investigation exists because nobody has the staff to chase down every misconfigured admin role and stale guest user across Salesforce, Workday, ServiceNow, Slack, and the 47 other tenants quietly billing your finance team. Vendors selling autonomous agents to do that work is the loudest possible signal about where the breaches are actually happening.

Pair that with what attackers are doing on the access side. Malwarebytes documented fake installers for ChatGPT, Claude, AutoTune, and other popular tools sitting on GitHub and SourceForge, dropping Deno RAT for full device takeover.

No CVE involved.

Just a search result, a trusted-looking domain, and a developer who needed the tool yesterday. The Hacker News flagged AI-assisted DDoS campaigns hunting for weak configurations at machine speed. Attackers want your configuration wrong, your credentials leaked, or your user clicking. Cyber security planning built around CVSS scores misses every one of those.

What To Actually Do This Quarter

Reorganize defense around exposure, not CVE count. The work isn’t glamorous and doesn’t fit on one dashboard. Concrete steps:

  • Inventory every identity, role, and token across your top ten SaaS tenants. Flag stale admins, never-logged-in service accounts, and OAuth grants nobody can explain. That inventory is where most of your breach probability actually lives.
  • Map exposed secrets across repos, CI logs, container images, and Terraform state. Treat any hit as a credential rotation event, not a Jira ticket.
  • Cut session and token lifetimes hard. If a stolen refresh token still works in a month, you have a token problem dressed up as an MFA story.
  • Enforce edge brute-force controls on every public auth endpoint, including vendor portals and SaaS admin consoles. Tools like IPBan or IPBan Pro at the network firewall edge raise the cost of credential stuffing long before a SaaS provider’s own threat detection wakes up.
  • Move patching from calendar-based to exposure-based. A reachable, internet-facing, exploited-in-the-wild CVE on a sensitive asset jumps the queue. A buried library nobody calls waits.
  • Rehearse incident response for non-CVE intrusions: stolen Workday admin, exposed CI/CD secret, malicious VS Code extension on a developer laptop. Most IR playbooks still assume malware was involved at some point in the kill chain.
  • Set a quarterly target for reducing standing privilege. Just-in-time access for admin roles is cheap insurance against the credential theft that’s powering the 69%.

This is defense in depth, done honestly. Security hardening on the identity and configuration layers. Threat protection tuned for behavioral anomalies, impossible travel, first-seen API consumers, suspicious admin role grants, sudden OAuth scope upgrades. A firewall posture that assumes the patch queue is permanently behind, because it is.

The Lithuania breach will get attributed to a sophisticated state-aligned actor, and that framing will be useful for the press release. Strip it away and you’ll find what you always find: an access path that shouldn’t have existed, or a credential that shouldn’t have been valid. The 34% problem makes the news. The 66% problem is the one quietly draining your environment right now.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.