Down the Security Rabbithole Podcast (DtSR)
Down the Security Rabbithole Podcast (DtSR)
Down the Security Rabbithole Podcast (DtSR)·Sep 9, 2026·48m·Episode #722

DtSR Episode 722 - Vulnerability Math Ain't Mathing

Show notes

TL;DR: Robert "RSnake" Hansen & Jeremiah Grossman join the pod to talk about the "Vuln-pocalypse", or rather, the lack thereof. We do some math, discuss whether it's worth patching vulnerabilities attackers don't exploit, and discuss a potential alternative to the madness of vuln management and patching we're all living with today.

Guests

Description

The “vulnerability apocalypse” makes great headlines, but our day-to-day reality is stranger: more scanners, more CVEs, more urgency, and still the same breaches. We sit down with Jeremiah Grossman and Robert Hansen from Root Evidence to ask a blunt question most security teams avoid saying out loud: if the overwhelming majority of known vulnerabilities are never exploited, why are we treating every patch like a debt we must repay at any cost?

We dig into where vulnerability management went off the rails. CVSS scores and severity tiers often turn into a kind of black magic, especially at enterprise scale where “patch everything” can be operationally impossible and sometimes actively dangerous. We share real-world patching fallout, talk about why prioritizing millions of findings is like turning the Titanic with a teaspoon, and outline what “reasonable” can look like when you stop optimizing for perfect dashboards and start optimizing for outcomes.

The turning point is data. Cyber insurance carriers and DFIR teams perform root cause analysis on real claims, and that actuarial view shows which remotely exploitable vulnerabilities actually drive financial loss. We talk about focusing on known exploited vulnerabilities, why a relatively small list of CVEs can matter more than thousands of “critical” alerts, and how controls like MDR, canary tokens, and segmentation help prevent exploitation from becoming a business-ending event.

We also pressure-test the AI panic. According to multiple carriers, AI-attributed losses are effectively zero when you exclude phishing, raising an uncomfortable thought: are we funding fear instead of risk reduction? If you want a more evidence-based approach to patch management, cyber risk, and cybersecurity ROI, hit play, subscribe, and share the episode, then leave us a review with the one change you’d make to how your team prioritizes vulnerabilities.

YouTube Video: https://youtube.com/live/wC1v8Vg7qr4

Have something to say? Let's hear it.

Support the show

>>> Please consider clicking the link above to support the show!
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=
YouTube home: https://youtube.com/playlist?list=PLyo0dkKRvfVtWXjRxNISrhme1MgBj3C2U&si=scHDiTuLXSEQ9qHq
LinkedIn Page: https://www.linkedin.com/company/down-the-security-rabbithole-podcast/
X/Twitter: https://twitter.com/dtsr_podcast