Threat Intelligence

Attackers Exploit New Flaws in Days, Businesses Take Weeks to Patch: Why Pentesting Needs to Change

The Hacker News · 17 Sept 2026
Key Takeaway Small businesses should move away from one-off annual security checks and adopt more frequent, ideally continuous, testing and faster patching processes to keep pace with attackers who now exploit new flaws within days.

New research highlighted in a guide from The Hacker News shows a widening gap between how fast attackers move and how slowly businesses respond. Google Mandiant data suggests attackers now weaponise new vulnerabilities in around five days, while Verizon's 2026 Data Breach Investigations Report found the median organisation takes 43 days to patch a known flaw, up from 32 days the previous year. The same report found that vulnerability exploitation has now overtaken stolen credentials as the leading cause of breaches, and that the share of critical, actively exploited vulnerabilities actually getting patched has fallen from 38% to 26%.

The guide argues that traditional annual pentesting, which produces a static report covering only part of a business's systems, simply cannot keep pace with attackers who move in days rather than months. It points to Cobalt's 2026 State of Pentesting research, which found the median time to fix a high-risk finding is 39 days, with a huge 25 times gap between the best and worst performing organisations. The rise of AI is making things worse on both sides: attackers use it to find and exploit flaws faster, while businesses use AI to write code faster than it can be properly tested, with AI-powered applications shown to carry high-risk security findings at nearly three times the rate of traditional software.

As an example, the article describes a common weakness called an IDOR (insecure direct object reference), where an attacker logged into a normal account can manipulate a request to access or change other users' data, potentially leading to full account takeover, without needing any special coding skill or known vulnerability.

Key Takeaway: Small businesses should move away from one-off annual security checks and adopt more frequent, ideally continuous, testing and faster patching processes to keep pace with attackers who now exploit new flaws within days.

Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.