SentinelOne®, the AI security leader, and Tenable® Holdings, Inc., the exposure management company, recently released joint research that suggests a growing disconnect between vulnerability discovery, disclosure and actual exploitation.
The research draws on Tenable’s exposure data across thousands of organisations and remediation telemetry with SentinelOne’s endpoint and post-exploitation detection data. Together, both views produce a prioritised picture of where risk is concentrating, with lessons ripe for the Frontier AI era. The most critical takeaway: Both nation state and criminal threat actors are focusing on vendors and susceptible points in the attack surface more than specific CVEs.
Current attacker timelines are already moving faster than standard patch cycles can address. New frontier AI models compress vulnerability discovery from months to hours, significantly expanding potential risks while speeding the time for attackers to move from disclosure to exploit code in about a week. Today, the median organisation takes five months to remediate known vulnerabilities.1 Closing that window takes more than speed, it takes knowing which product lines are more likely to carry the next wave of exploitation.
The research finds that exposure data and runtime detection converge on the same edge-device vendor surfaces 79% of the time, while they share only 21% overlap at the individual vulnerability level. Both state-sponsored actors and ransomware operators draw from the same small set of high-severity, actively exploited vulnerabilities. The surfaces are consistent and the actors are not. That distinction matters for how defenders prioritise; a pattern Tenable has termed the “Persistently Targeted Vendor.” This is the idea that a small set of vendor product lines, not individual CVEs, is the durable unit of risk over time.
Other key findings from the research include:
- Twelve vulnerabilities in the dataset carry confirmed “multi-nexus” attribution — state-sponsored and ransomware operators independently exploiting the very same flaw across five distinct threat categories, including China, Russia, DPRK, Iran-nexus, and criminal (financially motivated) actors.
- More than half (54%) of organisations running F5 products carry at least one exposed, actively exploited vulnerability, while Citrix customers post the slowest remediation of any vendor studied, at a median of 461 days — a concrete illustration of how specific product lines stay exposed long after a patch exists.
- Remediation complexity on high-priority vulnerabilities introduces a statistically significant 24-day gap, widening the window attackers have to operationalise an exploit — underscoring why patching speed alone isn’t enough without attack surface minimisation and endpoint protection working in tandem.
“Speed alone is not enough. By the time a vulnerability hits a remediation queue, adversaries are already iterating the exploit”, said Steve Stone, Chief Customer Officer at SentinelOne. “Static signatures run on human timelines, the threat does not. Runtime behavioural detection has to match that cadence, flagging exploitation patterns as they emerge rather than after the fact”.
For security teams, the research reinforces the need to look beyond individual vulnerabilities and understand which technology surfaces attackers repeatedly target. Tenable’s exposure data shows where organisations are most exposed and where risk is concentrated, while SentinelOne’s runtime threat and DFIR data shows where and how attackers are operating in the wild. The convergence of these two independent perspectives gives defenders stronger evidence for prioritising remediation, strengthening detection and reducing risk across persistently targeted technology surfaces.
“Attackers systematically target specific vendor ecosystems that could provide access. They aren’t obsessing over single vulnerabilities, and neither should defenders”, said Vlad Korsunsky, Chief Technology Officer, Tenable. “Our joint research confirms that attackers, big and small, target the same attack surfaces the majority of the time. This research underscores exposure management principles: seeing, prioritising and fixing exposures that create real business risk. As attackers weaponise AI to breach defences faster, organisations that embrace exposure management will win”.
The research is the latest collaboration in an expanding partnership between best-in-class AI-native CTEM and AI runtime detection and response companies, building on Tenable and SentinelOne’s existing work together, including SentinelOne’s participation as a founding member of Tenable’s CyberAgents Exchange announced at Black Hat USA 2026. It’s the latest step in a partnership that continues to deepen as both companies invest further in AI security. The full research is available at sentinelone.com and tenable.com.
1Tenable’s Key Takeaways from the Verizon DBIR (2026), May 19, 2026
Image Credit: Tenable
Source: Tahawul Tech
