Strip away the model and an AI agent is a process with an identity, a privilege level, and a set of things it can touch. Security teams already have a model for that.
CVE reachability claims are mostly inference. A former CISO grades three vulnerability tool categories, including his own, against one strict standard.
AI risk scoring for agentic AI: we evaluate AIVSS, MITRE ATLAS, and the OWASP Agentic Top 10, where each works, where it fails, and what to use now.
WinRAR is widely deployed and rarely updated, and its runtime behavior flagged it high-risk before its CVEs existed.
Punto Switcher's signed binary looks clean to file scanners. The flaw is an unquoted RunDll32.exe call it makes at launch that lets a local attacker run arbitrary code, caught by Spektion Research at runtime.
The mean time from CVE disclosure to exploitation hit negative seven days in 2025. CVEs are no longer leading indicators of risk, and runtime behavior is the signal that replaces them.
Mythos found thousands of critical vulnerabilities. Fewer than 1% have CVEs. If your entire security stack needs a CVE to see risk, you're structurally blind to what's already running on your endpoints.
Spektion Research discovered and disclosed a privilege escalation vulnerability in MobaXterm — caught at runtime, where static tools don't look.
AI tools like Claude are reshaping the attack surface in ways traditional vulnerability management can't track. Here's what security teams need to know.
Spektion wins two Global InfoSec Awards at RSAC 2026: Most Innovative Exposure Assessment Platform and Most Innovative Runtime Exposure Management
Continuous runtime exposure management has arrived. Joe Silva shares what Spektion built, why it matters, and why the window to act keeps shrinking.
AI agents are moving fast and security is scrambling to catch up. This post breaks down why static policies aren't enough, and gives security leaders a checklist to get ahead of the exposure.
Five supply chain campaigns. One has a CVE. The other four? Completely invisible to your vuln management program. And they're still your problem.
What failed in the update process, why CVEs didn’t tell the full story, and how runtime visibility helps security teams spot real exploit risk.
A deep dive into how runtime evidence transforms vulnerability prioritization.
PDF editors with zero CVEs can be just as dangerous as those with dozens. Our research shows why organizations need runtime behavioral monitoring, not just CVE tracking.
Learn what “runtime” means for vulnerability management and how runtime telemetry shows which vulnerabilities are truly exploitable, not just theoretically present.
Why traditional vulnerability management creates the illusion of security while leaving teams drowning in noise, and why runtime context is the way out.
Get the summary of the Security Theater Podcast featuring two CISOs, Joe Silva & Kyle Bubp, discussing the limitations of current VM practices and the reasons to shift to real-time, behavioral context for true risk reduction.