For most of the last decade, defenders could count on a grace period. A vulnerability would be disclosed, a patch would ship, and somewhere between two and six weeks later the first opportunistic scans would begin. That grace period paid for a lot of process: change windows, staged rollouts, monthly patch cycles. It is now gone.

The pattern across recent campaigns is consistent: the window between public disclosure and active exploitation has collapsed from weeks to days — and for internet-facing software with public proof-of-concept code, sometimes to hours. Attackers have industrialized the pipeline from advisory to exploit: automated diffing of patches, shared tooling, and scanning infrastructure that is already warm before the CVE number trends.

That shift quietly changes the economics of several security habits. A monthly patch cycle for edge devices is no longer a conservative choice; it is an accepted exposure of days-to-weeks against adversaries who need less time than that. Asset inventories that lag reality by a quarter mean the race starts before you know you're in it. And response playbooks that begin with "confirm the vulnerable version" lose the only hours that mattered.

What the fastest defenders do differently

The teams that handle this well have made three moves. First, they treat internet-facing exposure as a separate class of risk with its own clock: emergency patch paths measured in hours, pre-approved by change management before the emergency exists. Second, they invest in exposure management over vulnerability counting — knowing which few systems are reachable, valuable, and unpatched beats a spreadsheet of ten thousand CVEs. Third, they assume compromise during the window: tamper-resistant logging and forensic readiness so that "were we hit before we patched?" is an answerable question, not a permanent mystery.

The uncomfortable summary: patching speed is now a detection capability. If you cannot patch an edge device within days, you need to be able to prove what happened while you waited.

None of this requires new products so much as new defaults. The exploitation window will keep shrinking; the defenders who thrive will be the ones who stopped budgeting time they no longer have.