Vulnerability Exposure Is Set by What Ships Unfixed, and No Regulation Reaching Vendors Triggers on Internal Knowledge
arXiv 2609.03266 argues that with automated discovery and repair both getting cheaper, neither cost curve determines exposure; what determines it is remediation coverage at the release decision, meaning the fraction of identified vulnerabilities fixed before shipping and the residue of known, assessed, unremediated flaws. That residue is not a random sample of what was found, because triage sorts on cost and the expensive cases are architectural, and documented awareness alters an organization's legal and market position while producing an adverse selection that software pricing does not reflect. Every regulatory instrument reaching vendors fires on exploitation observed by a third party rather than on internal knowledge, leaving disclosure at vendor discretion; CISA's Binding Operational Directive 26-04 is examined as the exception.
↳ Follow the thread