Most security teams know they have more weaknesses than they can fix. The vulnerability list never ends. Scanners flag thousands of issues.

The real question is no longer which flaws exist. It is which ones an attacker can actually use, and which ones can wait. Severity scores do not answer that. An attacker does not care how a flaw is rated. They care whether it works.

Speed is why this matters. Take CVE-2026-39987, a critical pre-authentication flaw in the Marimo notebook tool. It was exploited against honeypots within hours of disclosure, and in one real intrusion, an attacker turned that single flaw into the theft of an entire internal database in about an hour.

The window between disclosure and exploitation can now be hours, not quarters. That is why an annual penetration test is no longer enough on its own. A point-in-time report is stale the week after it ships, and the attack surface keeps changing as the company adds cloud accounts, software, and identities.

Why the old way fails

Legacy vulnerability management collapses risk into a long list and a static severity score.

In practice, most vulnerabilities are never exploited, while a small number of exposures create most of the real risk. Without validation, teams burn time on low-impact issues and miss the ones attackers are actually using.

The shift is toward continuous testing: probing your own defenses the way an attacker would, and proving which exposures are real before someone else does.

From counting flaws to proving exploitability

The broader approach has a name: continuous threat exposure management, or CTEM. It runs as a loop: scope the environment, discover assets and exposures, prioritize by real risk, validate which exposures can actually be exploited, and get the fix done.

The core move is validation, proving a weakness can be used in your environment rather than trusting the number next to it. That is the clearest pattern in this year's winners, and they share a premise: a list of weaknesses means little until something proves which ones an attacker can use.

What this year's winners are building

What they build is not another scanner. It is proof that a flaw can actually be used. Pentera tests whether the weaknesses in an environment can be exploited, which the awards call adversarial exposure validation.

SafeBreach and Picus Security run real adversary techniques safely against defenses to show where they fail, a process known as breach and attack simulation. MazeBolt applies the same idea to availability, continuously testing the gaps that let denial-of-service attacks land, the kind of exposure a vulnerability scanner misses entirely.

Others run the offense itself, automated and continuous. Theori does automated penetration testing that probes code and web apps without waiting for a scheduled engagement; Novee Cyber Security runs AI-driven penetration testing continuously.

Cobalt pairs human testers with automation, and Viettel Cyber Security took the red team award for the human work automation still cannot match: chaining weaknesses, adapting mid-test, and finding paths a tool would miss.

On the discovery and prioritization side, Bitdefender took an Attack Surface Management award for reducing exposed assets before they can be attacked. PlexTrac took a risk-based vulnerability management award for tying validation findings to prioritization, so teams fix what matters first.

What to do now

  1. Map the attack surface beyond software flaws. Include identities, cloud configurations, exposed services, and third-party connections. Many real exposures are misconfigurations and excess permissions, not CVEs.
  2. Prioritize by what is actually exploited, not by CVSS severity. Cross-reference findings against CISA's Known Exploited Vulnerabilities catalog and current threat intelligence, and treat a known-exploited flaw as urgent, whatever its score.
  3. Validate to cut the list. Use automated validation or breach and attack simulation to test which exposures are actually reachable and exploitable in your environment. That shrinks the set that needs immediate attention.
  4. Focus on choke points and blast radius. Find the few systems or identities that, if compromised, open broad lateral movement. Protecting those beats is fixing hundreds of low-severity issues.
  5. Make validation continuous. Build it into CI/CD and change management, and re-run it after a patch to confirm the fix held. A clean result last month tells you nothing about this week.

For defenders, the takeaway is a change in measurement: not how many flaws you found, but how many an attacker could actually use. The winners here build tools for that. The principle holds without any of them. The number that matters is not the size of the backlog. It is how many attack paths someone has proven are still open.


Part of The Stars Briefing, our editorial series on the trends behind the 2026 Cybersecurity Stars Awards, a program The Hacker News runs. This piece analyzes where the field is moving and uses the winners as examples. It is not a product review. The complete list of 2026 winners is live at awards.thehackernews.com/winners/2026.