Every time you read "the company patched a critical vulnerability," it sounds like an admission of failure. The opposite is true. It's proof that somebody is actually watching the door. Below I explain exactly who guards it, what the hole is called before it gets plugged, and why a patch story is the good news, not the bad one.
The opposite of failure is true here. A patch means somebody was actually watching the door. Below I explain exactly who guards it, what the hole is called before it gets plugged, and why a patch story is the good news, not the bad one.
The hole has a name before it gets plugged
Picture a building with a new front door: the locksmith mounts the lock, but assembles it crooked. From outside it looks locked, but with the right push the door opens without a key. Nobody did it on purpose, it just happened that way during installation. In software it's the same: the program is written fast, by many people, and somewhere a gap remains, one an uninvited guest can slip through. That gap is called a vulnerability. It isn't a virus, and it isn't an attack by itself, just an oversight waiting for someone to find it.
Once someone finds it, the world needs a shared language for it. So every such hole gets a number, as if it were issued a national ID. The system is called CVE, short for an English phrase that roughly means "known breaches in systems". It's international, and mostly kept in the United States. Thanks to it, when your antivirus company says "we closed the issue" and another system's vendor says "so did we", everyone is sure they're talking about the same hole, not something described in different words.
There's a worse version too: a hole already in use before a patch for it even exists. In the trade it's called a zero-day, because defenders don't have a single day left to prepare. It's like the caretaker finding the warehouse door open and empty, and only then realizing the lock had been broken for a while. There was never a moment when he could have fixed it beforehand.
Who sounds the alarm
In the United States there's an agency that doesn't write software and doesn't sell anything. It tracks which holes in the real world are already being used to break in, not which theoretically could be. It's called CISA, short for the American Cybersecurity and Infrastructure Security Agency. Its job is like a caretaker who walks the buildings across the whole neighborhood: doesn't build the building or install the locks, but checks which ones have already been broken into, so the owners know where to put a bolt first.
The list it keeps is called KEV, which comes from "known exploited vulnerabilities". The difference from an ordinary registry of holes matters. An ordinary registry says "here's a gap, theoretically dangerous". KEV says "people are going through this gap right now and stealing". The second is a priority. The first is for later.
Why most breaches aren't the work of geniuses
When you hear about a hacked site or a leaked database, the image is a hoodie-wearing hacker cracking impossible code in a dark room. In most real cases the truth is duller and more unpleasant. Someone knew about the hole for months. A patch shipped. Nobody installed it. Like knowing the warehouse padlock has been broken for a month, having a new padlock in the drawer, and just never finding the half hour to swap it. The thief wasn't a genius. He just walked past the open door while looking for the next one.
Why the patch is the good news
Security isn't a state you reach once and finish. It's more like maintaining a building: the roof gets checked every year, because we know it will leak sooner or later, not because it's already caved in. Nobody thinks it's a scandal that the caretaker changes a padlock. The alarming thing is the opposite: a building where nobody touches anything for twenty years, because either nobody's watching, or something's being hidden.
So when you read that some company patched a vulnerability, it means someone there is working, watching the lists, reading what the agency across the way publishes, and doing the maintenance. Silence is the worse signal, not the patch.
What's new
I no longer ask "did the company get hacked". I ask "how long did they know, and how slowly did they react". The difference between the two questions is the difference between bad luck and bad maintenance. I forgive the first. Not the second.