HM HD Moore On Risky Business

“The dirty secret is CVE hasn't mattered in a long time. Most of the bugs people are exploiting don't have CVEs when they're being exploited. … Most of the vulns going forward will be exploited exactly once in your infrastructure and that's it. No one's going to go burn their good bug by sending it across the world.”

Risky Business · Software Engineering & Infra · September 2026

“The dirty secret is CVE hasn't mattered in a long time. Most of the bugs people are exploiting don't have CVEs when they're being exploited. … Most of the vulns going forward will be exploited exactly once in your infrastructure and that's it. No one's going to go burn their good bug by sending it across the world.” — HD Moore, Risky Business

Moore, whose company makes a network discovery and vulnerability scanner, is describing the flood of AI-found bugs. He says many will never get a CVE or a patch, which is why he thinks CVE-driven patching no longer reflects how attacks happen. The episode is a sponsored interview.

Transcript

Risky Business Around 06:42 into the episode
HD Moore

Yeah. And we can be pretty lazy about it. We can pull a lot of data from existing third-party data sets. So for example, Shoden has about nine of the 10 fingerprints we need is already in the Shoden data set. So we just pull them out to start with. Another fun thing about Shoden's data set is that there's holes in it and the holes are really conspicuous. Like you'll try to figure out, well, why doesn't Starlink exist in the Shoden data set is a really good example. And then what does Starlink have exposed that is not any public data set because it's been excluded from all the public ones. So an example of like interesting, I'll get to the punchline. 4,000 Fortinets is what's there. But very interesting that like, yeah, so the Starlink IP space is almost all Fortinet gateways and it's not in Shoden at all, which is kind of a weird conflict. Of things, but the stuff like that you run into when you start doing an inspection and stuff and say, okay, here's what we expect to see. Here's what's actually in these different third parties. Let's go scan the difference and figure out where they went.

Patrick Gray

You know, look, I just want to switch gears here for a second and talk about vulnerability scanning because, you know, you did a big sort of pivot into, well, not a pivot into vulnerability scanning, but you added a lot of features to Run Zero that made it quite a useful vulnerability scanner. You did this great talk at a Decibel event. I was there in San Francisco next to RSA. where you pointed out like the incumbent Vawn scanners basically haven't changed the way they do anything for 20 years. And they don't really give you much useful information. They just dump a bunch of CVEs on you. And that's why, you know, one of the reasons vulnerability management is such a mess. So the idea with Run Zero is you could scan, you could find stuff that attackers can actually reach. You can get a better sense of the impact. But it feels like now even that is just like untenable. Vulnerability management has just got completely untenable because of this AI-driven Volnpocalypse, right? And you and I have talked about this. Like it's got to the point now where people are just getting known by stuff that doesn't even have a CVE. So, you know, how is vulnerability scanning supposed to save you, right? So it's, you know, we've swung back to discoverability and control. But walk us through the, you know, walk us through the current state of exploitation out there, if you would.

HD Moore

I mean, the dirty secret is CVE hasn't mattered in a long time. Most of the bugs people are exploiting don't have CVEs when they're being exploited. So the, you know, Vawnpocalypse wheel is accelerating that. So you may see, what is it, like 65,000, 70 CVEs so far this year. That's not including the 200,000 that wings right now. They don't even get a CVE yet. If you look at the stuff that Anthropic presented, for example, they said they found about 20,000 to one point. But long story short, about 83 have got a fix patched, but 130 something have not been fixed yet, but have been disclosed and accepted by the vendor. And there's a giant pile of ones that the vendors have not accepted in the first place. So I can tell you, we did a disclosure process for OpenBMC, which is kind of the underpinnings of all modern BMC implementations these days. You know, Dell, IDRAC10, Supermicro, newest boards, you know, Huawei, Huawei 3COM, or sorry, Huawei is using OpenUBMC, but Huawei 3Com is using or HTTP is using OpenBMC. Long story short, we found an auth bypass directly to Priv Escalation. So you go from zero to root on every device that's running this BMC stack that is now the most popular stack in the world for managing every server out there, including the hyperscalers. And we, you know, we announced it or we told the vendors about it 60-something days ago. They did not patch it. We disclosed it a couple of days ago. No one even noticed. We've been reporting vulnerabilities in Run Zero for this thing for almost since 60 days ago. Like we've been telling customers about it, hey, this is something you need to turn off really quickly. There's an exploit coming out for it, ASAP. No one cares. And more surprisingly, the vendors who are downstream of OpenBMC, the commercial vendors that rely on OpenBMC for their own stacks, they don't care until it's a patch available. So we've got CVs for it. But again, even the case of a CVE that we've been telling customers about for almost two and a half, three months now, is not really on anyone's radar. So in a lot of ways, and this is just one of 40 bugs that we're trying to get fixed right now. These are the only two that have been published of the set of 40. So it's a nightmare out there. I've been looking at working with other folks in the kind of volume discovery space. And, you know, everyone's sitting on hundreds of thousands of bugs. Most will never get a CV. Most will never get patched. So the question is, okay, if CVs no longer matter and exploitation is only an example of what happens when something is exploited enough that someone else notices, like put it this way, most of the vaults going forward will be exploited exactly once in all in your infrastructure and that's it. Like no one's going to go burn their good bug by sending it across the world. They'll continue to. Well,

Patrick Gray

you don't need to either. You just got to find some enterprise crapware, right? And then throw tokens at it until you get a bug because it hasn't been QA'd that well. So like, you know, I was talking recently about how I think where we're going to land is, say, you're an airline, your ticket booking website, that's going to have a lot of tokens burned on it to look for bugs, to make it secure, to refactor it, to make it as good as it possibly can be. And everything else that was touching the internet from your org, you're going to try to get that off the internet. You're going to go back to like zero trust network access principles. You're going to, you know what I mean? Like it's all about like attack surface reduction at the moment. But what you're saying seem to be saying right now is that there's not much that can be done, right? Like even if you've got the run zero vault scanning and everything, like people aren't just, they're just drowning.

HD Moore

Yeah, I mean, the important part isn't that you've patched everything on the CV side because that doesn't really matter anymore. The important part is you don't have in the first place. Where is it connected? How can you get to it? What is it connected to? What's a blast release of a bug? What vendors are in place? Like you need to understand, okay, if new something comes out, where is it? What can it impact? And then if someone gets into that work and they go, and that's true, no matter what CV it is, no matter what level of patchability the issue has. So it really is back to basics. Like you go back to mid-1990s and everybody who was a hacker at the time could walk their way into any system they wanted to. So we're talking about... So this is fine.

Patrick Gray

Like I've had variations of this conversation, especially down at Unprompted where I'm seeing people I've known 25 years. Yeah, they were doing this a few years ago, right? Exactly. Right? Like that, that's the thing is, is like, I think for, and it's been really funny watching the discourse of the, you know, we're all going to die from the labs, right? And everything. Because for those of us who are old and have been around in this for a long time, we're like, we've been here before. Like, we've lived this reality previously. And like, it was messy and it was ugly, but like, we got through it. I mean, you seem to be like singing from the same songbook right now. Yeah,

Speaker names from our own diarization · position estimated from where the line sits in the episode

More from Risky Business