The Big Short Circuit
You’re a CISO at a regulated utility — positioned and growing to service power-hungry new AI datacenters, 1,200 employees, a small security team you built from scratch, a compliance framework you maintain because the regulator requires it. On July 22, J.P. Morgan publishes a 26-page systemic risk assessment telling wealth management clients that 48,185 vulnerabilities were disclosed in 2025 with about 7,500 patched; that average time from disclosure to first exploitation has fallen to a single day. This report was not written for you. But its exhibits describe your week: critical and high-severity disclosures from the major vendors — the only tier you could ever afford to chase — went vertical this year. The utility has one IT contractor. He’s on vacation.
Patchmageddon. Inside the critical infrastructure sectors, the practitioners are reaching for 2008 — a systemic risk demanding coordinated response, institutions comparing notes the way the banks did in the subprime crisis. They mean the coordination. They may be onto something bigger.
The Summer of Pretty Disquiet
The report was authored by Michael Cembalest, JPM’s Chairman of Market and Investment Strategy, with contributions from Global CISO Pat Opet and the firm’s senior cybersecurity leadership. It tracks the collision from both sides — vulnerability volume surging across every dimension they measure, remediation capacity flat. The starkest exhibit: attacker time-to-exploit has crossed below organization time-to-remediate. The lines inverted in 2025. Exploits now arrive before patches exist.
The report recommends ten action steps for business owners. Read them as a capability inventory:
Maintain a comprehensive, continuously updated inventory of all hardware, software, and cloud assets. Know your major SaaS and outsourced dependencies. Most organizations have never held a complete inventory once, let alone continuously.
Build and operate a robust vulnerability management program. Run the latest software versions — and move off dependencies where you can’t identify the steward. Optimize change management for speed. At JPM, that’s infrastructure. At a 300-person manufacturer, it’s a paragraph in a document no one has read.
Aggressively filter outbound traffic from production systems. Manage remote access and segment where possible. Flat networks, no segmentation, no one on staff who could implement either recommendation.
Stress test incident response and resiliency plans. Assumes an incident response plan.
Remove standing privileges from employee entitlements. Assumes you can enumerate them.
Embed security into the AI development and deployment lifecycle. The utility company buys its AI.
Each prescription is operationally sound. Asset inventory, change management, vulnerability management, and the others — baseline hygiene for a mature cybersecurity operation, aspirational for most of the economy. Expert prescriptions, written from inside the capability they assume. The systemic risk exists because most of the economy doesn’t have the floor.
The ratings model wasn’t built for this. SOC 2, ISO 27001, penetration tests — measure control implementation at a point in time. They were never designed to measure whether an organization can absorb 10,000 new findings per month and remediate before weaponization. And they can’t see the findings: 95% of Mythos disclosures had no public advisory — invisible to the CVE feeds, vulnerability databases, and scanners the entire attestation apparatus runs on.
Opet warns that we can’t simply rely on every organization to just ‘do better’. His answer is a government-hosted domestic cyber defense strike force. Great instinct. Now what do we do while we wait for them to select their logo?
Securitization & Shared Dependencies
The risk is correlated because the supply chain is shared.
The earlier posts in this series laid out the mechanics: 99% of commercial codebases contain open-source components, the transitive dependency graph is maintained by volunteers — the majority maintained by a single individual — and when a fix ships, the dead middle of the graph stops it from reaching production. Of the high- and critical-severity findings Glasswing reported to maintainers, 530 went in and 75 came back patched. Tuskira measured discovery outpacing maintainer remediation 16.5 to 1, with 90% acknowledgment. The maintainers see the findings. They cannot service them.
What the Patchmageddon data adds is the market-structure implication. What looks like independent organizational risk is the same exposure repeated thousands of times — and increasingly the utility company doesn’t run its own code at all. It runs a hosted platform, which concentrates rather than distributes the correlated default risk. Fewer, larger counterparties holding the same exposure. The shared dependency chains are the bundled mortgages, the compliance certifications are the AAA ratings, the prescriptions calibrated to G-SIBs are the prime model applied to subprime — the structural parallel the practitioners reached for runs all the way down. The amplification that 2008 got from balance-sheet leverage, this system gets from concentration — platforms aggregating the correlated dependency into fewer, larger points of failure. They’re holding the bundled exposure.
The attackers have read the underwriting. They converged on exactly this population — oft-regulated, operationally fragile, homogeneous-stack organizations with bootstrapped security functions and institutionalized capability gaps. One exploit chain, near-zero marginal cost, thousands of structurally identical targets. Wavestone puts the average maturity of large companies at 55.3 out of 100 — large companies — and the global cybersecurity workforce is short 4.8 million people. The attackers operate as a decentralized open-source R&D lab. The defenders sit behind vendor contracts and proprietary threat intelligence.
Tranche Warfare
The adjustable rates are resetting. Disclosure is weaponization — AI can reverse-engineer a patch into a working exploit in minutes. Median time to exploitation fell from a year in 2021 to a day in 2026, projected to one minute by 2027. Open-weight models are three months behind the frontier and safety-strippable in under an hour. The organizations barely servicing their vulnerability debt at the old disclosure rate are defaulting at the new one.
If the prescriptions can’t reach the long tail, the only prescriptions that work are ones that eliminate the need for the capabilities assumed — security as a property of the platform, not a discipline of the organization, where the utility company never touches the dependency chain and the remediation obligation sits with an entity capable of executing it. Send in the strike force.
The circuit is overloaded. The wiring is shared. The breaker that’s supposed to trip is a compliance checkbox calibrated to a question it was never asked. The people who built the best breaker in the industry just told you it can’t rely on everyone doing better. Cembalest read the aggregate — the macro trend, the crossing, the systemic risk. The attacker is running the short.
Views are my own. This is a postscript to the Off the Beaten Patch series on vulnerability management, and the opening volley of Malice in Wonderland — truth, tokens, and consequences in the age of AI.

