The images in this article were generated with artificial intelligence. How we publish
The assumption is no longer optional: zero failures continue to appear, automation and IA accelerate the creation of exploits and the old mandate of "patching all in time" ceased to be a realistic defense. If you can't stop vulnerabilities from coming up, what you can control is how far one can go when it does.. That is a decision of architecture: how does your network have, what paths it offers to an attacker and where your apparent barriers are broken.
In theory, critical areas are isolated after a firewall or a separate VLAN; in practice, the most common way in which a scale attack article is not by a magic vulnerability in the most valuable asset, but by invisible routes: multi-interface devices that create segments, gateways of industrial protocols that make OT accessible from IT, and unregistered equipment that respond in networks where they should not be. The difference between your static inventory and real topology is the space that an attacker exploits..

HD Moore, creator of Metasploit and now CEO of RunZero, has been showing that offensive perspective for years because understanding the map of the attacker is the most reliable way to close the path. It is not just about counting assets, but about map engagement roads - attack paths - that connect an initial access point to an impact target. Tools and frameworks such as Metasploit have taught the advocates to search and exploit these paths; today there are also solutions that seek the same information for defenders. See how an attacker "see" your network changes what you have to fix first. Beyond the tool, practice is key: discover unknown assets and validate that segmentation really cuts attack routes.
The operational implications are clear and urgent. If IT, IoT and OT share poorly applied infrastructure or control policies, any gap can quietly cross the limits you thought were waterproof. Convergence between corporate networks and industrial environments increases risk and makes the mentality of "putting a firewall to the problem" obsolete. The answer is not to add more patches: it is to reduce the damage radius and control the motion surface.
In day-to-day that requires changes in focus and process. First, convert static inventory into continuous visibility, combining passive and active discovery and audits of multiowned devices and "unauthorized IT" (shadow IT) and "ghost IoT." Second, validate segmentation with attack route models and actual team or purple team exercises that show if a point A can really reach point B, and if so, why. Prioritizes remediations that shorten or break routes to critical assets, not those that sound most urgent on a static list.
The technologies and controls worth considering include microsegmentation and identity access policies rather than subnetwork, network access control (NAC), egress filters to limit outgoing communications, strong and multifactor authentication, and network telemetry monitoring that detects involuntary bridges between areas. In OT environments, it adds specific scanning and visibility of industrial protocols to not only depend on IT-designed scanners. Documenting ownership and responsibility between IT / OT equipment is as important as technology.
Do not underestimate the advantage of modeling: graphic representations of attack roads and exposure scores allow for practical decisions on what to fix first. A small correction in the right place can eliminate an entire path to critical assets, which is more efficient than trying to park everything in record time. Modern tools attempt to automate this analysis; they should be evaluated within a human process of validation and governance.

This way of thinking also changes governance and culture. It requires teams traditionally separated to work together on a continuous basis, that the OT accept asset management practices and that IT no longer assume that "if it is not in my CMDB, it does not exist." The early detection of uninvented devices and the normalization of processes to isolate them immediately reduce the usable surface by an attacker.
For those who want to deepen, it is useful to compare tactics with public frameworks such as MITRE ATT & CK and to review specific guides for industrial environments published by agencies such as CISA. MITRE ATT & CK provides context on side techniques and movements; CISA it publishes guidance focused on the security of industrial infrastructure. To understand discipline from offensive practice to defensive detection, it is appropriate to review initiatives and tools for the discovery of assets and network mapping such as those developed by runZero and the learning of historical projects such as Metasploit: RunZero and Metasploit can serve as a technical and educational reference, not a single recipe.
The conclusion is simple but disruptive: stop betting on an impossible race against the emergence of vulnerabilities and start investing in to remember that your network is a road map, not a list of things. If you adapt governance, visibility and remediation priorities to that reality, you will drastically reduce the likelihood of timely exploitation climbing to a disaster.
Related
More news on the same subject.

GitLab critical alert: emergency patch fixes CVE-2026-19478 allowing to modify or eliminate public projects without credentials
GitLab published an emergency patch on August 17, 2026 to correct critical vulnerability in its self-hosted software (Community and Enterprise Edition) which, under certain cond...

When the MCP server keeps your credentials: the silent attack vector of the IA in production
The incorporation of IA agents into business processes has opened a practical way for production systems and data to be accessible from models: it is called Model Context Protoc...

Critical alert: CVE-2026-58231 in SAP Commerce Cloud could allow remote code execution; patch and urgent mitigation
A critical vulnerability that affects SAP Commerce Cloud, registered as CVE-2026-58231 and with maximum score 10.0 on the CVSS scale, it is being exploited attempts shortly afte...

The massive purchase of expired domains drives fraud, malware and streaming pirate: the business behind the dropcatch
An intelligence report on DNS published by Infoblox and disseminated by specialized media confirms that criminals are buying large-scale expired domains - the so-called dropcatc...

HoneyMyte updates CoolClient with a signed kernel driver to hide processes and protect the C2 channel
Kaspersky has published an analysis that attributes to the actor known as HoneyMyte (also Mustang Panda) an updated version of the CoolClient backdoor that incorporates a signed...

GeoServer on zero-day vulnerability alert in jsonArrayContains with real risk of remote execution
The GeoServer open source project has a zero-day vulnerability that is being actively explored by attackers, according to researchers' public alerts and the watchTowr intelligen...

AmnesiaStealer MacOS malware that steals credentials and controls real-time browser sessions
Security researchers have documented a new malware family aimed at macOS - called AmnesiaStealer - that combines a dropper in shell, an infostealer written in Rust and a remote ...