
Healthcare’s 30-day patch policy may already be obsolete
By Errol Weiss, Chief Security Officer, Health-ISAC Five days: That was the median time in 2025 between the publication of a high- or critical-severity vulnerability and its addition to CISA’s Known Exploited Vulnerabilities (KEV) Catalog of flaws known to be exploited in the wild, according to Rapid7’s 2026 Global Threat Landscape Report. Now put that […]
The post Healthcare’s 30-day patch policy may already be obsolete appeared first on Health-ISAC - Health Information Sharing and Analysis Center.