Security teams should treat patch latency as part of attack surface management. The practical defense is fast OS and browser updating, restricting high-risk links delivered by SMS, and limiting exposure on devices that cannot be reliably updated. Organizations also need monitoring for exploit-chain indicators, because commercial spyware often succeeds by combining a fresh zero-day with a lingering known weakness.
How commercial spyware gets around patching and why that changes the defense
Commercial spyware is not just “old-vulnerability malware.” The more effective products chain an unpatched or newly disclosed zero-day with a second weakness that is already known and often already patched somewhere in the fleet. That means defenders cannot assume the zero-day is the only problem. Exposure persists wherever patch latency, unsupported devices, or inconsistent update behavior leaves a second foothold available.
The right mental model is attack surface management, not single-bug response. If the initial exploit lands through a zero-day, the follow-on step often depends on a known weakness, a stale browser, a delayed OS update, an exposed link path, or a device class that cannot be remediated quickly enough. Reducing exposure therefore depends on shrinking the time window in which any link in the chain remains usable.
Fast remediation matters most when the chain can be broken by normal hygiene. That is where CISA's Known Exploited Vulnerabilities Catalog is useful as a prioritization lens, because it reflects vulnerabilities with confirmed active exploitation rather than theoretical severity alone. For teams that need a second prioritization signal, FIRST EPSS helps separate patch queues by likelihood of exploitation, not just by CVSS score.
Where exposure persists in practice
The biggest practical gap is usually not the zero-day itself, but the conditions that let a chain continue after the first exploit. Delayed OS and browser patching, devices with poor update reliability, and user channels that deliver risky links all make it easier for spyware to bridge from initial access to durable compromise. In mobile environments, SMS and messaging-based delivery remain important because they can reach users outside normal web filtering and application controls.
In older fleets, exposure is often structural. Unsupported operating systems, deferred browser restarts, and exception-heavy device management create long-lived pockets where a second-stage exploit remains available even after a vendor patch exists. That is why exposure management has to include inventory discipline, update enforcement, and an explicit decision about which devices are too risky to keep on the network without compensating controls.
For teams that need to understand how real-world exploit chains are assembled, The 52 NHI Breaches Report is a useful reminder that attackers often win by chaining small failures, not by relying on a single dramatic break. Even though the subject here is spyware rather than identity abuse, the same pattern applies: one weak control rarely matters alone, but two weak links in sequence do.
When commercial spyware targets high-value users, it often favors environments where patching is slow, link filtering is weak, or device management is inconsistent. That means the team’s real objective is to reduce the number of reachable combinations, not just to patch the latest headline vulnerability.
Practical controls that break the chain
Start with the controls that reduce exploitable time. Enforce rapid OS and browser updates, minimize deferrals, and measure patch lag by device group rather than by average compliance. Then reduce exposure to the delivery path itself: harden SMS and link handling, train users on high-risk messages, and treat untrusted links as a containment problem rather than a pure awareness issue.
Use the same logic for devices that cannot be reliably updated. Segment them, restrict their access, and remove them from high-value workflows where a compromise would be unacceptable. If a device cannot consistently receive security fixes, compensating controls must assume that a known weakness will remain available to the attacker long enough to matter.
Teams that want a policy anchor for this approach can look at NIST Cybersecurity Framework 2.0 for the broader identify, protect, detect, respond, and recover structure, and NIST Cybersecurity Framework 2.0 is especially helpful when you need to align patching, detection, and recovery around a single risk picture. For control detail, NIST SP 800-53 Rev 5 Security and Privacy Controls gives the access control, configuration management, and system integrity structure that supports that operating model.
Good defense here is less about perfect prediction and more about reducing the number of ways an exploit chain can stay alive. If the initial compromise is possible, the second weakness must be made difficult to reach, difficult to reuse, or impossible to keep open for long.
Risk and Threat Considerations
Commercial spyware is attractive because it monetizes short windows of exposure. A zero-day creates the initial foothold, but a lingering patched vulnerability, stale browser, or delayed OS update can provide the persistence path that turns a one-time exploit into durable access. The risk is highest where patching is inconsistent across device classes or where users can be reached through messaging channels that bypass normal web controls.
Failure mechanism: The attacker chains a fresh exploit to an older weakness that remains reachable because updates are delayed, blocked, or not uniformly deployed, so the compromise survives longer than the zero-day alone would allow.
Impact: Exposure expands from a single exploit event into longer-lived device compromise, broader user targeting, and higher odds that sensitive communications, location data, or app content are collected before containment.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | ID.RA-01 — Risk and Threat Intelligence | Patch-lag exploitation needs current exploit-risk prioritization. |
| PR.AA-05 — Network Segmentation | Segmentation limits reach on devices that remain unpatchable. | |
| PR.DS-10 — Integrity Checks | Integrity controls help detect exploit-chain tampering and persistence. | |
| Recommendation — Prioritize devices with confirmed exploitation exposure first. Segment high-risk devices away from sensitive workloads. Verify device integrity after suspected spyware exposure. | ||
| NIST SP 800-53 Rev 5 | SI-2 — Flaw Remediation | Fast patching is central to reducing exploit-chain exposure. |
| CM-8 — System Component Inventory | You need accurate inventory to find devices left exposed by patch latency. | |
| AC-20 — Use of External Systems | High-risk links and unmanaged endpoints expand spyware delivery exposure. | |
| Recommendation — Enforce accelerated remediation for exploitable flaws. Maintain device inventory for patch and exposure tracking. Restrict risky external link handling on managed devices. | ||
Practitioner Guidance
What to prioritise: Put the shortest patch-lag populations first, especially high-risk mobile devices, executive endpoints, and any fleet segment that receives external links by SMS or messaging apps. If a device class cannot reliably update, treat that as an access and exposure decision, not a maintenance inconvenience.
What to verify: Confirm that update enforcement is actually closing the exploitable window, not just reporting nominal compliance. The most useful evidence is device-level lag, restart completion, and whether high-risk browser and OS versions are still reachable in production.
Practitioner takeaway: The objective is not to eliminate every zero-day, it is to make the attacker's second step disappear fast enough that the chain cannot turn brief access into sustained compromise.
Related resources from NHI Mgmt Group
- How should security teams reduce exposure to email-borne exploit chains that try to harvest credentials through patched vulnerabilities?
- How should security teams use continuous validation to reduce exposure when critical vulnerabilities are being exploited faster than they can be patched?
- How should security teams reduce exposure when an Oracle E-Business Suite internet-facing application is vulnerable to a zero-day exploit?
- How should security teams reduce exposure to shadow vulnerabilities in AI libraries and models?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org