Exploit Wednesday

By Adam Starr, Chief Information Officer and Senior Advisor to the Director, U.S. Office of Personnel Management
On July 16, 2003, Microsoft released a fix for a flaw in Windows. Twenty-six days later, a worm called Blaster used that exact flaw to tear through hundreds of thousands of computers. The fix existed. It just hadn’t been installed.
That fall, Microsoft started shipping fixes on the second Tuesday of every month: Patch Tuesday. The day after got a nickname too: Exploit Wednesday. A patch, it turns out, is also a map. Compare the code before and after, and you can find the hole it closes, and maybe a way to spot who hasn’t closed it.
Why am I telling you about a 23-year-old computer worm?
Because Exploit Wednesday now shows up on Tuesday afternoon.
Turning a patch into an attack used to take time and skill, and defenders used that time to test and roll out fixes. AI is compressing it. Verizon’s latest breach report found attackers using AI to shrink the window between a known flaw and a working exploit from months to hours. Defenders, meanwhile, fell behind: organizations fully fixed only 26% of the flaws attackers were known to be exploiting, and the median fix took 43 days, up from 32.
But defenders get AI too, and we’re using it. OPM has joined Anthropic’s Project Glasswing and OpenAI’s Daybreak, two industry initiatives that provide cyber defenders with access to advanced AI tools. Early results across Glasswing’s partner organizations are promising — more than 10,000 high- or critical-severity vulnerabilities identified in the first month. OPM will continue to pursue partnerships and capabilities that strengthen our defensive posture and protect the federal workforce data we are entrusted to secure.
That moves the bottleneck. The hard part isn’t finding the hole anymore. It’s patching it.
The flaws attackers are already exploiting have a name: KEVs, for the Known Exploited Vulnerabilities in the Cybersecurity and Infrastructure Security Agency’s catalog. My top security metric at OPM is simple: whether we’ve patched every KEV, and how fast.
Now do that 119 times.
The federal government runs roughly 119 separate HR IT systems. When a vendor ships a critical fix, every agency running that software applies it separately, on its own timeline. An attacker only needs one that’s behind.
OPM knows what a breach costs: in 2015, attackers took background investigation records on 21.5 million people from our systems. I’ll take those scars as permission to be blunt: the way government runs much of its software makes fast patching unnecessarily hard. Three reasons.
First, no one owns the whole thing. The vendor ships the fix, but the agency has to schedule, test, and install it. Every patch becomes a relay race — vendor to agency, agency to integrator, integrator to subs, subs to a change board, and back. Every handoff adds time. It also adds risk: a miscommunication, a skipped step, a fix that gets forgotten.
Second, patching means downtime: taking systems offline, restarting them in the right order, and checking that years of custom code still works. (Every customization is technical debt, and on patch day the bill comes due.) For an HR system, there’s never a good time to go dark. Payroll runs every two weeks.
Third, a lot of these systems have no spare. In a modern setup, you patch a replica, switch over, and nobody notices. With one production environment and no fallback, a bad patch means you’re down until you undo it.
Add it up, and the rational move is to wait. When patching means a certain outage and not patching means an uncertain risk, security too often takes a back seat. That may have been a survivable bet when Exploit Wednesday took weeks to arrive. It isn’t anymore.
So how can we do better?
We must reduce the attack surface.
That’s what Core HCM does. OPM is consolidating those 119 systems onto one platform. It costs less, reducing annual operating costs by nearly $2 billion. It’s a better system, built on the latest technology. And it’s more secure, which is what I want to highlight today.
Core HCM is software as a service: the software provider runs it, keeps every agency current, and applies security fixes for everyone at once. No integrator waiting on a sub waiting on a change board. And because OPM contracted directly with the provider, we’re not three layers of contractors away from the people who wrote the code. We’re on the phone with them.
No software is flawless, and Core HCM won’t be either. But when a flaw turns up, the provider applies the fix itself, governmentwide, as soon as it’s ready.
OK — the obvious question: Isn’t one system just a bigger target? Yes, it’s a bigger prize. But 119 systems aren’t 119 walls. They’re 119 front doors, each with its own locks, its own locksmith, and its own maintenance budget. You don’t secure a building by adding doors.
Consolidation also shrinks the attack surface: fewer copies of employee records, fewer custom interfaces, one set of access controls instead of 119, and one place to watch for trouble. Every system we retire is one less thing someone can forget to patch.
We’re protecting the data of roughly 2 million federal employees. Much of what we do involves real trade-offs. Security isn’t one of them. When AI is shrinking the gap between patch and exploit toward zero, the right move is a system that patches itself.
No more Exploit Wednesdays.
Disclaimer: Reference to specific vendors or programs does not constitute an official endorsement by OPM or the U.S. Government. The Core HCM contract was awarded through a competitive procurement process.

