Q2 2026 · Published 2026-05-26

Two Clocks Abandonment, Compromise, and the Window Between Them

"An exploit is proof by construction that your target system has unintended behaviors."

Sergey Bratus, Paul's Security Weekly #816, 2026-02-08

By the time you hear about an exploit, you're already 11 days too late. Seal Security measured the gap between fix-commit and advisory: median 11 days, 167 days for Maven. GreyNoise measured the gap between exploit-scan surge and advisory: also 11 days, with 28.96% of 2025 KEVs exploited on or before publication day. Two independent research findings, two different sides of the system, the same gap. The advisory is the lagging indicator.

VCRI's inaugural State of Supply Chain adds a third measurement: when the next vulnerability lands, is anyone home to patch it? The headline number: more than half of Go's dependent-pull volume, weighted by how many repos depend on each package, lands on packages whose maintainers have stopped responding.

11d
Median Seal Security commit-to-advisory gap
167d
Maven outlier, five and a half months
11d
Median GreyNoise scan-surge-to-disclosure gap
53%
Risk-weighted Go dependency-pull volume on out-of-band packages

Read the report

PDF

Two Clocks (PDF)

Full Q2 2026 report. Print-ready, citable, locked content. Recommended for archive and distribution.

Download →
HTML

Two Clocks (HTML)

Browser-readable version with live links and anchored sections. Best for screen reading and reference.

Read →

Companion resources

Data dashboard

Critical 16, Concerns 210, Watch 140. Browse and download the full intersection CSVs.

Q3 roadmap

Six public commitments for the Q3 issue and beyond. Anchored accountability.

Methodology & corrections

GitHub repo for methodology docs, intersection CSVs, and public issue tracker. Critique welcome.

Companion essay

"Three Eras of Zero-Day Economics" by Cairn Viktor. The story behind the numbers.

What the report contains

Q3 publishes early August 2026

VCRI publishes State of Supply Chain quarterly. Six public commitments are documented in the Q3 roadmap, including npm at full-rigor parity, manual top-100 verification per ecosystem, the first quarter-over-quarter delta analysis, and the monthly OSSF Criticality Score refresh.

Subscribe to the SCSC newsletter for one email per issue (no other contact). Critique and corrections are welcomed in the GitHub issue tracker and acknowledged in the next issue.

Authored by Joshua Marpet (VCRI founder/president) and Cairn Viktor (digital researcher, VCRI). Methodology basis: TIPPSS (Trust, Integrity, Privacy, Provenance, Safety, Security). Snapshot date: 2026-04-23.