The trick: Moved Ruler
The vendor reporting that 99.9% of AI vulnerabilities go unpatched rated the same class of packages 'low to medium risk' in its own 2024 report.
Orca's telemetry is real and the hygiene warning is fair. But the 99.9% counts alerts at scan time, the report offers no non-AI baseline, and the baseline that exists elsewhere says nobody patches most of anything.
99.9% of AI vulnerability alerts with an available fix remain unpatched, and 81% of organizations running AI packages have a known vulnerability with an average CVSS of 8.79
Before you read on. Your call?
TRUE, BUT
10%
the numbers are real Q2 2026 telemetry from 1,200+ Orca customers, but the 99.9% counts alerts, not vulnerabilities or systems, at a point in time, with no time window and no non-AI comparison anywhere in the report. Cyentia and Kenna's long-running remediation research found the typical org fixes about 10% of its open vulns in any given month, for everything, not just AI. And Orca's own 2024 report described the same package class as mostly low to medium risk. Real hygiene problem, engineered headline.
There’s more to this story.
Membership opens the full investigation, the strongest counterargument and what to do with what you’ve learned.
Start your free month →First membership: 30 days free, then A$89 a year. One introductory trial per customer. Card required; renews annually until cancelled. Cancel before the trial ends to avoid the first charge. Already a member? Sign in
Couldn't check your access. That's on us.
The trick has a name
We call it Moved Ruler: two methods, two answers, one of them quoted. You'll see it again. Learn to spot it →
Receipts
- Supports orca.security:
99.9% of fixable AI vulnerabilities remain unpatched.
- Refutes cyentia.com:
The typical organization only fixes about 10% of its vulnerabilities in any given month.
- Context helpnetsecurity.com:
81.2% of companies running AI packages have at least one known vulnerability
- Context orca.security:
most of these vulnerabilities are low to medium risk with an average CVSS score of 6.9, and only 0.2% of the vulnerabilities have a public exploit (compared to the 2.5% average)
Open the Receipts Pack → What each source proves, every figure traced, and what would change our verdict.