Subscribe

The trick: Moved Ruler

The vendor reporting that 99.9% of AI vulnerabilities go unpatched rated the same class of packages 'low to medium risk' in its own 2024 report.

Orca's telemetry is real and the hygiene warning is fair. But the 99.9% counts alerts at scan time, the report offers no non-AI baseline, and the baseline that exists elsewhere says nobody patches most of anything.

Issue 814 August 20264 receipts4 min

99.9% of AI vulnerability alerts with an available fix remain unpatched, and 81% of organizations running AI packages have a known vulnerability with an average CVSS of 8.79

Before you read on. Your call?

the numbers are real Q2 2026 telemetry from 1,200+ Orca customers, but the 99.9% counts alerts, not vulnerabilities or systems, at a point in time, with no time window and no non-AI comparison anywhere in the report. Cyentia and Kenna's long-running remediation research found the typical org fixes about 10% of its open vulns in any given month, for everything, not just AI. And Orca's own 2024 report described the same package class as mostly low to medium risk. Real hygiene problem, engineered headline.

99.9%AI VULN ALERTS WITH AN AVAILABLE FIX STILL OPEN AT SCAN TIME
10%SHARE OF ALL ITS OPEN VULNS THE TYPICAL ORG FIXES IN A MONTH
250xORCA'S OWN PUBLIC-EXPLOIT RATE JUMP

There’s more to this story.

Membership opens the full investigation, the strongest counterargument and what to do with what you’ve learned.

Start your free month →

First membership: 30 days free, then A$89 a year. One introductory trial per customer. Card required; renews annually until cancelled. Cancel before the trial ends to avoid the first charge. Already a member? Sign in

The trick has a name

We call it Moved Ruler: two methods, two answers, one of them quoted. You'll see it again. Learn to spot it →

Say this in tomorrow's meeting“'99.9% compared to what?' The report never shows the non-AI patch rate from the same scanner. The industry baseline says orgs fix about 10% of everything per month. Show me the AI column next to the non-AI column, then we can talk about recklessness.”

Receipts

  1. Supports orca.security: 99.9% of fixable AI vulnerabilities remain unpatched.
  2. Refutes cyentia.com: The typical organization only fixes about 10% of its vulnerabilities in any given month.
  3. Context helpnetsecurity.com: 81.2% of companies running AI packages have at least one known vulnerability
  4. Context orca.security: most of these vulnerabilities are low to medium risk with an average CVSS score of 6.9, and only 0.2% of the vulnerabilities have a public exploit (compared to the 2.5% average)

Open the Receipts Pack → What each source proves, every figure traced, and what would change our verdict.

This story is a stable, citable object. If you can falsify a verdict,tell us. Corrections are loud here.