Smarter sites, safer businesses — no strings attached.
Short answer: Unpatched software is a program with a known, publicly fixed security flaw whose update hasn't been installed, and attackers actively scan the internet for exactly that gap. Turning on automatic updates wherever they're offered closes the door before those scans find it.
Both the ransomware and malware posts named this as a common way in, without fully explaining it. Here's what "unpatched software" actually means, and why the update notification you keep dismissing matters more than it looks like it does.
No software is written perfectly. A "vulnerability" is just a mistake in the code that creates a way in — every piece of software has them, discovered over time by the company itself, independent security researchers, or sometimes attackers first. When one's found, the company fixes it and ships that fix as an update, often called a "patch."
Here's the part that surprises people: releasing the patch doesn't just fix the problem — it also reveals exactly where the problem was. Security researchers call the period right after a patch comes out "Exploit Wednesday" (a play on "Patch Tuesday," when many companies release monthly updates) — attackers compare the old and new code, work out precisely what changed, and build a working exploit targeting anyone who hasn't installed the update yet. That window between a patch existing and an exploit targeting it has been shrinking for years, in some cases down to a matter of hours. The update isn't just a fix; it's also a public map of exactly what's broken on every system that hasn't installed it.
This is different from a "zero-day" — a vulnerability being actively exploited before any fix exists at all. Zero-days are real but comparatively rare and hard to defend against directly. The much more common, much more preventable risk for most small businesses is the opposite: a fix has existed and been public for weeks or months, and the only thing missing is installing it.
(A composite, illustrative pattern — not one specific business's story.)
A small business runs its website on an older version of a common content management system, with a plugin that hasn't been updated in over a year. A security researcher discovers and publicly discloses a vulnerability in that exact plugin version; the plugin's developer ships a fix within days. The business owner never sees the announcement — there's no reason they would — and the update sits unused.
Nobody targeted this business specifically. Automated tools constantly scan large swaths of the internet, checking for the exact software fingerprint that signals "this specific outdated version is running here." One of those scans finds the site weeks later and exploits the known, already-patched gap automatically, no human attacker involved on the other end at any point. The business wasn't singled out — it was simply still running the version the patch was written for.
A note on what this is and isn't: this post is general security education, not a personalized risk assessment of your specific business or systems. If you want a free, automated starting point for your own site, we offer a Security Health Check — free for any business, no obligation.
The fake email that looks just real enough to trust. How phishing actually works, and the one habit that catches almost all of it.
Security awarenessAll sectorsNot a dramatic hack-movie moment — a normal Tuesday until every file on the network is locked. How ransomware actually gets in, and the one habit that makes it survivable.
Security awarenessAll sectorsA password is one point of failure. Why MFA is the single highest-leverage security habit a small business can turn on — and what it actually does when a password gets stolen.
Security awareness