Provides empirical proof for the 'Honeymoon Effect' and documents that 77% of initial vulnerabilities are regressive flaws inherited from legacy code reuse.
An analysis of 700 software releases and over 30,000 vulnerabilities confirms a 'Honeymoon Effect' where new software enjoys a median grace period of 110 days before its first vulnerability is discovered—an interval 1.54x longer than subsequent discovery windows. Remarkably, 77% of these first (primal) vulnerabilities are 'regressive,' lurking in legacy code reused from earlier versions that lay dormant for years. Open-source releases enjoy a longer honeymoon (median 115 days) than closed-source (98 days), suggesting that attacker familiarity, rather than source code access, is the primary driver of vulnerability discovery. Most critically, 21% of legacy vulnerabilities are 'less-than-zero' days, where a new product version is released with existing, well-known exploits already active, immediately ending the honeymoon phase.
New software releases enjoy a median 110-day 'honeymoon' before the first vulnerability is found, indicating that risk increases as attackers gain familiarity.
underestimating the risk of a project just because it has no 'current' vulnerabilities during its honeymoon phase
the honeymoon effect proves that 'zero vulnerabilities' in a new release is a temporary function of attacker unfamiliarity, not necessarily high code quality.
The study identifies 'Less-than-Zero days'—where new versions are released vulnerable to existing exploits—accounting for 21% of legacy vulnerabilities.
launching new products that are immediately exploitable by established, well-known attack vectors
releasing code vulnerable to existing CVEs (less-than-zero) is a documented high-frequency risk in software evolution, as seen in Windows 7's launch.
77% of primal vulnerabilities were regressive... dormant vulnerabilities are not the only cause... less-than-zero days account for 21% of legacy vulnerabilities.
Risk Guard focuses on new CVEs but doesn't explicitly track 'Legacy Persistence' or identify code blocks that have been reused across 5+ versions without a fresh audit.
Risk Guard would be better if it flagged 'Long-Lived Legacy Blocks' (code unchanged for 3+ years) as prime targets for deep security review based on the high probability of regressive flaws.