AI-Driven Exploitation is Destroying Vulnerability Management. Here’s How to Handle It.
This article discusses the accelerating pace of vulnerability exploitation driven by the use of AI by both attackers and defenders. The traditional approach of simply ‘patching faster’ is no longer sufficient due to the shrinking timelines between vulnerability disclosure and exploitation. Organizations need to shift to a proactive approach, focusing on identifying and mitigating the most likely vulnerabilities quickly, validating exposures, and implementing temporary controls to reduce risk while full remediation efforts are underway.
The rapid advancement of AI is dramatically shortening the time it takes for vulnerabilities to be discovered, reproduced, and exploited. Previously, the window between a vulnerability's disclosure and in-the-wild exploitation was measured in days, but now it’s often within hours. This is largely due to AI-powered tools being used by both security teams and attackers to accelerate the vulnerability research and exploitation process. The article highlights the disconnect between the speed of attack and the traditional, slower patching cycles of many organizations.
The core issue is the ‘bottleneck’ in remediation. Attackers operate on timelines measured in hours, while defenders typically operate on weeks. This gap is being exploited, and the pressure from regulators, such as India’s CERT-IN, is pushing for faster patching, which is often impractical given operational constraints. Organizations are advised to move beyond simply ‘patching faster’ and instead adopt a more strategic approach focused on preemptive identification and mitigation of high-risk vulnerabilities.
To combat this, organizations should prioritize identifying vulnerabilities with characteristics that make them likely to be exploited – broad deployment, internet reachability, and a clear path to access. Rapid validation of exposure and implementation of temporary controls are crucial steps. The article suggests a shift to a ‘preempt, validate, and mitigate’ operating model, emphasizing the need for quick decision-making and proactive risk reduction.
