news.mlab.sh
Back to the feed
threat-intel

AI Changed the Exposure Problem. Validation Needs to Change With It.

High
Summary

The volume of disclosed vulnerabilities is increasing dramatically, but the number of those actually exploited in the wild remains relatively low. Traditional methods like relying solely on CVSS scores are insufficient because an exposure’s impact varies greatly depending on the specific environment and asset. To effectively manage this growing challenge, security teams need a layered approach combining exploitability validation (determining if an exposure is actually exploitable), security control validation (testing if existing defenses work), and agentic pentesting (simulating real attacks). This combined strategy, along with a focus on decision-driven response and exposure reduction, is crucial for navigating the complexities of a rapidly evolving threat landscape, particularly in an era where attackers are leveraging AI to enhance their attacks. The Validation Summit ’26 will explore these concepts and provide insights from leading enterprises.

The cybersecurity landscape is experiencing a significant shift, driven by a dramatic increase in the number of disclosed vulnerabilities. In the first half of 2026, a staggering 35,853 CVEs were published, representing a 49% increase compared to the previous year. However, only a small fraction – 495 – were exploited in the wild, and 116 were under attack on the day they became public. This disparity highlights a critical problem: relying on CVSS scores alone is inadequate for determining which vulnerabilities pose a genuine threat to an organization.

Traditional vulnerability management often treats every CVE with a High or Critical CVSS rating as an emergency, a strategy that’s increasingly ineffective. The reality is that a single vulnerability can affect hundreds of assets, but its impact varies significantly depending on whether those assets are reachable, protected by existing controls, or critical to business operations. Some exposed assets may be completely unreachable, while others might be shielded by defenses that prevent exploitation.

Automated pentesting can provide valuable evidence, but it’s not a complete solution. While 95% of organizations consider pentesting a top priority, only 32% of their average attack surface is tested annually. Automated tools can expand coverage, but they can't overcome constraints like the need for a working exploit or the inability to safely test against restricted or air-gapped assets.

To address this gap, a more sophisticated approach is needed. This involves a three-pronged strategy: exploitability validation (determining if an exposure is actually exploitable, even without a working exploit), security control validation (testing whether existing defenses effectively block or detect attacks), and agentic pentesting (simulating real attacks to demonstrate how far an attacker could progress within a specific environment). These methods answer different questions under different exposure conditions.

Leading enterprises, such as Chanel, Atlassian, and the NFL, are adapting their security validation programs to incorporate these techniques. The Validation Summit ’26, hosted by Picus Security, will feature insights from security experts and industry leaders on how to implement this integrated approach, emphasizing decision-driven response and exposure reduction. The summit will demonstrate a validation workflow starting with a newly disclosed vulnerability – without a patch or working exploit – and progressing through validation before a Proof of Concept exists, testing the exploit against live controls once it appears, and then re-validating after a fix is implemented.

This approach moves beyond simply identifying vulnerabilities and focuses on understanding their true risk within a specific organization’s environment.

Read the full article at The Hacker News