news.mlab.sh
Back to the feed
threat-intel

AI-Assisted Exploit Development Outpaces Scanner Detection

Critical
Summary

Research from Cogent indicates that AI-assisted exploit development is dramatically accelerating, reducing exploit creation time from 125 days to just 0.5 days using large language models. This creates significant ‘visibility gaps’ for security teams, as vulnerability scanners struggle to keep pace with the rapid development of exploits. The findings highlight a critical challenge for organizations relying on traditional scanner detection, particularly as AI-powered exploit development tools like Anthropic’s Claude Mythos become more widely available.

A new report from Cogent Research reveals a concerning trend: attackers are leveraging artificial intelligence to drastically reduce the time required to develop functional exploits for software vulnerabilities. Previously, creating an exploit for a CVE could take upwards of 125 days, but with the use of AI-powered tools, this time has been compressed to a mere 0.5 days. This acceleration is driven by large language models (LLMs) capable of analyzing patch diffs and generating proof-of-concept (PoC) exploits. The research underscores the growing sophistication of cyberattacks and the urgent need for security teams to adapt their strategies.

The study analyzed 69,159 CVEs, focusing on vulnerabilities published in 2025 and 2026, and found that a significant portion – 83.2% of critical vulnerabilities – created ‘visibility gaps’ for defenders. This means that many critical vulnerabilities went undetected by automated scanning tools, with over half (55.7%) receiving no detection coverage from major scanning vendors like Tenable, Qualys, and Rapid7. Furthermore, a concerning 62% of vulnerabilities already had exploits circulating before detection signatures were published. The report emphasizes the need for continuous vulnerability monitoring and proactive threat hunting.

Security vendors are responding to this challenge, with Tenable and Qualys highlighting their prioritization of high-risk vulnerabilities and their focus on actionable detections. However, the Cogent Research suggests that the speed of AI-driven exploit development is outpacing the ability of even these advanced scanning solutions to provide timely protection. The proliferation of AI-powered tools like Anthropic’s Claude Mythos, predicted to be within six to twelve months, is expected to further exacerbate this issue, creating a baseline for exploit development speed rather than a ceiling.

Read the full article at Dark Reading