news.mlab.sh
Back to the feed
threat-intel

AI Broke Vulnerability Management. That's Why CISOs Are Moving Budget to BAS.

High
Summary

The rapid advancement of AI, particularly through tools like Anthropic's Claude Mythos Preview, has dramatically reduced the time it takes to discover and exploit vulnerabilities in software. This has collapsed the traditional ‘buffer’ used by cybersecurity teams, making it increasingly difficult to patch vulnerabilities before they are actively exploited. Consequently, organizations are shifting their focus and budget towards Breach and Attack Simulation (BAS) to proactively test their defenses against realistic AI-powered attack techniques.

The article details a significant shift in the cybersecurity landscape driven by the accelerating pace of vulnerability discovery facilitated by AI. Tools like Claude Mythos Preview are identifying vulnerabilities at an unprecedented scale, moving from months of research to just hours. This has effectively eliminated the ‘buffer’ – the time between vulnerability disclosure and exploitation – that previously allowed defenders to prepare. The sheer volume of vulnerabilities being uncovered, including previously undetected issues like the 27-year-old OpenBSD bug, is overwhelming traditional vulnerability management processes.

Organizations are responding by re-evaluating their strategies. The traditional approach of simply patching vulnerabilities based on severity scores is proving ineffective against the high volume and rapid discovery rate. The data from Verizon's 2026 DBIR highlights a concerning trend: the median time to patch known vulnerabilities has increased from 32 days to 43 days, and the percentage of fully patched vulnerabilities has decreased from 38% to 26%. This gap between attack and remediation is creating a significant window of opportunity for attackers.

To address this, CISOs are increasingly investing in Breach and Attack Simulation (BAS). BAS allows organizations to simulate real-world attacks, using the latest adversary tactics, techniques, and procedures (TTPs) to test the effectiveness of their security controls. This provides a more accurate understanding of vulnerabilities and how defenses would actually perform against active threats, rather than relying solely on static vulnerability assessments. The article emphasizes that simply patching faster isn't a viable solution when the time to exploit has shrunk to 24 hours.

Read the full article at The Hacker News