AUTO-UPDATED

AI Broke Vulnerability Management. That's Why CISOs Are Moving Budget to BAS.

The rapid rise of AI-driven vulnerability discovery and exploitation has collapsed the time-to-exploit window to 24 hours, rendering traditional manual patching strategies insufficient for modern enterprise cybersecurity defense.

Key Points

  • AI tools like Anthropic’s Claude Mythos have enabled the discovery of over 10,000 high-severity vulnerabilities in a single month.
  • The average time-to-exploit for new vulnerabilities has plummeted from approximately 53 days in 2024 to just 24 hours in 2026.
  • Verizon’s 2026 Data Breach Investigations Report shows that median patch times for known vulnerabilities have increased to 43 days.
  • Breach and Attack Simulation (BAS) platforms, such as those offered by Picus Security, use autonomous agents to validate security controls against real-world threats in minutes.
  • Gartner identifies this shift toward "Adversarial Exposure Validation" as a critical strategy for prioritizing risks based on actual exploitability rather than raw severity scores.

Why it Matters

The shift to machine-speed attacks means that traditional vulnerability management, which relies on manual triage and patching, can no longer keep pace with the threat landscape. By adopting autonomous validation tools, organizations can move beyond theoretical risk assessments to prove which vulnerabilities are actually exploitable, allowing security teams to focus resources on the most urgent gaps.
Internet Published by info@thehackernews.com (The Hacker News)
Read original