Skip to content

AI Accelerates Vulnerability Discovery: CISOs Must Rethink Patch Management

In a nutshell: CISOs must shift from regular patch cycles to risk-based “Just-in-Time Patching” with real-time exploitation intelligence as AI tools now expose vulnerabilities at scale.

AI-driven vulnerability discovery identifies security gaps faster than ever before — traditional, time-based patch cycles can no longer keep pace. Security experts therefore call for a fundamental rethink in vulnerability management strategy.

AI systems like Claude Mythos are significantly accelerating vulnerability discovery and signal a structural shift in the cybersecurity landscape. According to authorities such as the UK National Cyber Security Centre, this leads to a sharp increase in patching requirements. Security experts warn that most organizations are already struggling to fix known security gaps quickly — an AI-driven flood of additional findings could overwhelm teams and widen the gap between problem discovery and remediation.

The traditional patch management model was designed for an era when vulnerability discovery still moved at the pace of human research: researcher finds a flaw, reports it, CVE is assigned, vendor releases a patch, organization tests and deploys — a process that typically takes a median of 43 days according to the Verizon database. Autonomous AI systems fundamentally break this model: an AI system does not wait for proof-of-concepts on GitHub or CVSS scores in dashboards, but finds the gap, confirms exploitability and acts immediately.

Muhammad Yahya Patel, vCISO at Huntress, calls for a paradigm shift to risk-based, continuous approaches coupled to real-time exploitation intelligence rather than waiting for patch windows that leave exploitation windows open for days or weeks. Shane Fry of RunSafe Security argues that patching as a security strategy has been in crisis for years and AI-accelerated discovery has now intensified this. Virtual patching — blocking exploit attempts at a security layer — can play a role but does not close the gap.

Instead, security teams should move to preventive strategies that make it impossible to exploit bugs. According to Rik Ferguson, Vice President Security Intelligence at Forescout, this requires a concept called “Assume Autonomy”: organizations must establish continuous asset visibility, know precisely which systems exist, where they are located, and what current exposure they face. Just-in-Time Patching — prioritizing and deploying fixes based on current exploitation intelligence — is a goal to strive for, but it requires that organizations have this basic infrastructure in place.


Source: www.csoonline.com · Published 16 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: