Skip to content

Vulnerability Flood from AI-Powered Security Research – CISOs Must Rethink Defence Model

In brief: AI-powered vulnerability discovery is overwhelming traditional patch processes; CISOs must shift from patch speed to network microsegmentation to block lateral movement.

Microsoft released patches for 570 vulnerabilities in July 2026 – the largest Patch Tuesday in its history, including three zero-day exploits and 141 remote code execution vulnerabilities. This explosion reveals a structural problem: AI models like Anthropic’s Mythos discover security gaps faster than organisations can fix them.

Following Anthropic’s introduction of Mythos Preview on 7 April 2026, vulnerability discovery accelerated dramatically. At Microsoft, monthly patches rose from 120 in May to 200 in June and then to 570 in July – an increase of 375 per cent within two months. Google Chrome saw a jump from 126 patches in May to 429 in June (plus 240 per cent) and 433 in June. Adobe doubled its monthly reports from 52 in May to 123 in June (plus 137 per cent). While these figures do not prove that Mythos discovered all these vulnerabilities, they illustrate the massive pace of vulnerability disclosure in the era of AI-powered research.

The traditional patch management model – prioritise active exploitation, perform testing, patch promptly – is reaching its limits. When vulnerability discovery outpaces organisational capacity to remediate, gaps inevitably emerge. Anthropic reports that Mythos has already identified thousands of high-severity vulnerabilities, including critical gaps in widespread operating systems and browsers. Both attackers and defenders will soon face speed and scale that human teams cannot match.

The core issue, however, lies not in the vulnerability itself, but in subsequent compromise: a vulnerability is typically only the initial entry point. Real damage occurs through lateral movement to critical systems – domain controllers, databases, production environments, backup infrastructure and cloud control planes. Zero Networks’ 2026 Lateral Movement Exposure Report analysed 54 trillion activities across 312 enterprise environments and revealed significant security gaps: 80 per cent of servers are reachable from anywhere in the network, 87 per cent accept RDP or SSH connections from broad internal sources, 78.7 per cent are accessible via SMB or WinRM, and 43.2 per cent of authentication still relies on the outdated NTLM protocol. A compromised host can reach 85 per cent of internal systems on the first hop alone.

CISOs should fundamentally reshape their strategy: rather than running faster in the patch race, change the rules of the game. This means making lateral movement harder – through network microsegmentation, strong authentication and limiting host-to-host communication. This dramatically reduces the exploitable surface even for non-critical vulnerabilities.


Source: www.it-daily.net · Published 28 July 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.

Share on: