AI Is Finding Vulnerabilities Faster Than Teams Can Fix Them. That Changes Everything.
AI is accelerating both vulnerability discovery and exploitation, collapsing the window organisations have to respond. Continuous, automated remediation is now essential.
The exploit window is collapsing
The gap between a vulnerability being discovered and being exploited is shrinking. In some cases, it is approaching zero. AI-powered tools now enable attackers to scan, identify, and launch exploits at a speed and scale that manual processes simply cannot match.
This is not a theoretical concern. It is the operational reality for every organisation running internet-facing systems.
Two recent developments highlight how quickly this landscape is shifting, and why organisations need to rethink their approach to vulnerability management.
AI as a vulnerability hunter
Anthropic recently announced Project Glasswing, an AI model purpose-built for discovering software vulnerabilities. It proved so effective that Anthropic made the unusual decision to postpone its public release entirely. Instead, the company granted early access to Apple, Microsoft, Google, Amazon, and a coalition of other major vendors so they could find and patch bugs before adversaries could weaponise them.
The predecessor model, Mythos Preview, had already demonstrated a remarkable ability to surface previously unknown flaws. Project Glasswing took that further. The responsible disclosure approach was welcome, but it raises a harder question: who is going to fix all the bugs these models find?
Discovery is only half the problem. Remediation takes people, time, and prioritisation. If AI can surface hundreds of critical vulnerabilities in a fraction of the time it previously took, patching pipelines will become the bottleneck.
Automated exploitation is already here
On the offensive side, AI is compressing the exploit lifecycle. Attackers are using AI to automate reconnaissance, craft exploits, and chain vulnerabilities together at machine speed. The concept of a "collapsing exploit window" captures this well. Organisations that previously had days or weeks to respond to a disclosed vulnerability may now have hours, or less.
This changes the calculus for defenders. Patching cycles measured in weeks are no longer adequate. Vulnerability scanners that run monthly are too slow. The assumption that you will have time to assess and plan before an exploit appears in the wild is becoming unreliable.
What this means for organisations
This is not about panic. It is about preparation. There are practical steps organisations should be taking now.
- Reduce your attack surface proactively. Every exposed service, every unpatched endpoint, every forgotten test environment is a target that AI-powered tools can find instantly. Asset management and configuration hygiene matter more than ever.
- Automate your patching pipeline. If exploitation is automated, remediation needs to be too. Prioritise critical and internet-facing systems. Invest in tooling that can deploy patches rapidly with minimal manual intervention.
- Adopt continuous vulnerability management. Point-in-time assessments are insufficient. Organisations need continuous scanning, real-time prioritisation based on exploitability, and integration with their change management workflows.
- Plan for the remediation bottleneck. When AI surfaces vulnerabilities faster than teams can fix them, you need a clear framework for triage. Not every vulnerability carries the same risk. Context, such as exposure, business criticality, and available compensating controls, should drive your response order.
- Layer your defences. Patching alone will not keep pace. Network segmentation, zero-trust architecture, runtime protection, and robust detection and response capabilities all buy time when a patch is not yet applied.
Metaphor's perspective
We see this as a turning point for vulnerability management. AI is accelerating both sides of the equation. Defenders who treat patching as a periodic exercise will fall behind. Those who build automated, continuous remediation pipelines will be better positioned.
The responsible approach Anthropic took with Project Glasswing, giving vendors time to patch before public release, is commendable. But not every AI-driven discovery will come with that courtesy. Threat actors are building their own models, and they are not coordinating disclosure with anyone.
Organisations need to assume that their vulnerabilities will be found, quickly, by both sides. The question is whether your defences and response processes can keep up.
If you are unsure where your patching pipeline stands or whether your vulnerability management programme is fit for this new pace, we can help you assess and strengthen it.
Sources: The Hacker News - Beating Automated Exploitation at AI Speed, The Hacker News - Project Glasswing: Who's Going to Fix Them?