Skip to main content
AI Compresses Attack Windows to Days, Not MonthsVulnerability & Exposure Management
4 min readFor CISOs & Security Leaders

AI Compresses Attack Windows to Days, Not Months

More than 100 technology and cybersecurity firms have signed an open letter with a clear warning: AI will speed up cyberattack timelines so much that your existing vulnerability backlog is a ticking bomb. Led by OpenAI and including Microsoft, Google, Amazon Web Services, and Anthropic, the coalition warns that enterprises have less time to fix weaknesses that have been ignored for years.

This isn't about new attack methods. It's about speed and scale. AI systems can now discover and exploit the same misconfigurations, unpatched software, and excessive permissions you've been dealing with for months, but they'll do it in hours.

What the Data Shows

The coalition's letter highlights three findings that change how you should approach vulnerability management:

Organizations can only remediate roughly one in ten vulnerabilities each month. This capacity issue, noted by Robbie Mueller at ArmorCode, means your backlog is growing, not shrinking. AI doesn't need to find new zero-days when it can link existing weaknesses into attack paths faster than your team can address them.

The threat is throughput, not sophistication. Mueller states, "What matters is not the number of findings but which ones chain together into a viable path." AI excels at pattern recognition, mapping multi-step attack sequences while your analysts are still reviewing last quarter's CVSS scores.

Focus on executing existing security practices. You don't need a new framework. You need to fix the basics before AI-enabled attackers exploit them at machine speed.

What This Means for Your Team

Your current vulnerability management process was built for human-speed attacks. An adversary needed time to explore your environment, find weaknesses, and develop exploits. That timeline allowed you to prioritize based on risk scores and remediation complexity.

AI changes that timeline. Johnathan Hunt at LogicMonitor says, "Bad actors will move at machine speed, while many legacy systems still rely on human reaction times."

AI is also speeding up your development processes. Ryan McCurdy at Liquibase notes that security teams must now determine whether changes are "authorized, safe, and expected" faster than manual review allows. You're defending a faster-moving target against faster-moving threats.

The reality is stark. If you can only fix one in ten vulnerabilities per month, and AI can exploit chains of those vulnerabilities in days, your Mean Time to Remediate becomes your primary risk metric. Not detection capability. Not response plan. Your ability to close gaps before they're weaponized.

Action Items by Priority

1. Identify and kill attack paths, not individual CVEs.

Stop treating your vulnerability backlog as a flat list ranked by CVSS score. Map which combinations of weaknesses create viable paths to your critical assets. A medium-severity misconfiguration combined with excessive permissions and weak authentication creates a critical path. Fix the chain, not the score.

Start with CIS Controls v8.1 focusing on Control 7 (Continuous Vulnerability Management) and Control 6 (Access Control Management). These controls address excessive permissions, weak authentication, and unpatched software.

2. Enforce least-privilege access across your environment.

The letter highlights "excessive permissions" as a longstanding weakness. Audit your identity and access management posture now. Every service account, API key, and user permission that exceeds the minimum required creates an exploitable step in an attack chain.

NIST SP 800-53 Control AC-6 (Least Privilege) provides the technical framework. If you're subject to SOC 2, this maps directly to the Common Criteria for access controls. Document your privilege boundaries and test them with exercises assuming an AI adversary can map your entire permission structure in minutes.

3. Accelerate your patch cycle for internet-facing and identity infrastructure.

You can't fix everything in ten days. Prioritize systems that authenticate users, manage credentials, or face the public internet. These are the entry points AI will probe first.

If you're managing a federal system under NIST SP 800-53, this aligns with SI-2 (Flaw Remediation). For commercial environments, CIS Controls v8.1 Implementation Group 1 provides the baseline: automated patch management for operating systems and applications.

4. Deploy AI-assisted detection where you have visibility gaps.

The coalition calls for putting "cyber-capable AI in the hands of defenders." If you're overwhelmed by security events and can't correlate them fast enough, AI-assisted detection tools can help you spot the attack chains Mueller describes.

Sophos, a signatory, notes that AI can help defenders "find exposures and respond to threats before they cause material harm." Evaluate Endpoint Detection and Response platforms and SIEM solutions that use machine learning to surface anomalous chains of activity, not just individual alerts.

5. Share threat intelligence and indicators of compromise.

John Strand at Black Hills Information Security emphasizes "greater sharing of IOCs." If you're part of an Information Sharing and Analysis Center for your sector, actively contribute and consume indicators.

NIST Cybersecurity Framework 2.0 Function DE (Detect) includes category DE.AE-5 (Incident alert thresholds are established). Update your thresholds based on shared intelligence about AI-enabled reconnaissance patterns.

The Incentive Question

Seemant Sehgal at BreachLock raises a valid concern: "The companies asking governments to fund AI defensive tools are the same ones that would get paid to supply them." This doesn't invalidate the threat, but it means you should evaluate AI security solutions with the same rigor you'd apply to any vendor claim.

Focus on measurable outcomes: Can the tool reduce your Mean Time to Detect for chained vulnerabilities? Can it prioritize remediation based on actual attack paths in your environment? If the answer is "we use AI" without specifics, keep looking.

You Might Also Like