Frontier AI Just Made the Race to Patch Vulns That Much Harder

For the 99.9% of organizations bracing for an era of endless Zero Days, it’s time to act—and fast

  • The window between vulnerability disclosure and exploitation is collapsing from days to minutes, making traditional patching timelines woefully inadequate in the face of AI-powered attackers.
  • As frontier AI accelerates both vulnerability discovery and exploit development, security leaders must assume threats will move faster than patching processes can keep pace.
  • While frontier AI-driven patching remains out of reach for most organizations, defenders can strengthen resilience today through layered controls, unified visibility, AI-assisted detection and response, and faster mitigation and recovery practices.

The mean time to exploitation (MTTE) of a new vulnerability is shrinking at a pace that nearly defies belief. Last year, MTTE reached one week. This year, it will reach one minute

The fact that threat actors will soon be able to weaponize flaws literally within seconds of their disclosure is likely to worry IT teams that on average require nearly a week or longer to test and deploy critical patches. (That’s a lot faster than the patching pace of even a year or two ago, but thanks in part to AI, even six days isn’t fast enough.)

There is another, even more worrisome, development: The number of Zero Days is multiplying, with Zero Days now representing 82% of all exploited vulnerabilities (up from 53.6% in 2025). This means more exploits will be discovered even before software vendors realize there’s a problem. For security teams, however, that scenario is particularly alarming, because it means they will face more vulnerabilities for which no patch yet exists.

Frontier AI has entered the chat

AI, in fact, is the reason patching has suddenly become a boardroom concern. C-level execs are alarmed because they’re reading about powerful frontier AI models capable of discovering previously undetected vulnerabilities at a pace no human or standard vulnerability scanner can match, while at the same time identifying complex exploit paths that could put assets and data at real risk. The fear is that many of these vulnerabilities, which on their own might be low-risk gaps, can be chained together to form a viable attack path that threat actors can exploit to do real damage.  

Eventually, something very similar to these frontier AI models will fall into the hands of threat actors. But in a way, that doesn’t matter, because attackers already are able to use AI to dig up previously unknown vulnerabilities and then create working exploits within hours, and their pace is quickening. They’re able to exploit a vuln faster than most patch approval committees take to schedule a meeting. And that’s assuming, as noted before, that a patch is even available when it’s time to act.

No wonder security leaders everywhere are wondering how they can hope to defend their endpoints, networks, SaaS apps, and data in an era of endless Zero Days and rapid exploitation. 

Certainly, streamlining and automating patching processes is becoming critical. But patching, as important as it is, is typically the job of IT, not security. The process is usually very deliberative because patches can break software and workflows—sometimes disastrously. Shrinking a week-long patching process down to days, hours, or minutes is not a light lift. But while this process takes place, what should security teams be focused on? Plenty.

Patching alone won’t solve this

Given that the danger to all organizations—particularly medium-sized enterprises and smaller—is present and escalating, it’s vital that security teams do all they can to protect against ever-more-powerful AI models in the hands of threat actors. (Today’s “non-frontier” AI models already can find vulns faster than any human or vulnerability scanner; this isn’t a “someday problem”—it’s a “today problem.”)

Most security professionals understand they can’t patch their way out of this problem. No matter how fast your patching processes become, it still won’t be enough to protect your organization. There will be times when patches aren’t available. That’s where compensating controls come in. They’re the only way to protect your endpoints, networks, and data in the age of accelerated AI vulnerability discovery. 

Here’s what security practitioners can do right now to implement compensating controls and improve their defenses against what’s coming. These broad compensating controls can prevent a broad range of vulnerabilities, regardless of the software involved, the status or speed of patching, or even the outright lack of patches. 

  1. Harden at the edge. Ensure appropriate firewalling, IDP, authentication, and malware detection controls are all in place and fully operational. Don’t neglect the software you expose to public networks. On-premise or cloud-based endpoint protection allows you to shield these popular points of infiltration
  2. Block bad behavior before it does damage. IT may be focused on patching, but security focuses on preventing exploits and attacks. That job becomes far easier if you can stop attacks before they begin. Behavioral blocking automatically stops potentially suspicious activity, including anomalous use of legitimate software—ground zero for living off the land (LOTL) attacks. Also: Consider deploying application control protections that deny access and executables by default, allowing them to enter or run only after proving they’re trustworthy. Both protections carry the added benefit of shrinking your attack surface. (And if you’re thinking of applying default-deny policies to just mission-critical or externally facing servers, be aware that thanks to attackers’ use of AI, every server is at risk and should have these protections.)
  3. Unify your visibility to stop unpatched lateral movement. Let’s face it, with exploits happening before patches are available and deployed, something’s bound to get through. That’s why it’s vital to understand what’s happening throughout your environment so you can stop attackers before they get what they came for. AI-enabled cross-vector visibility is a must here, and so is the ability to correlate telemetry from endpoints, networks, SaaS applications, and data to surface real understanding about what’s happening before it gets out of hand. This ensures that if one unpatched system is probed, machine-speed AI contains the incident immediately. 
  4. Deploy AI protections to anticipate, investigate, and remediate attacks. Believe it or not, you can deploy AI-powered tools today that leverage a massive database of real-world threat intel to actually predict an attacker’s next four or five moves and shut down their path before they can progress. Add the ability to visually and dynamically investigate an attack, and produce investigation summaries that connect the dots for analysts at all levels, provide MITRE mappings, and even offer a path to remediation. Because when attacks happen at this velocity, every second matters.  
  5. Do all you can to mitigate faster. Threat actors are moving at machine speed, and mitigation needs to operate just as quickly. Consider platform solutions like XDR that pull together the entire picture and give you all the tools and intelligence you need to mitigate quickly while shutting down avenues for future attacks. 
  6. Run only supported software. Unsupported versions of software expose environments to exploit and compromise regulatory compliance. Coordinate with IT to ensure users and systems run only supported software. (This goes for AI tools as well, which, even if they’re not jailbroken by threat actors, can still expose sensitive data if you don’t have the right controls in place.) 
  7. Reassess configurations. Configuration errors or gaps leave you exposed. Work with IT to ensure software is not just up to date but also configured to support security controls. Some systems, including email, almost always benefit from a configuration review.
  8. Confirm you’re set with comprehensive logging and monitoring. Operational telemetry is critical in post-incident response and for detection and containment. Once again, the ability to gather and correlate telemetry across all domains puts you a step ahead here.
  9. Prepare to recover quickly. The sober reality for security practitioners is that, despite all the compensating controls you put in place, it’s possible you could be seeing more breaches than before. Everything you can do to shorten your recovery point and recovery time objectives will help your organization weather the storms that are coming. 

The future is here and it’s time to act

Execs may be focused on patching these days, but patching is only part of the picture. Compensating controls will shore up protections no matter what your patching environment is like.   

You can’t afford to wait, and the good news is that you don’t have to. The capabilities outlined in this blog are available to all security teams, not just a select few.

While IT goes about the vital work of automating their patching processes, security teams can deploy these protections now to immediately harden their IT environment, monitor and block suspicious behaviors, stop attacks before they do damage, and mitigate and recover quickly. 

In an age of endless Zero Days and accelerating threats, defenders need all the advantages they can get. 

Explore how you can deploy the latest breakthroughs in AI-driven protections in the eBook, 8 Ways AI is Easing Stress on the SOC

You might also enjoy

Explore Upcoming Events

Find experts in the wild

See what's next