The cybersecurity industry has long thought that when a vulnerability is disclosed, defenders have enough time to set patch priorities, but AI is rapidly cutting that time, Axios reported on July 21 local time.
The report said AI is shortening the time from disclosure to real attacks, leaving companies in a situation where they may need to patch systems in just hours rather than days or weeks.
In July, Microsoft released fixes for more than 600 vulnerabilities. It was the largest ever. That means there are more software flaws that defenders must find, prioritise and fix, Axios reported, citing experts.
Dustin Childs (더스틴 차일즈), head of threat awareness at Trend Micro's Zero Day Initiative, said a "defect deluge is coming."
AI can make both defenders and attackers stronger. AI is helping discover more vulnerabilities than ever, but there is also growing concern that attackers can weaponise these flaws much faster than organisations can patch them.
Hido Cohen (히도 코언), head of threat analysis at security firm Dream, said he identified a case in which attackers produced working attack code just 9 hours after a serious flaw was disclosed and targeted government agency customers. He said, "9 hours is time that passes before most patch approval processes even open."
Even before AI increased the speed of attacks, companies were already failing to fix critical flaws in time. Verizon's annual Data Breach Investigations Report said the median time companies took to fix critical flaws last year was 43 days, up from 32 days in 2024.
Industry attention is now shifting from AI that finds vulnerabilities to AI that helps organisations prioritise, respond and fix issues before attacks. Some security companies are already releasing small language models for classifying vulnerabilities, citing that they are inexpensive and can run continuously.