AI is breaking cybersecurity's patch playbook
Add Axios as your preferred source to
see more of our stories on Google.

Illustration: Annelise Capossela/Axios
The cybersecurity industry spent decades assuming defenders would have enough time to prioritize patches after vulnerabilities became public.
- AI is rapidly reducing the time defenders have to act.
Why it matters: As AI shrinks the time between a vulnerability's public disclosure and its exploitation, organizations may have only hours — not days or weeks — to patch affected systems.
Driving the news: Microsoft released fixes for more than 600 vulnerabilities this month, a record that experts say underscores the growing volume of software flaws defenders must now identify, prioritize and patch.
- "The bug apocalypse has fully descended upon us," Dustin Childs, head of threat awareness at Trend Micro's Zero Day Initiative, said in a statement.
- The Trump administration also said last week it had started accepting reports to its AI vulnerabilities clearinghouse, which was established as part of last month's executive order.
The big picture: AI is making both defenders and attackers better at finding software flaws. Security researchers said AI is helping uncover more vulnerabilities than ever, while also raising concerns that attackers will soon be able to weaponize those flaws much faster than organizations can patch them.
- In the long run, experts said, AI tools will likely be able to proactively find, dissect and patch vulnerabilities in a system, as well as write code that's free of security flaws from the very beginning.
- But in the next two to three years, there will be a gap between when attackers start automating and when defenders will see gains from AI.
Threat level: Hackers are also moving at unprecedented speeds.
- Hido Cohen, cyber research lead at security firm Dream, said his team has observed an attacker take just nine hours to create a working exploit for a critical flaw after it was disclosed and then point that exploit at government customers.
- "Nine hours is faster than most patch approval processes even convene," Cohen said.
Reality check: Even before AI tools began accelerating attacks, companies struggled to patch critical security flaws.
- Last year, the median time companies took to patch critical bugs rose to 43 days, up from 32 days in 2024, according to Verizon's annual data breach report.
Between the lines: Basic cyber defenses like multifactor authentication and identity security are becoming even more important as organizations have less time to patch newly disclosed flaws.
- AT&T CISO Rich Baich and RSAC conference chair Hugh Thompson last week called on organizations to focus more on preventing attacks and doubling down on identity security practices like multifactor authentication as attacks start to move at machine speed.
- "Our profession shouldn't be defined by how efficiently we observe compromise," Baich and Thompson wrote. "It should be defined by how effectively we reduce the likelihood of compromise in the first place."
The intrigue: Former CISA Director Jen Easterly warned last week that her former agency's Known Exploited Vulnerabilities (KEV) catalog will need to be updated for the AI world.
- KEV is a widely used catalog of vulnerabilities that hackers are actively exploiting. It helps defenders prioritize which flaws to patch first.
- "For widely deployed, internet-facing products, the period in which defenders can wait for confirmed exploitation before acting is shrinking," Easterly wrote.
What to watch: The cybersecurity race is starting to shift from building AI that can find vulnerabilities to building AI that can help organizations prioritize, mitigate and eventually remediate them before attackers strike.
- Some security vendors are already releasing small language models designed for vulnerability triage and other security tasks, arguing they're cheaper and practical enough to deploy continuously.
Go deeper: Companies don't need advanced AI to defend against AI-powered hacks
