AI-Accelerated Vulnerability Discovery Crisis and Remediation Bottleneck
Frontier AI models are discovering thousands of novel vulnerabilities at unprecedented speed, collapsing the disclosure-to-exploit window to 'half-day'. CISA BOD 26-04 mandates 3-day patching, but patch volume surged 285% with only 26% of AI-generated patches fully correct. EY's new guidance on SOC reporting emphasizes continuous validation and days-long patching cycles. New developments: Nucleus AI early warning system to address scanner gaps; Frontier AI VM article offers practical exposure management and ring-based patching; CISA issued 72-hour patch deadline for actively exploited Oracle bug CVE-2026-21962 (CVSS 10). Chinese-speaking hackers (UAT-10147) are using AI to accelerate attacks on exposed servers, reinforcing the half-day exploit window.