















The mean time to exploitation (MTTE) of a new vulnerability is shrinking at a pace that nearly defies belief. Last year, MTTE reached one week. This year, it will reach one minute.
The fact that threat actors will soon be able to weaponize flaws literally within seconds of their disclosure is likely to worry IT teams that on average require nearly a week or longer to test and deploy critical patches. (That’s a lot faster than the patching pace of even a year or two ago, but thanks in part to AI, even six days isn’t fast enough.)
There is another, even more worrisome, development: The number of Zero Days is multiplying, with Zero Days now representing 82% of all exploited vulnerabilities (up from 53.6% in 2025). This means more exploits will be discovered even before software vendors realize there’s a problem. For security teams, however, that scenario is particularly alarming, because it means they will face more vulnerabilities for which no patch yet exists.
AI, in fact, is the reason patching has suddenly become a boardroom concern. C-level execs are alarmed because they’re reading about powerful frontier AI models capable of discovering previously undetected vulnerabilities at a pace no human or standard vulnerability scanner can match, while at the same time identifying complex exploit paths that could put assets and data at real risk. The fear is that many of these vulnerabilities, which on their own might be low-risk gaps, can be chained together to form a viable attack path that threat actors can exploit to do real damage.
Eventually, something very similar to these frontier AI models will fall into the hands of threat actors. But in a way, that doesn’t matter, because attackers already are able to use AI to dig up previously unknown vulnerabilities and then create working exploits within hours, and their pace is quickening. They’re able to exploit a vuln faster than most patch approval committees take to schedule a meeting. And that’s assuming, as noted before, that a patch is even available when it’s time to act.
No wonder security leaders everywhere are wondering how they can hope to defend their endpoints, networks, SaaS apps, and data in an era of endless Zero Days and rapid exploitation.
Certainly, streamlining and automating patching processes is becoming critical. But patching, as important as it is, is typically the job of IT, not security. The process is usually very deliberative because patches can break software and workflows—sometimes disastrously. Shrinking a week-long patching process down to days, hours, or minutes is not a light lift. But while this process takes place, what should security teams be focused on? Plenty.
Given that the danger to all organizations—particularly medium-sized enterprises and smaller—is present and escalating, it’s vital that security teams do all they can to protect against ever-more-powerful AI models in the hands of threat actors. (Today’s “non-frontier” AI models already can find vulns faster than any human or vulnerability scanner; this isn’t a “someday problem”—it’s a “today problem.”)
Most security professionals understand they can’t patch their way out of this problem. No matter how fast your patching processes become, it still won’t be enough to protect your organization. There will be times when patches aren’t available. That’s where compensating controls come in. They’re the only way to protect your endpoints, networks, and data in the age of accelerated AI vulnerability discovery.
Here’s what security practitioners can do right now to implement compensating controls and improve their defenses against what’s coming. These broad compensating controls can prevent a broad range of vulnerabilities, regardless of the software involved, the status or speed of patching, or even the outright lack of patches.
Execs may be focused on patching these days, but patching is only part of the picture. Compensating controls will shore up protections no matter what your patching environment is like.
You can’t afford to wait, and the good news is that you don’t have to. The capabilities outlined in this blog are available to all security teams, not just a select few.
While IT goes about the vital work of automating their patching processes, security teams can deploy these protections now to immediately harden their IT environment, monitor and block suspicious behaviors, stop attacks before they do damage, and mitigate and recover quickly.
In an age of endless Zero Days and accelerating threats, defenders need all the advantages they can get.
Explore how you can deploy the latest breakthroughs in AI-driven protections in the eBook, 8 Ways AI is Easing Stress on the SOC.


Dominic Djannesari
Senior Product Manager Enterprise EDR, Enterprise Security Group
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。