











TL;DR: AI has collapsed the time between vulnerability disclosure and active exploitation from weeks to hours1. Third-party applications remain the most exploited and most under-managed attack surface2. N-central™ and N-sight™ answer both with a single, AI-accelerated workflow that scans, prioritizes, remediates, and verifies vulnerabilities across 900+ applications on Windows, macOS, and Linux, without tool switching.
A record 48,185 CVEs were published in 2025, roughly 131 every day3, and forecasts point to between 70,000 and 100,000 in 20264. Vulnerability exploitation now sits behind 20% of all breaches, up 34% year over year5.
That is not a patching backlog. It is a structural mismatch between how fast threats move and how fast most IT teams can respond. The teams that close the gap do more than patch faster. They consolidate workflows, cut manual triage, and use AI to operate at a speed that matches the threat.
Attackers are not waiting for your next patch window. Work that used to require a skilled human researcher, from vulnerability discovery to exploit weaponization to attack chaining, is now automated in hours with AI-assisted tools and open-source offensive frameworks6. The disclosure-to-exploitation window has collapsed: nearly 29% of vulnerabilities added to CISA’s Known Exploited Vulnerabilities catalog in 2025 were exploited on or before the day their CVE was published1.
The math is unforgiving. The average team takes 30.6 days to deploy a patch. Attackers weaponize the same vulnerability in 19.5 days1. That is an 11-day exposure window, and attackers only need one of those days.
AI has also lowered the skill barrier. LLM-powered phishing, automated reconnaissance, and AI-assisted exploit generation let less-experienced adversaries operate with the capability of senior researchers. The pool of capable attackers is widening, not just quickening.
Operating system patching gets the attention. Third-party applications get the exploits. Browsers, PDF readers, communication tools, developer utilities, and runtime libraries are the largest, fastest-changing, and most-exploited surface in any environment, yet most patch tools are built OS-first and treat third-party support as an afterthought7. Seventy percent of accumulated security debt traces back to third-party library flaws5.
Fragmentation compounds the problem. One tool for Windows, another for Mac, a third for Linux, a fourth for third-party apps, each with its own catalog, cadence, and blind spots. The apps a tool skips are the apps that get exploited. Manual tracking gives out at this volume, and lean teams default to patching what is loudest while the rest of the surface stays exposed.
Three things have to work together, and most teams have none of them fully in place:
N-central™ and N-sight™ deliver AI-accelerated vulnerability and patch management as one continuous workflow, built into the unified endpoint management platform IT teams already run.
This is an early expression of ResilienceAI, the embedded intelligence layer woven across the N-able platform to help IT teams shrink the attack surface before a threat lands.
The value is not the AI. It is what the AI lets teams accomplish.
AI industrialized the attack. N-central and N-sight industrialize the response, giving IT teams and the service providers who support them a way to move at the speed the threat now demands, without adding headcount to do it.
Sources
© N‑able Solutions ULC and N‑able Technologies Ltd. All rights reserved.
This document is provided for informational purposes only and should not be relied upon as legal advice. N‑able makes no warranty, express or implied, or assumes any legal liability or responsibility for the accuracy, completeness, or usefulness of any information contained herein.
The N-ABLE, N-CENTRAL, and other N‑able trademarks and logos are the exclusive property of N‑able Solutions ULC and N‑able Technologies Ltd. and may be common law marks, are registered, or are pending registration with the U.S. Patent and Trademark Office and with other countries. All other trademarks mentioned herein are used for identification purposes only and are trademarks (and may be registered trademarks) of their respective companies.
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。