惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
DataBreaches.Net
MongoDB | Blog
MongoDB | Blog
GbyAI
GbyAI
L
LangChain Blog
B
Blog
博客园 - 三生石上(FineUI控件)
Martin Fowler
Martin Fowler
博客园 - 【当耐特】
Recent Announcements
Recent Announcements
P
Proofpoint News Feed
U
Unit 42
Last Week in AI
Last Week in AI
WordPress大学
WordPress大学
有赞技术团队
有赞技术团队
雷峰网
雷峰网
Microsoft Security Blog
Microsoft Security Blog
T
The Blog of Author Tim Ferriss
爱范儿
爱范儿
小众软件
小众软件
I
InfoQ
G
Google Developers Blog
大猫的无限游戏
大猫的无限游戏
人人都是产品经理
人人都是产品经理
C
Check Point Blog

Help Net Security

ChatGPT advanced account security adds passkeys and hardware keys Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for months Automating Pentest Delivery: A Step-by-Step Guide - PlexTrac Open-source privacy proxy masks PII before prompts reach external AI services Shadow AI risks deepen as 31% of users get no employer training Identity is the control plane for distributed infrastructure AI traffic is getting bigger, louder, and less predictable New infosec products of the month: April 2026 cPanel zero-day exploited for months before patch release (CVE-2026-41940) Cisco releases open-source toolkit for verifying AI model lineage Met Police face criticism for using AI to spy on their own officers Nine-year-old Linux kernel flaw enables reliable local privilege escalation (CVE-2026-31431) Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security IP Fabric MCP server adds governance and control to enterprise AIOps workflows - Help Net Security Aqua Compass MCP server enables real-time investigation and containment of runtime threats - Help Net Security Google brings instant email verification to Android, no OTP needed - Help Net Security If cyber espionage via HDMI worries you, NCSC built a device to stop it - Help Net Security Apple fixes iPhone bug that let FBI retrieve deleted Signal messages(CVE-2026-28950) - Help Net Security GopherWhisper APT group hides command and control traffic in Slack and Discord - Help Net Security OpenAI tackles a bad habit people have when interacting with AI - Help Net Security A year in, Zoom's CISO reflects on balancing security and business - Help Net Security Scenario: Open-source framework for automated AI app red-teaming - Help Net Security GDPR works, but only where someone enforces it - Help Net Security Ransomware, fraud, and lawsuits drive cyber insurance claims to new peaks - Help Net Security Google’s Workspace Intelligence promises privacy while running on your data - Help Net Security Cyberattack on French government agency triggers phishing alert - Help Net Security Claude Mythos finds 271 Firefox flaws, Mozilla believes zero-days are numbered - Help Net Security Prove Identity Platform connects verification, authentication, and fraud prevention - Help Net Security New Mirai variants target routers and DVRs in parallel campaigns - Help Net Security Acronis GenAI Protection gives MSPs control over AI usage and data risks - Help Net Security
AI shrinks vulnerability exploitation window to hours
Anamarija Pogorelec · 2026-05-18 · via Help Net Security

Time has become organizations’ biggest vulnerability because the gap between vulnerability discovery and exploitation has narrowed to hours, according to Synack’s 2026 State of Vulnerabilities Report.

AI-driven vulnerability trends

Total vulnerabilities by severity (2022-2025) (Source: Synack)

AI expands the attack surface

Agentic AI systems that act autonomously across systems introduce new risks that require human expertise to identify and understand. Automated scanning detects known signatures but can miss logic flaws, misconfigurations, and unexpected behavior.

In 2025, mean time to remediation dropped by approximately 47% across all severity levels, showing that the industry is moving toward continuous security validation, with periodic testing serving a supporting role.

Published CVEs reached 48,244 in 2025, a 20% year-over-year increase. Customer programs that maintained stable findings against that backdrop indicate that security posture is keeping pace with a faster-moving environment.

“Adversaries can identify and exploit vulnerabilities within increasingly shorter timeframes. Organizations that continuously validate security across their environment are responding faster and closing critical exposure windows earlier,” said Dr. Mark Kuhr, CTO of Synack.

Low- and medium-severity findings declined in 2025. High-severity findings increased, especially in mature programs that tend to generate less noise.

AI-enabled adversaries are shrinking the gap between a CVE’s public disclosure and the first observed exploitation by threat actors. Unexpected zero-day vulnerabilities such as React2Shell (CVE-2025-55182) allowed unauthenticated attackers to send malicious HTTP requests that resulted in remote code execution on servers.

In 2025, total vulnerability volume remained relatively stable, but high-severity vulnerabilities increased by 10% compared with 2024.

Familiar vulnerabilities, faster exploitation

The most frequently identified vulnerability remained cross-site scripting (XSS), followed by authorization and permission issues. Content injection, brute-force attacks, and remote code execution increased throughout 2025. These trends show growing attacker focus on social engineering, identity-based exploitation, supply chain vulnerabilities, and authentication boundaries, aligning with AI-enabled adversaries testing access controls.

Average mean time to remediation dropped from 63 days in 2024 to 38 days in 2025, while critical vulnerabilities were remediated 25 days faster. Shorter remediation timelines reflect pressure from AI-enabled attackers that continue to reduce average time to exploit. PTaaS platforms help teams correlate vulnerability data across assets and business units, improving prioritization and workflows.

Growing infrastructure expands exposure

Security teams in retail, financial services, government, technology, and manufacturing continue to face challenges in mapping IT assets and infrastructure. Average asset counts grew or remained stable in 2025, except in retail. Manufacturing recorded the sharpest increase, from 2,053 to 2,486 assets per organization.

Subdomains remained the largest asset category by volume, averaging about 40,000 per organization. Web applications also increased year over year, showing faster development cycles associated with AI coding assistants.

Critical and high-severity vulnerabilities accounted for 37% of findings across these industries. Manufacturing, technology, and government recorded the largest share of critical and high-severity findings. Retail and financial services remained below the overall average.

The technology sector accounted for the largest share of critical SQL injection findings, followed by financial services. Critical remote code execution findings were distributed more evenly across sectors.