AI Models are Finding Vulnerabilities Faster
.webp?t=1787774405)
A report by SentinelOne and Tenable Holdings analyzed vulnerability discovery, exposure, and exploitation. According to the report, current attacker timelines are already moving faster than standard patch cycles can address. New frontier AI models compress vulnerability discovery from months to hours, significantly expanding potential risks while speeding the time for attackers to move from disclosure to exploit code in about a week.
The research finds that exposure data and runtime detection converge on the same edge-device vendor surfaces 79% of the time, while they share 21% overlap at the individual vulnerability level. Both state-sponsored actors and ransomware operators draw from the same small set of high-severity, actively exploited vulnerabilities.
Other key findings from the research include:
- Twelve vulnerabilities in the dataset carry confirmed "multi-nexus" attribution — state-sponsored and ransomware operators independently exploiting the very same flaw across five distinct threat categories, including China, Russia, DPRK, Iran-nexus and criminal (financially motivated) actors.
- More than half (54%) of organizations running F5 products carry at least one exposed, actively exploited vulnerability, while Citrix customers post the slowest remediation of any vendor studied, at a median of 461 days — a concrete illustration of how specific product lines stay exposed long after a patch exists.
- Remediation complexity on high-priority vulnerabilities introduces a statistically significant 24-day gap, widening the window attackers have to operationalize an exploit — underscoring why patching speed alone isn't enough without attack surface minimization and endpoint protection working in tandem.
Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!





