< Back to all clusters
[TECHNOLOGY] · United Kingdom · 2 sources

Vulnerability Exposure Window Shrinks as AI-Driven Exploits Accelerate

Industry research shows the time between a vulnerability’s public disclosure and its exploitation has collapsed dramatically. In 2016 the average window was 84 days; by 2024 it fell to five days, and recent findings suggest attackers can exploit flaws before patches exist, resulting in a negative seven‑day exposure window.

The acceleration is driven by AI models such as Anthropic’s Claude Mythos, released in April 2026, which identified over ten thousand high‑severity vulnerabilities within a month. Threat actors now weaponize vulnerabilities within hours, outpacing traditional manual remediation processes, especially in operational technology (OT) and Internet of Things (IoT) environments where devices often lack regular updates.

Regulators are responding: the U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued a binding directive requiring patches for known exploited vulnerabilities within three days. Vendors and security teams are turning to automated remediation platforms that can detect, prioritize, and remediate threats at machine speed, replacing the outdated “grace period” approach.

Entities: Anthropic · CISA · Claude Mythos · Mandiant · Rapid7