Skip to main content
CybersecurityVulnerability Management

Vulnerability Management Faces AI-Driven Overhaul

Security professional examines technology equipment on a tablet or laptop.

"Is my vulnerability program ready for this revolution?" asked Kevin Garvey, SANS Certified Instructor — a question he says Frontier AI models force every security team to face.

Anthropic's Mythos and Frontier AI's new tempo

Frontier AI models such as Anthropic's Mythos, Garvey writes, are shifting the vulnerability landscape by identifying zero-day flaws, chaining complex exploits, and adapting in real time. That machine-speed capability, the author argues, collapses the window between discovery and exploit and renders many traditional prioritization heuristics insufficient. For organisations that have backlog-laden vulnerability programs or distant plans to migrate to CTEM-style programs, Garvey warns, the answer to his opening question is often “no.”

Going beyond CVSS, EPSS, and CISA's KEV

Garvey notes that CVSS scores alone no longer cut through the noise. EPSS and CISA's KEV list, while now table stakes, are likewise insufficient when Frontier AI can rapidly convert flaws into working exploits. The article argues vulnerability programs must move past these legacy risk indicators and adopt a prioritization approach that maps exploitability to real business impact — not simply to a numeric severity or inclusion on a watchlist.

Building an exposure management function

To answer that prioritization gap, Garvey prescribes building an exposure management function inside vulnerability programs. Exposure management augments traditional VM by assessing true risk across the attack surface and helping prioritise remediation based on exploitability and business impact. It broadens the scope beyond open CVEs to include misconfigurations, reachability, and other sources of threat intelligence, and it leverages continuous monitoring, breach attack simulations, and automated pen testing to validate exposures.

In Garvey’s framing, exposure management makes it possible to "drill down into the vulnerabilities that need action as soon as possible" and to prioritise those fixes that will make the largest impact to organisational risk — a capability he calls essential in the face of Frontier AI–driven velocity.

Patch management's revolution and the uptime trade-offs

Patching must change in lockstep. Garvey describes a shift away from a calendar-driven cadence such as waiting for Patch Tuesday, toward an automated lifecycle of patch identification, testing, and deployment designed to match the speed of exploit development. He endorses a ring-based methodology: automation pushes patches outward to the next ring only after the prior ring has been validated for stability.

That acceleration, he cautions, forces hard conversations between patching teams, security teams, and business stakeholders. Historically, patch teams have been tasked with minimising availability disruptions and meeting uptime requirements; increased patching velocity may force a recalibration of downtime tolerances, greater investment in resiliency, and closer integration with BC/DR teams. These are described not as optional debates but as necessary, proactive choices to avoid an alternative of escalating incidents.

What this means for technologists and security teams, patch teams and BC/DR, and procurement leaders

  • Technologists and security teams: adopt exposure management practices that prioritise exploitability and business impact, and expand toolsets to include continuous monitoring, breach attack simulations, and automated pen testing rather than relying solely on CVSS/EPSS/KEV signals.
  • Patch management and BC/DR teams: prepare to implement automated, ring-based patching workflows and to renegotiate uptime and downtime commitments with business stakeholders; expect to engage more closely with resiliency planning.
  • Procurement leaders and enterprise decision-makers: evaluate whether existing VM and patching investments support rapid automation, exposure-based prioritisation, and the integrations needed for continuous validation — or whether a systematic upgrade is required to meet the Frontier AI threat.

Garvey closes with a practical, training-oriented next step: he will address these changes in SANS LDR516 course runs at SANS DC Metro (Sept. 28–Oct. 2, 2026) and SANS Dallas (Dec. 7–11, 2026), promising attendees "all of the necessary actions to take" upon return to their organisations.

Frontier AI, as characterised in the piece, is not merely a new source of research productivity — it is a force that compresses the time between discovery and exploitation and exposes structural weaknesses in how organisations prioritise and remediate risk. The prescription is systemic: exposure management to see true risk, automated ring-based patching to keep pace, and candid organisational trade-offs about uptime and resiliency. For those still planning gradual change, Garvey’s message is blunt: the time to revolutionise a vulnerability program is now.

Original story — The Hacker News