In the past, unearthing security vulnerabilities was a matter that sorely tested one’s patience. Some flaws would be discovered before the developer had fixed them, and the security researcher would report the vulnerability to the developer, granting time for a remedy. In return, the developer would offer the researcher a bounty, encouraging them to keep hunting flaws and improving product security.
Many hackers, meanwhile, would wait until after the developer released a patch, then unearth vulnerabilities by analyzing the code within that fix. Once they found a usable method of exploitation, they could launch attacks against systems that had not yet installed the update. Analyzing patch code to uncover an exploitation method likewise tested one’s patience. In the age of artificial intelligence, however, hackers no longer need any such patience.
Just 15 Minutes After a Patch, Hackers Can Build an Exploit
In its recently published cybersecurity assessment, the EU Agency for Cybersecurity (ENISA) warns that frontier AI models have compressed the vulnerability-weaponization window to a mere 15 minutes. That is, within 15 minutes of a security patch’s release, hackers can enlist an AI model to analyze the flaw and find the corresponding method of exploitation. The finding appears in ENISA’s assessment of cybersecurity in the frontier AI era.
ENISA stresses that automated systems are accelerating every phase of the attack lifecycle, from initial reconnaissance to data theft. The median time of the attack cycle now stands at 72 minutes. This may render traditional, human-managed patch cycles obsolete: manual management and installation of patches may simply come too late, and hackers, aided by AI, may launch attacks while the flaw remains unfixed.
In the Security Lifecycle, Humans Become the Bottleneck
Frontier AI models can chain together multiple low-severity vulnerabilities by analyzing application logic, configurations, and API access. This also renders the risk scoring of isolated vulnerabilities misleading, since several flaws chained together may inflict far graver harm.
In the report, ENISA also notes that the accelerated pace of vulnerability discovery creates an authorization gap: the time required for an IT administrator’s approval process exceeds the time an attack script needs to establish persistence. In essence, because AI can discover and exploit vulnerabilities in so short a span, humans have become the bottleneck within the security lifecycle.
To counter these swiftly evolving threats, ENISA recommends that enterprises shift resources from endless vulnerability discovery toward priority-assessment systems, such as the Exploit Prediction Scoring System (EPSS) and the Vulnerability Exploitability Exchange (VEX). IT administrators, meanwhile, should rigorously enforce asset inventories and set their detection-and-response targets at single-digit-minute levels.
Support Our Threat Intelligence
If you find our technology report and cybersecurity news helpful, consider supporting our work.