LIVE · cybersecurity feed
Live wire
vulnerability managementhigh

When AI-Accelerated Discovery Outruns Patching, Exploitability Proof Decides What Gets Fixed First

The increasing speed at which AI models discover software vulnerabilities, particularly in open-source components, is outpacing the ability of organizations to patch them. This necessitates a shift in risk prioritization, focusing on exploitability rather than just severity scores. An industry coalition called Athena aims to accelerate the defense of open-source software, while tools like those from Qualys help organizations identify which discovered vulnerabilities are actively being exploited and require immediate attention.

zeroday.news · 24d ago

The rapid acceleration of vulnerability discovery, particularly through AI-powered tools, is outpacing the ability of organizations to patch them, creating a critical need to prioritize remediation efforts based on actual exploitability rather than theoretical severity. This challenge is being addressed by the Athena coalition, an industry initiative launched by Chainguard to coordinate defenses for open-source software. Qualys, a cybersecurity solutions provider, has joined this coalition, bringing its expertise in validating whether vulnerabilities can be exploited in real-world environments.

The volume of identified vulnerabilities has become a velocity problem, with AI models discovering novel flaws in open-source software at an unprecedented speed. In its initial weeks, the Athena project processed tens of thousands of findings, with a significant portion categorized as critical or high severity. However, the true exposure can be even greater, as AI can chain together lower-severity vulnerabilities to achieve critical outcomes like unauthenticated remote code execution, which might not be apparent from individual CVSS scores.

Research indicates that vulnerabilities are often weaponized before patches are even available, with mean time-to-exploit sometimes being negative. Data from over 10,000 organizations shows a substantial increase in closed vulnerability events between 2022 and 2025, yet the proportion of critical vulnerabilities remaining open after seven days has also risen. This suggests that simply discovering more vulnerabilities, without a corresponding improvement in remediation effectiveness, leads to an accelerating backlog.

A key issue highlighted is the discrepancy between vulnerability severity and actual exploitability. Less than one percent of vulnerabilities labeled as critical are ever exploited in the wild. Many remediation queues are filled with theoretical issues flagged by scanners based on version matches with CVEs, without considering factors like code path reachability, service exposure, or existing protective controls. This leads to wasted engineering resources on non-exploitable flaws while genuinely dangerous ones languish.

Furthermore, a growing number of real-world exposures lack a CVE identifier, making them invisible to traditional scanning tools. Some findings within Athena relate to packages that are over five years old, where vulnerabilities may have been silently fixed upstream without any formal record. Attackers do not rely on CVEs, and defenders are increasingly finding themselves at a disadvantage by depending solely on them.

Qualys aims to bridge this gap by providing validated exploitability information. Their TruConfirm technology is designed to confirm whether a vulnerability is actively exploitable on a specific asset. This is achieved through safe, non-destructive validation methods that mimic attacker techniques without deploying malicious payloads. Examples include triggering benign callbacks or obtaining read-only response signatures that confirm code execution.

The goal of this validation process is to provide concrete proof of exploitability, enabling remediation teams to act with confidence and auditors to verify actions. This transforms raw vulnerability intelligence into actionable decisions tailored to an organization's specific environment. When Athena identifies a vulnerability under embargo, Qualys can provide customers with confirmed information about its exploitability within their systems, along with details on existing compensating controls.

Validation does not replace patching but rather informs and prioritizes it. In scenarios where time-to-exploit is extremely short and patch deployment takes weeks, knowing precisely which exposures are live is crucial. This allows organizations to implement interim controls, schedule patching based on business needs, and subsequently verify that the vulnerability has been successfully closed.

The Athena coalition, with its focus on accelerating the discovery and fixing of open-source software vulnerabilities, and Qualys, with its capability to validate exploitability and provide environmental context, represent a coordinated approach to modern cybersecurity challenges. This partnership aims to move beyond simply receiving alerts to making informed, validated decisions that reduce actual risk before attackers can exploit them.

vulnerability managementaiopen sourceexploitabilityrisk prioritization
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]

security

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]

security

BGP ORIGIN attribute manipulation and its impact on the Internet

By doing in-depth testing, we found nearly 70% of BGP paths experience ORIGIN attribute rewrites by transit providers seeking traffic advantages. We examine the global impact of this practice and argue for deprecating ORIGIN in route selection.

security

Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry

The new British prime minister is retaining Liz Lloyd in a cyber policy role, making her one of the few Keir Starmer allies remaining in government.

security

'Wrench' attacks against crypto holders appear to be on the rise

There are more reports than ever before of strong-arm tactics like home invasions and kidnappings against cryptocurrency holders, researchers say.

vulnerability

Microsoft blames massive Microsoft 365 outage on maintenance bug

Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services. [...]