The images in this article were generated with artificial intelligence. How we publish
Just a few years ago, vulnerability management worked with a simple logic: to discover, prioritize by gravity, to patch and validate. This cycle rested on a temporary limitation: between the publication of a failure and its exploitation, weeks or months passed, sufficient time to organize patches and controls. Today, that limitation has almost disappeared. Artificial intelligence models and automated attack servers have compressed the time between discovery and explosion from months to hours, which makes it necessary to rethink the defence strategy from end to end.
Public reports and technical pieces have shown the magnitude of the change: AI researchers and companies have demonstrated the ability to find and, in many cases, generate evidence of the exploitation of thousands of failures in a short time. In parallel, malicious actors have industrialized the abuse of weak credentials and the automation of offensive tools in distributed infrastructure. The result is an uncomfortable equation: the attack now runs at machine speed while the business mediation processes remain human, slow and subject to maintenance and testing windows.

This asymmetry has practical and regulatory consequences. The risk frames and the Boards call for immediate patches; regulations begin to demand increasingly short response times. However, operational reality shows that ordering "faster parking" does not remove problems such as regression tests, change windows or impacts on availability. When the operation comes in hours and the patch takes weeks, the chance of a gap is triggered..
In this scenario, traditional metrics such as the CVEs list ordered by CVSS are no longer useful on their own. A lot of vulnerabilities rated as critical do not help if we do not know which ones are really accessible from the specific environment of the organization or if they are already neutralized by existing controls. The practical question that should guide the decisions is no longer "what is broken" to be "what the attackers can exploit against us right now and our defenses would detect or block it."
This is where in practical sense adversary simulation and exposure validation comes in: methodologies that run, against your systems and under controlled conditions, the real attack techniques and chains used by the adversaries. The Breach and Attack Simulation (BAS) platforms and the autonomous penetration tests allow to check whether the tools we have already deployed (EDR, WAF, IPS, SIEM) work as we believe and what real gaps remain.. It is not a passive scan: it is an active test aimed at measuring operational efficiency.
Validating controls on a continuous basis offers three specific benefits. First, make an avalanche of theoretical alerts a priority list of exploitable risks in your environment. Second, it allows to take advantage of previous investments by showing what mitigation is already working, which buys safe time to make patches without resorting to emergency changes. Third, when it detects a specific gap, it guides corrective actions to proven impact mitigation and verifies their effectiveness after applying the remedy.
However, defensive automation also requires safeguards. To ask generative models to write uncontrolled exploits or binaries can produce dangerous results: active malicious code, false positive that divert resources, or irrelevant tests that do not reflect real techniques. The practical response consists of architectures where the IA coordinates and composes tests from previously validated attack blocks, in safe test environments; the orchestra machine, but does not invent and execute harmful code in production without human filters and safety controls.
In terms of operational and governance, the transformation required by the new reality involves several simultaneous actions. First, to implement continuous adversarial simulation capabilities and autonomous tests integrated with IMS and orchestration platforms to close the detection cycle to remediation. Second, improve the visibility of the environment (inventory, endpoints and networks telemetry) so that priority is contextual and non-theoretical. Third, harden preventive and detection controls: MFA, credentials management, network segmentation and proven lock rules are now elements that allow you to buy time. Fourth, establish processes for validating venor-specific mitigation and automatically revalidate them after any change.

Organizations should also update their risk metrics. Valuation of actual adverse exposure, time for effective detection and rate of verified mitigation is more useful than counting outstanding CVEs. Also, the adoption of safe practices for the use of IA in security - curated test libraries, isolated testing environments and human reviews for exceptions - reduces the risk of creating useless or dangerous defenses.
The good news is that technology and practices already exist to adapt to this new speed of the offensive. To adopt a logic of continuous and automated validation of controls allows to transform the management of vulnerabilities: from a race to patching as soon as possible to a strategy based on evidence of real exploitation, mitigations that work and remediations that change the result. In order to deepen the techniques and frameworks of reference, public resources such as the MITRE ATT & CK framework ( MITRE ATT & CK) and sectoral reports showing operating trends and response times ( Verizon DBIR, AWS Security Blog).
The "blink window" era forces the defenses to automate and validate with the same speed as the attack. Parking is still necessary, but not enough: prioritizing by proven exploitation and validating controls in real time will be the difference between suffering a gap and containing it without impact. The effective safety today is to test, demonstrate and correct with evidence - and do it at the speed of the machine.
Related
More news on the same subject.

GitLab critical alert: emergency patch fixes CVE-2026-19478 allowing to modify or eliminate public projects without credentials
GitLab published an emergency patch on August 17, 2026 to correct critical vulnerability in its self-hosted software (Community and Enterprise Edition) which, under certain cond...

When the MCP server keeps your credentials: the silent attack vector of the IA in production
The incorporation of IA agents into business processes has opened a practical way for production systems and data to be accessible from models: it is called Model Context Protoc...

Critical alert: CVE-2026-58231 in SAP Commerce Cloud could allow remote code execution; patch and urgent mitigation
A critical vulnerability that affects SAP Commerce Cloud, registered as CVE-2026-58231 and with maximum score 10.0 on the CVSS scale, it is being exploited attempts shortly afte...

The massive purchase of expired domains drives fraud, malware and streaming pirate: the business behind the dropcatch
An intelligence report on DNS published by Infoblox and disseminated by specialized media confirms that criminals are buying large-scale expired domains - the so-called dropcatc...

HoneyMyte updates CoolClient with a signed kernel driver to hide processes and protect the C2 channel
Kaspersky has published an analysis that attributes to the actor known as HoneyMyte (also Mustang Panda) an updated version of the CoolClient backdoor that incorporates a signed...

GeoServer on zero-day vulnerability alert in jsonArrayContains with real risk of remote execution
The GeoServer open source project has a zero-day vulnerability that is being actively explored by attackers, according to researchers' public alerts and the watchTowr intelligen...

AmnesiaStealer MacOS malware that steals credentials and controls real-time browser sessions
Security researchers have documented a new malware family aimed at macOS - called AmnesiaStealer - that combines a dropper in shell, an infostealer written in Rust and a remote ...