AI shrinks vulnerability exploitation window to one day, raises cyber risks: J.P. Morgan
Artificial intelligence is rapidly finding software flaws, which attackers exploit quickly. The time between vulnerability disclosure and exploitation has narrowed significantly. Organisations struggle to patch discovered weaknesses before they are compromised. AI can also bolster defenses by suggesting code fixes and remediation. Businesses must prioritize swift software updates and patch…
Artificial intelligence is transforming the cybersecurity landscape, allowing for faster discovery and exploitation of software vulnerabilities, according to a report by J.P. Morgan Asset & Wealth Management. The study warns that the gap between when a vulnerability is disclosed and when it is exploited has shrunk dramatically to just one day, leaving companies with minimal time to respond to cyber threats.
This zero-day event poses significant risks, as malicious actors, such as ransomware operators, terrorists, and hacktivists, could leverage AI capabilities to quickly exploit newly discovered vulnerabilities.
The report highlights that while AI models like Mythos and GPT 5.5 are improving the ability to detect previously unknown software vulnerabilities, they could also be exploited by malicious actors. Despite patches being available in 60% of breaches, companies often fail to respond in time. In 2025, the global cyberattack rate increased by 18%, with approximately 75,000 attacks occurring every hour. Phishing remains the primary attack vector.
The cybersecurity professional shortage is exacerbating the situation, with a global deficit of nearly 4.8 million professionals. AI models can now detect thousands of previously unknown vulnerabilities at scale, leading to a surge in zero-day vulnerabilities. Within the first month of testing advanced AI systems, more than 10,000 high- and critical-severity zero-day vulnerabilities were identified, many of which were not present in public vulnerability databases.
Furthermore, attackers can reverse-engineer software patches within minutes using AI, quickly developing working exploits. The report projects that the median time to exploit a vulnerability could decline further to just one minute by 2027. However, AI can also enhance cyber defenses, as the same tools used for detection and exploitation can propose code fixes and remediation. Security-focused AI tools from companies like Anthropic and OpenAI are being developed to address this growing threat.
Written by urgent.news from Economic Times Tech's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.