Urgent.News

What's breaking now, across thousands of outlets.

AI

AI is speeding up exploits. Vulnerability spreadsheets can’t keep up.

Artificial intelligence has changed almost every aspect of software development and cybersecurity. But perhaps one of the most profound changes The post AI is speeding up exploits. Vulnerability spreadsheets can’t keep up. appeared first on The New Stack .

AI is speeding up exploits. Vulnerability spreadsheets can’t keep up.

Artificial intelligence has transformed almost every facet of software development and cybersecurity, with one of the most profound changes occurring in the way organizations manage software vulnerabilities. Traditional vulnerability-management models, which involve scanning software, identifying Common Vulnerabilities and Exposures (CVEs), assigning severity scores, and prioritizing findings for remediation, have remained relatively unchanged for years. These methods, while not perfect, have become increasingly inadequate in the era of AI.

The issue lies not only in the growing number of vulnerabilities but also in the rapid acceleration of software production, the speed at which vulnerabilities are being discovered, and the shrinking time required to develop exploits. Furthermore, AI-enabled attacks can exploit vulnerabilities in ways that are difficult to anticipate manually, leading to a widening gap between the number of vulnerabilities security teams can identify and those they can effectively investigate and remediate.

Rather than focusing on the sheer number of CVEs, organizations should shift their attention to which vulnerabilities pose meaningful risk to their environment. Severity scores, as provided by systems like the Common Vulnerability Scoring System (CVSS), do not accurately reflect the likelihood of exploitation, the vulnerability's exposure, or its execution path within a specific environment. Two organizations with identical CVEs in their environments may face vastly different risk levels based on their security posture.

The rise of AI is also accelerating the economics of exploitation. With more code being developed and a greater reliance on open-source components, organizations face an expanding attack surface. AI-powered attackers can rapidly generate exploits, further exacerbating the situation. As a result, organizations cannot afford to rely on manual, time-consuming vulnerability triage processes.

To improve vulnerability management, organizations must prioritize reducing the number of vulnerabilities entering their environments in the first place. This begins with the software foundation, utilizing hardened or curated base images and libraries to minimize the vulnerability footprint. Static Application Security Testing (SAST) and AI-assisted code scanning can help address first-party code vulnerabilities, while security configuration frameworks like Security Technical Implementation Guides (STIGs) can identify and remediate configuration weaknesses, which are equally important in ensuring software security.

Ultimately, security leaders should recognize that production environments represent the source of truth, and should focus on continuously assessing what is actually running in production. Production scanning, reachability analysis, and environmental context are essential for identifying vulnerabilities that may have been missed during development and addressing configuration weaknesses to strengthen overall software security.

Written by urgent.news from The New Stack's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at thenewstack.io →

More in AI

Why Philosophers Are Worried About AI

Debate over artificial intelligence has largely focused on whether machines could become too powerful. Harvard philosopher Michael Sandel argues that a more immediate question is whether AI changes…

More from Saturday 3 October →