{
  "id": 11700377,
  "title": "AI is speeding up exploits. Vulnerability spreadsheets can’t keep up.",
  "url": "https://urgent.news/2026/10/03/ai-is-speeding-up-exploits-vulnerability-spreadsheets-cant-keep-up",
  "topic": "ai",
  "section": "AI",
  "published": "2026-10-03T14:00:00.000Z",
  "source": {
    "name": "The New Stack",
    "slug": "the-new-stack",
    "url": "https://thenewstack.io/cve-vulnerability-risk-management/"
  },
  "original_language": "en",
  "account": "Artificial intelligence has transformed almost every facet of software development and cybersecurity, with one of the most profound changes occurring in the way organizations manage software vulnerabilities. Traditional vulnerability-management models, which involve scanning software, identifying Common Vulnerabilities and Exposures (CVEs), assigning severity scores, and prioritizing findings for remediation, have remained relatively unchanged for years. These methods, while not perfect, have become increasingly inadequate in the era of AI.\n\nThe issue lies not only in the growing number of vulnerabilities but also in the rapid acceleration of software production, the speed at which vulnerabilities are being discovered, and the shrinking time required to develop exploits. Furthermore, AI-enabled attacks can exploit vulnerabilities in ways that are difficult to anticipate manually, leading to a widening gap between the number of vulnerabilities security teams can identify and those they can effectively investigate and remediate.\n\nRather than focusing on the sheer number of CVEs, organizations should shift their attention to which vulnerabilities pose meaningful risk to their environment. Severity scores, as provided by systems like the Common Vulnerability Scoring System (CVSS), do not accurately reflect the likelihood of exploitation, the vulnerability's exposure, or its execution path within a specific environment. Two organizations with identical CVEs in their environments may face vastly different risk levels based on their security posture.\n\nThe rise of AI is also accelerating the economics of exploitation. With more code being developed and a greater reliance on open-source components, organizations face an expanding attack surface. AI-powered attackers can rapidly generate exploits, further exacerbating the situation. As a result, organizations cannot afford to rely on manual, time-consuming vulnerability triage processes.\n\nTo improve vulnerability management, organizations must prioritize reducing the number of vulnerabilities entering their environments in the first place. This begins with the software foundation, utilizing hardened or curated base images and libraries to minimize the vulnerability footprint. Static Application Security Testing (SAST) and AI-assisted code scanning can help address first-party code vulnerabilities, while security configuration frameworks like Security Technical Implementation Guides (STIGs) can identify and remediate configuration weaknesses, which are equally important in ensuring software security.\n\nUltimately, security leaders should recognize that production environments represent the source of truth, and should focus on continuously assessing what is actually running in production. Production scanning, reachability analysis, and environmental context are essential for identifying vulnerabilities that may have been missed during development and addressing configuration weaknesses to strengthen overall software security.",
  "summary": "Artificial intelligence has changed almost every aspect of software development and cybersecurity. But perhaps one of the most profound changes The post AI is speeding up exploits. Vulnerability spreadsheets can’t keep up. appeared first on The New Stack .",
  "key_points": [],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}