AI Broke Vulnerability Management. That's Why CISOs Are Moving Budget to BAS.
AI has compressed exploit development from months to hours, overwhelming patch-first vulnerability programs and pushing CISOs toward BAS for real-world validation.
Intelligence analysis by GPT-5.4 Mini
The piece argues that the old vulnerability management model depended on a long gap between finding a flaw and seeing it weaponized. With AI shrinking that gap and flooding teams with disclosures, the article says security leaders are shifting budget toward BAS to test what is actually exploitable and detected.
It’s like a house where burglars used to need days to make a copy of the key, but now they can do it in hours. The article says checking every lock on a list is not enough anymore, so teams are using BAS to see which doors really open and which alarms really work.
Analysis
The old model no longer has time
For years, vulnerability management worked because defenders had breathing room. A flaw would be disclosed, teams would triage it, and the likely weaponization window was long enough to patch before attackers could reliably use it. The article says AI has removed that cushion. Discovery-to-exploit is now described as a matter of hours, not months, which means the traditional patch queue can lag behind real attacker pace.
AI is increasing both discovery and exploitation
The article points to Anthropic’s May 2026 update, saying Claude Mythos Preview and about 50 partners found more than 10,000 high- or critical-severity vulnerabilities in a month. It also cites a Firefox test in which the model reportedly produced 181 working exploits, compared with 2 from the previous frontier model, and notes that more than 99% of those findings were still unpatched at the time. On the attacker side, it references an AWS threat-intelligence report about a campaign that used weak credentials and autonomous offensive tooling rather than zero-days.
Why patch speed is not enough
The piece argues that telling teams to patch faster does not solve the bottleneck. Patches still need testing, change windows, approvals, and uptime safeguards. It cites Verizon’s 2026 DBIR saying the median fix time for known-exploited vulnerabilities was 43 days, up from 32, and that fully patched coverage fell from 38% to 26%. When offense moves in hours and remediation moves in weeks, exposure remains.
Why BAS gets the budget
The article’s core claim is that vulnerability severity lists are too blunt when everything looks critical. BAS is presented as the better control point because it runs real adversary techniques against live defenses and shows what is blocked, detected, or missed. In that framing, BAS helps teams answer the more useful question: what is actually exploitable in this environment right now, and would current controls stop it?
Key points
- AI has shortened the gap between vulnerability discovery and real-world exploitation.
- The article cites more than 10,000 high- or critical-severity findings from Claude Mythos Preview in one month.
- Verizon’s 2026 DBIR is used to show that remediation is still measured in weeks, not hours.
- BAS is presented as a better way to test whether vulnerabilities are actually exploitable in a specific environment.
- The argument is that defenders need to prioritize real attack paths, not just severity scores.
If BAS is adopted well, security teams can spend less time chasing every scary-looking flaw and more time fixing what attackers can really use. That could make defenses more practical, especially when patching cannot keep up with AI-driven offense. It may also help companies prove that some risks are already contained by existing controls.
If organizations treat BAS as a replacement for patching rather than a complement, known flaws may still pile up behind the scenes. The article also suggests that even with better validation, remediation will remain slow because testing, approvals, and uptime constraints do not disappear. That means attackers may still find windows where defenses lag behind disclosures.



