It's Launch Week at Axonius! Get Decision-Grade AI Context.

Read the Product Announcements

From vulnpocalypse to patchmageddon: security operations in the AI era

Ivan Dwyer

Principal Product Marketing Strategist, Axonius

JP Morgan’s latest Eye on the Market sounds the alarm for what danger AI poses to vulnerability patch cycles. The in-depth report surveys the new normal, where frontier models can discover vulnerabilities and weaponize exploits at a scale and speed never seen before. 

As an industry, we've watched vulnerability disclosures rise and exploit windows fall for years. Teams have been fighting it on every front: sharpening prioritization models, optimizing cross-functional coordination, building automated remediation workflows.

But that progress was made along the same linear growth path as the attack surface. We’ve always been neck-in-neck. AI completely changes the calculation. Bound by the laws of physics, there is simply no way teams operating under today’s conditions can absorb tomorrow’s impact.

But this assumes we’re taking these findings at face value. We can’t ignore the coming vulnpocalypse or patchmageddon or whatever the next Michael Bay movie is. But we can change the equation.

Why the volume war is unwinnable

attacker-time-to-exploit.png

Every AI headline says the same thing about speed and volume. The clearest visual from the JP Morgan report shows the time-to-exploit window dropping below zero and the time it takes to remediate growing along the same timeline. For a long time, those two trends were roughly at parity, making vulnerability management feel survivable. AI removed the thing that kept these trajectories linear in the first place: the slow, expensive work of discovering vulnerabilities and building working exploits. Take that limiter off, and the trajectories change course, widening the gap past the point of survivability.

This is already showing up in production. Anthropic’s Project Glasswing, and other efforts across frontier models, have demonstrated incredible abilities to discover vulnerabilities. And the previously manageable periodic patch updates from large software vendors like Microsoft and Oracle suddenly became record-breaking drops. Speed matters, but no security team on earth can triage thousands of patches from vendors in a single cycle just by resolving to move faster.

But when you ask the teams actually doing the work what stalls patching, the answers have little to do with pace. The JP Morgan report cites survey data that illustrates what holds teams back. You can’t patch faster than you can see, prioritize faster than you can rank, or prove a fix landed if you weren’t tracking it to begin with.

patch-delays.png

Contain risk with a common denominator

If we can’t beat explosive volume with pure speed, we have to change the calculation. But to what? Defense-in-depth starts with a common denominator, one that represents your total attack surface. 

Every individual asset carries a risk. And every individual exposure carries a risk. Measuring in isolation is another volume trap. Measuring against a common denominator gives you something to reason with.

AI changed decision-making. When patch timing was periodic, prioritization was purely ordering: which patch first, ranked by severity, against a window you controlled. There is no window anymore, decisions must now be as dynamic as the environments being protected.

common-denominator.png

Impact and reach are properties of the environment more than they are the finding. What the exposed host talks to, which credentials sit on it, whether controls are working, if the path extends to a business critical asset.

Defense-in-depth is largely about policies and controls. Every tool in your stack is there to do what it does and do it well. Endpoint security, network security, identity & access management, cloud security, vulnerability scanners all have a role to play in their respective domain. But none hold the common denominator.

Asset intelligence is reconciled at the collective, so you always have the common denominator of the full environment. Then any vulnerability, issue, drift, misconfiguration, gap, or violation is addressed with full context. 

The new calculation is dynamic containment. Humans and agents measure findings against the common denominator and make containment decisions in real-time. Security operations in the AI era runs on asset intelligence for exactly this reason.

"You can't calculate risk without a denominator. If you don't know your full attack surface, you can't tell leadership what percentage of assets are exposed or protected. What we needed was a way to understand what we have and how it contributes to risk. Axonius became that denominator.” - Kara Keene, Senior Manager of Attack Surface Reduction, TransUnion

Categories

  • Artificial Intelligence Ai
  • Threats Vulnerabilities
Get Started

Get Started

See how to make asset intelligence actionable with a guided demo:

  • Stop chasing data — work from one asset model your entire team can trust.
  • See what's exposed before it's a problem — surface coverage gaps automatically.
  • Turn alert noise into action — cut thousands of alerts down, to the ones that matter.