AI Is Cutting the Time Attackers Need to Exploit a Flaw. Defenders Haven't Caught Up.
Security vendor Picus argues defenders can no longer wait for public exploits or vendor fixes before acting.

Key points
- AI is cutting the gap between a flaw being disclosed and criminals exploiting it, according to Picus Security.
- Defenders who wait for a public exploit or a vendor patch are increasingly arriving too late.
- Picus recommends exploitability validation, control testing, and autonomous penetration testing as practical responses.
- The pitch lands as security teams already struggle to triage thousands of flagged vulnerabilities each month.
The old rhythm of vulnerability response, wait for a patch, wait for proof-of-concept code, then scramble, is breaking down. That's the argument from Picus Security, a control-validation vendor, in a piece first surfaced by BleepingComputer. Their claim: attackers using AI are closing the gap between disclosure and exploitation faster than most defenders can react.
It's a vendor pitch. But the underlying trend is real, and worth walking through in plain terms.
What is a zero-day, and why does the timing matter?
A zero-day is a software flaw that attackers know about before the maker has issued a fix. The name comes from the idea that defenders have had zero days to prepare. Once such a flaw is public, a race begins: the vendor rushes a patch, criminals rush an exploit, defenders try to install the fix before they're hit.
Historically that race played out over weeks. Picus argues it's now compressing into days, sometimes hours, because attackers can use AI to read an advisory, understand the vulnerability, and produce working attack code far faster than before. That compression isn't hypothetical: our coverage of Microsoft's September 2026 patch release found two flaws already being actively exploited at the moment the fix arrived, and SonicWall's VPN zero-days in early September were being paired together in live attacks before most teams had even scheduled a maintenance window.
What is Picus telling defenders to do?
Stop waiting. That's the short version. The company recommends three practices that assume a patch may not arrive in time.
Exploitability validation means shifting the question from "is this vulnerability present?" to "can it actually be reached and abused here, given our specific configuration?" Most vulnerabilities a scanner flags aren't reachable from outside. Knowing which ones are lets teams focus where it counts.
Security control testing means running safe, simulated attacks against your own defences to see whether the firewalls, email filters, and endpoint tools you already pay for would catch the technique in question. Buying a product isn't the same as it working on the day.
Autonomous penetration testing, software that continuously probes an organisation the way a human attacker would, replaces the once-a-year manual pentest most companies still rely on.
The three approaches at a glance
| Practice | What it answers | Why it matters now |
|---|---|---|
| Exploitability validation | Can this specific flaw be reached and abused in our environment? | Cuts a long vulnerability list down to what an attacker could actually use |
| Security control testing | Would our existing defences stop the attack? | Catches gaps between what a tool promises and what it does |
| Autonomous pentesting | Where would a live attacker get in today? | Replaces annual snapshots with continuous checking |
Should ordinary businesses care?
Yes, at least in principle. Small and mid-sized organisations rarely have the staff to run any of this in-house, and they're the ones most exposed when a patch takes a week to test and deploy. If AI's trimming the attacker's development time from days to hours, the practical answer for a small IT team is unglamorous: assume you'll be late to patch, and make sure the layers around the flaw are actually working. Omdia research we reported on 31 August found 88% of organisations plan to increase offensive-security spending for exactly this reason.
One honest caveat: Picus sells tools in exactly these categories, so the framing isn't neutral. That doesn't make the observation wrong. Multiple incident-response firms have said the same thing this year.
The judgement from this beat: vendors calling this a "post-mythos era" are overselling the phrase, but they're right that the calendar has moved. Treat every high-severity advisory as if an exploit already exists, because increasingly, one does.



