AI Is Shrinking the Time Between Bug and Break-In. Playbooks Haven't Caught Up.
Vendors are pitching AI-driven vulnerability tools like Mythos as the answer. The harder question is what defenders have been doing wrong for years.

Key points
- Security teams say the window between a flaw being disclosed and criminals exploiting it is shrinking, driven partly by AI tools that help attackers write working exploits.
- Mythos, an AI-assisted vulnerability platform being discussed across the industry, is one of several products claiming to help defenders keep up.
- Vulnerability management, the routine work of finding and fixing software flaws before criminals exploit them, has long suffered from a backlog problem, not just a speed problem.
- Patching every flaw is impossible for most organisations; the real fight is deciding which handful actually matter this week.
- Buying an AI tool won't fix a process that was already broken before AI showed up.
There's a conversation running through security teams right now. AI is making it faster for attackers to turn a newly published flaw into a working break-in. Tools like Mythos are being marketed as the counterweight. The vulnerability management playbook is due a rewrite.
That framing gets the question right. It doesn't answer it.
What is actually changing?
The time between a flaw being made public and criminals using it in the wild is collapsing. Where defenders once had weeks to test and roll out a patch, some flaws are now weaponised in days, occasionally hours. AI coding assistants can help an attacker turn a vague advisory into functional exploit code far faster than before.
This isn't hypothetical. Researchers have publicly demonstrated large language models producing working exploits from CVE descriptions, given the right prompting and access to vulnerable software. Our 23 July story "Can You Still Patch Your Way to Safety?" put that timeline at under a day.
So does the playbook need to change?
Yes, but not in the way vendors are selling it. The core failure in most vulnerability programmes isn't detection speed. It's prioritisation and follow-through.
A typical enterprise scanner flags tens of thousands of findings per month. The security team can't patch them all. They never could. What matters is whether flaws that are actively exploited in the wild, or trivially exploitable and publicly reachable, get fixed this week rather than next quarter.
AI can help sort that pile. It can't make a change-management board move faster, and it can't make a business owner agree to a Saturday reboot.
Where AI-assisted tools genuinely help
There are real gains on offer. Ranking flaws by likelihood of exploitation, drafting the internal ticket, summarising a vendor advisory into plain English for the team that owns the server: honest, useful automation.
The risk is treating the tool as the strategy. A company that couldn't patch a two-year-old flaw in its VPN before buying an AI platform won't suddenly patch it after.
What defenders should actually do
Start with the boring questions. Are your internet-facing systems inventoried? Do any run software the vendor no longer supports? Who, by name, owns patching responsibility for each one? When a critical flaw drops, how many hours pass before someone with authority to reboot production is in the room?
Most organisations can't answer these cleanly. That's the gap AI won't close for you. Worth noting: our 20 July piece "The Real Mythos Problem Isn't New Bugs" found that known flaws often sit unpatched on networks for far longer than anyone admits. That's a people-and-process failure, not a tooling gap.
| Playbook element | Traditional approach | What AI actually changes |
|---|---|---|
| Flaw discovery | Scheduled scans | Faster triage of scanner output |
| Prioritisation | CVSS score sorting | Exploit-likelihood ranking |
| Patch decision | Change board, weekly | Same board, same week |
| Response time | Days to weeks | Hours, if the process allows |
Common questions
Is AI making attacks faster than defenders can respond?
In narrow cases, yes. AI is speeding up exploit-writing, but most successful attacks still rely on unpatched flaws that have been public for months or years. That's a process failure, not a speed failure.
Should a small business buy an AI vulnerability tool?
Not as a first step. An accurate inventory of what it owns, automatic updates turned on, and a written plan for who patches what will deliver more security than any AI platform.



