87% of exploited bugs are attacked on disclosure day, up from 23% in 2020, as AI collapses the patch window
cyb3rops · x · 2026-09-07
Security researcher matrosov cites a16z data showing the window to patch software bugs is collapsing: 87% of bugs hackers actually exploit are now attacked on or before the day they become public, versus 23% in 2020.
His core argument:
- Legacy appsec was built for a threat model where humans had days to think: pre-generated heuristics (rules, SAT/SMT solvers) or fuzzing harnesses found issues, humans understood the problem first, defined a fix path, then scaled remediation.
- AI-driven attacks remove that luxury—discovery and remediation must now happen almost simultaneously.
- Pointing AI agents at existing security tools doesn't fix this; ineffective mitigations neither stop AI attackers nor buy time.
The takeaway: AI is breaking the foundational assumption of application security, and defenses need to operate at machine speed.
Related event: a16z: 87% of Exploited Vulns Attacked Same Day as Disclosure(4 posts)→
More from AGI Musings
- Lex Sokolin: A graveyard of early attempts is rarely proof the thesis was wrong — LexSokolin · 2026-09-07
- Researchers publish blog post on anthropomorphism in AI explanations — Dr_Atoosa · 2026-09-07
- OpenAI shut down video gen over economics — tokenomics dictates what models are for — felpix_ · 2026-09-07
- Geoffrey Hinton admits he was wrong about AI replacing radiologists — and explains why — Afinetheorem · 2026-09-07
- Open Offices Were Onto Something — But They Need Mature Ambient Compute to Work — curious_vii · 2026-09-07
- Ex-xAI researcher Ethan He: finding the right axis to scale matters more than raw compute — ricklamers · 2026-09-07