AI Broke Vulnerability Management. That's Why CISOs Are Moving Budget to BAS.
13:30 · June 11, 2026 · Hacker News AI Section

For thirty years, vulnerability management ran on a buffer: the months between when a vulnerability was found and when someone could figure out how to weaponize it. The solution was straightforward enough; triage by severity, schedule the fix, validate, and move on. The buffer was what made that work. Today, that buffer is gone. AI didn't make your team slower. It changed the other side of the
Summary
AI has compressed the once-substantial interval between vulnerability discovery and exploit availability from months to roughly 24 hours on average in 2026, down from about 53 days two years earlier. Models such as Anthropic’s Claude Mythos Preview have demonstrated the shift by surfacing more than 10,000 high- or critical-severity issues in a single month and generating 181 working exploits against Firefox alone, compared with two from an earlier model. Similar automation now lets attackers industrialize credential abuse and port tools across environments without zero-day code, as shown in an AWS threat-intelligence case that identified hundreds of compromised devices across dozens of countries.
Traditional vulnerability management, built around CVSS-based triage and scheduled patching, cannot absorb this volume or pace. Even high-performing organizations remediate only 30–40 percent of known-exploited vulnerabilities within the first week, while remediation itself requires regression testing, change windows, and uptime commitments that cannot be compressed arbitrarily. Verizon’s 2026 DBIR data indicate that 32 percent of initial-access incidents already stem from vulnerability exploitation, a share expected to rise as AI coding tools lower the barrier for less-skilled actors.
In response, many CISOs are reallocating budget toward Breach and Attack Simulation platforms that run adversary techniques against live controls to determine what is actually reachable and blockable in a given environment. These tools replace severity-score lists with evidence of whether specific attack chains would succeed or be detected. When paired with autonomous validation that matches fresh threat reports to pre-vetted test cases, BAS operates at machine speed rather than human cycle times, allowing teams to confirm control effectiveness and prioritize remediation where it materially reduces risk instead of chasing every disclosed flaw.
Why it matters
This article is highly relevant for security professionals as it highlights a critical shift in the threat landscape driven by AI, specifically the rapid weaponization of vulnerabilities. It provides actionable insights for Dutch CISOs and security teams to adapt their defensive strategies and tooling, such as adopting BAS, to maintain robust security postures against AI-accelerated threats.










