cvtoken.vip

Council Post: AI Is Commoditizing Vulnerability Discovery Faster Than Organizations Can Respond

Varun Badhwar is CEO & Co-Founder at Endor Labs. Previously, he built Prisma Cloud for Palo Alto Networks following the RedLock acquisition.getty​For years, application security has operated on a simple ass...

Varun Badhwar is CEO & Co-Founder at Endor Labs. Previously, he built Prisma Cloud for Palo Alto Networks following the RedLock acquisition.

getty

​For years, application security has operated on a simple assumption: If organizations could find vulnerabilities faster, they would become more secure. Artificial intelligence fundamentally changed that equation.​

Today, vulnerability discovery is accelerating at a pace few organizations could have imagined even a year ago. But while AI has made it dramatically easier to identify software flaws, it has done almost nothing to expand the industry’s capacity to understand, prioritize and remediate them. The result is a widening gap between what organizations know and what they can realistically fix.​

J.P. Morgan’s recent “Patchmageddon“ report offers one of the clearest illustrations yet of this shift. Drawing on research from Anthropic, Mozilla, Cloudflare and others, the report concludes that AI-assisted vulnerability discovery has moved from theoretical to operational. Models are finding zero-days at unprecedented speed, exploitation windows are collapsing and attackers increasingly have access to the same capabilities as defenders.​

Detection Is Table Stakes

One of the report’s most important observations echoes what we’ve always said: Detection is not the hard part. The report confirms that vulnerability discovery is no longer a scarce capability. AI systems are already identifying vulnerabilities at a pace that would have been difficult to imagine only a few years ago. History suggests that once a breakthrough capability becomes commercially viable, it rarely remains exclusive for long. Performance improves, costs decline and sophisticated techniques become broadly accessible. Vulnerability discovery is following that same trajectory.​

For years, organizations invested heavily in tools designed to uncover more vulnerabilities because discovery itself represented the primary challenge. Even before AI, the economics had shifted. The gap wasn’t finding; it was prioritizing and fixing. Finding vulnerabilities will remain important, of course, but it will no longer be the factor that differentiates mature security programs from everyone else.​

Prioritization is following a similar path. Modern AI systems can already correlate exploit intelligence, evaluate reachability, synthesize application context and explain likely business impact in seconds. Those tasks once required analysts to manually assemble information from multiple tools before making a decision. While human judgment remains essential, particularly for business context and risk acceptance, the mechanics of prioritization are becoming progressively more automated.​

That progression leaves one part of the application security lifecycle that refuses to become a commodity: remediation.​

Remediation Hasn’t Kept Pace

The more revealing stats come later, after maintainers review all those findings.​

According to the report, more than 1,400 vulnerability reports generated through Anthropic’s research were acknowledged by maintainers, with roughly a 90% validation rate. Only a small percentage had been patched during the reporting period. Additional research estimates that vulnerability discovery is now outpacing remediation by more than 16 to one.​

Those numbers point to a capacity challenge rather than an awareness challenge. The maintainers responsible for these projects understood the vulnerabilities existed and agreed they warranted attention. What they lacked was sufficient engineering capacity to remediate them as quickly as AI could identify them. That distinction has meaningful implications for enterprise security programs because it shifts the conversation away from improving visibility and toward improving execution.​

Unlike detection, remediation changes production software. Every proposed fix has the potential to introduce regressions, break dependencies or alter application behavior in ways that are difficult to predict. Fixing a vulnerability therefore becomes a high-risk engineering activity that requires testing, validation and confidence that the application will continue to function as intended after the change.​

Remediation also has an economic dimension that receives far less attention than discovery. AI can generate code changes, but every iteration consumes compute, engineering review and increasingly AI tokens. Safe remediation often requires multiple attempts, automated testing and human validation before code is ready to merge. Finding a vulnerability produces information. Remediating one requires changing software that businesses depend on every day. Those are fundamentally different problems, and only one of them scales cleanly with additional AI capacity.​

Security Needs To Operate Alongside Development

The implications extend beyond vulnerability management. Traditional application security programs were designed around review gates that software needed to clear before deployment. That model evolved when code was written primarily by humans and vulnerability discovery occurred at a pace organizations could reasonably absorb. AI has changed those functions entirely.​

Software is being produced more quickly, vulnerabilities are being identified more rapidly and developers are expected to maintain that velocity. Meeting those expectations requires security to operate as a continuous source of intelligence throughout the development process. Developers need timely context about which findings matter, why they matter and how to remediate them safely without slowing delivery. The organizations that adapt to this model will be better positioned to maintain both development speed and security outcomes as AI continues reshaping software engineering.​


Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?