Enterprises are facing an urgent need to rethink their vulnerability management strategies due to the accelerating pace at which vulnerabilities are being exploited. Security experts assert that organizations must pivot towards a model of “just in time” patching to mitigate risks effectively.
As cyber attackers increasingly leverage AI technologies, traditional methods for managing vulnerabilities may no longer suffice. The shift enabled by advanced tools has led to a spike in exploitation rates, compelling security professionals to rethink their operational frameworks.
According to Muhammad Yahya Patel, a virtual Chief Information Security Officer (vCISO) and cybersecurity advisor at Huntress, organizations should transition to a risk-based, continuous vulnerability management framework. “This approach must be connected to real-time exploitation intelligence rather than relying on scheduled patch cycles, which tend to leave open windows for exploitation lasting days or even weeks,” he highlighted in a recent interview.
AI's Impact on Vulnerability Discovery
The emergence of frontier AI tools like Claude Mythos has brought about significant changes in vulnerability discovery, prompting government security agencies like the UK’s National Cyber Security Centre to suggest a coming wave of patches. However, Andrew Woodford, CTO at Titania, pointed out that many organizations already struggle to resolve known vulnerabilities in a timely manner. A surge in AI-accelerated discovery risks overwhelming these teams and widening the gap between identification and resolution.
Experts like Shane Fry from RunSafe Security believe that the vulnerabilities management process has faced challenges for years. AI has merely escalated these issues. While some advocate for virtual patching—where security measures block attempts to exploit vulnerabilities—Fry cautions that this strategy has its limitations. “Virtual patching can help, but it isn't a catch-all solution and leaves security teams racing against an ongoing issue,” he states.
To address the intrinsic weaknesses in current vulnerability management practices, experts suggest employing mitigation-first strategies to prevent attackers from exploiting software bugs altogether. Fry argues, “By removing vulnerable exploit classes early, organizations can shift patching from a reactive measure to a strategic element of security.”
The Limitations of Conventional Patching
The traditional model of patch management is no longer viable in a landscape where vulnerabilities are discovered almost instantaneously. Rik Ferguson, VP of security intelligence at Forescout, emphasizes a critical point: “If offensive AI can quickly identify, validate, and exploit vulnerabilities, then the typical 43-day median patch time is merely the tip of the iceberg.”
Ferguson proposes an “Assume Autonomy” approach, where organizations need to implement compensating controls to limit what attackers can accomplish after an initial breach. “The real challenge is establishing protections between discovering a vulnerability and remediating it,” he explained. Just-in-time patching should theoretically support this approach by prioritizing urgent fixes as threats emerge. Yet, for many organizations hampered by lack of asset management proficiency, achieving this ideal can be daunting.
Virtual Patching in Practice
Gunter Ollmann, CTO at Cobalt, points out that while just-in-time patching is advantageous when a patch is readily available, various realities complicate this ideal. Often, organizations encounter vulnerabilities in systems they lack the right to modify. In such cases, reliance on third-party solutions introduces delays dictated by external service level agreements.
Virtual patching emerges as a possible solution, providing much-needed capabilities to block or deflect exploits targeting vulnerable assets. However, Ferguson notes that while virtual patches can serve as compensating controls, they come with caveats, such as requiring accurate detection signatures and potentially fostering a false sense of security that forestalls proper remediation. Risks abound if temporary solutions become normalized, allowing underlying vulnerabilities to persist.
Just-in-Time Risk Reduction
Douglas McKee from Rapid7 advocates for what he terms just-in-time risk reduction, distinguishing it from the tricky concept of just-in-time patching. “In real-world scenarios—especially with critical systems in operational technology or healthcare—you often can’t deploy patches immediately upon a CVE release,” he explained. The need for thorough testing and meticulous planning remains paramount.
Modern Strategies for Vulnerability Management
The swift expansion of the enterprise attack surface necessitates a transition from traditional patch management models to continuous monitoring frameworks. Moving forward, vulnerability management must integrate real-time intelligence to prioritize threats effectively. Ferguson emphasizes the need for holistic visibility across the entire asset inventory, something that older tools simply weren't equipped to handle.
As security teams redefine their priorities, they must differentiate between “known vulnerable” assets and those that are “reachable and exploitable” within their environments. This can be accomplished through comprehensive asset inventories, vulnerability intelligence, and strategic prioritization based on risk factors such as public exposure and known exploitability.
In summary, the necessity for a dynamic and responsive approach to vulnerability management has never been clearer. Organizations must quickly adapt to ensure their defenses align with the realities presented by sophisticated cyber threats.