{"slug": "ai-changed-the-exposure-problem-validation-needs-to-change-with-it", "title": "AI Changed the Exposure Problem. Validation Needs to Change With It.", "summary": "In the first half of 2026, 35,853 CVEs were published, roughly 49% more than the year before, but only 495 were catalogued as exploited in the wild, according to VulnCheck data cited in a Picus Security analysis. Anthropic's disclosure data shows Mythos-class models surfaced 26,153 vulnerability candidates in open-source software, with only 421 patched upstream, and Omdia research found that while 95% of organizations rank pentesting as a top or high priority, only 32% of their average attack surface is tested each year. Picus Security argues that CVSS severity alone cannot determine which exposures matter in a given environment, and that exploitability validation and security control validation are needed alongside automated pentesting to close the gap.", "body_md": "There’s a lot of noise around AI and cybersecurity right now. What’s actually important is far simpler, if often lost in the hubbub. **Vulnerability discovery is getting faster and happening at a much greater scale, while defenders still have to work out which findings actually deserve their action.**\n\nIn the first half of 2026, a whopping 35,853 CVEs were published, [roughly 49%](https://zerodayclock.com/) more than in the year before. Yet only [495 were catalogued](https://www.vulncheck.com/blog/state-of-exploitation-1h-2026) as exploited in the wild during that same period, and 116 were already under attack on the day they became public. Meanwhile, Anthropic’s own [disclosure data](https://red.anthropic.com/2026/cvd/ledger/) shows Mythos-class models surfacing 26,153 vulnerability candidates in open-source software, with only [421 of those](https://red.anthropic.com/2026/cvd/) getting patched upstream.\n\nThat small exploited subset is a very important point. It tells defenders that **treating every vulnerability with a High or Critical CVSS rating as an emergency is not only impossible, it’s actually the wrong model**. The critical task security teams face is **deciding which exposures, on which assets, require immediate action**, especially as both the number of findings grows and the gap between disclosure and exploitation narrows.\n\n## **The CVSS Alone Can’t Tell You What Matters in Your Environment**\n\nThe same CVE can affect hundreds of assets, but the **impact is rarely the same across them**. Some instances are unreachable. Some sit behind controls that interrupt the techniques required for exploitation. Others are exposed on business-critical systems where prevention fails, and detection never fires.\n\n**The CVSS gives you a common severity baseline. It can’t give you the context that determines impact to your organization.**\n\nThis is why defenders need evidence from their own environment to find out whether the exposure is actually exploitable, which assets it affects, and whether those assets are reachable and important to the business. As vulnerability volume grows, this distinction becomes more and more important.\n\n## **Automated Pentesting Alone Can’t Validate Every Exposure**\n\nOnce you move beyond severity scores, automated pentesting gives you some of the strongest evidence you can gather. It can run real exploits, prove that an exposure is exploitable in your environment, chain vulnerabilities, credentials, and misconfigurations into attack paths, and show how far an attacker could actually progress across your network.\n\nYet coverage remains limited in practice. [Omdia research](https://go.synack.com/ai-pentesting-report-omdia)**found that while 95% of organizations rank pentesting as a top or high priority, only 32% of their average attack surface is tested each year.** Agentic and automated approaches can expand that coverage, but they don’t remove every **constraint of live exploitation**.\n\n**For CVE-based exploitation, a working exploit still has to exist, and the target has to be safe to test.** Newly disclosed CVEs may have no working exploit yet, while it simply may not be possible to test a live exploit on business-critical, restricted, and air-gapped assets. Those exposures still need an exploitability verdict, even when there’s nothing an automated pentest can safely run.\n\nThis is the gap automated pentesting can’t close on its own. It’s **a required part of validation**, but **it can’t validate every exposure**.\n\n## **All for One. One for All Exposures.**\n\nThis is where the pieces come together.\n\n- **[Exploitability validation](https://www.picussecurity.com/platform/exposure-validation)** determines whether an exposure is, in fact, exploitable in your environment, including CVEs with no working exploit and assets that live exploitation can’t safely reach.\n- **[Security control validation](https://www.picussecurity.com/platform/breach-and-attack-simulation)** tests whether your prevention and detection controls actually block, detect, or miss the attack.\n- **[Agentic pentesting](https://www.picussecurity.com/platform/autonomous-penetration-testing)** safely runs real exploits and chains exposures to show how far an attacker can progress through your specific environment.\n\nThese methods answer different questions under different exposure conditions. **Mythos readiness requires all three capabilities, brought together in one platform with the same goal: validating exposures across your unique environment.** This doesn’t mean you have to always use all three against every exposure. The goal is to **apply each method where it fits best** and let the **evidence contribute to the same decision process**.\n\nThese three key pieces become even more powerful when they operate as one program. A **finding can trigger the validation step it actually needs**, **new evidence can change remediation priority**, and **fixes can be re-validated** instead of disappearing into a closed ticket. That keeps exploitability, control effectiveness, and attack-path evidence connected instead of leaving them to wallow in separate workflows.\n\nThis is also where [Gartner®’s May research](https://www.gartner.com/en/documents/7851581) note points: toward validated attack paths, decision-driven response, and exposure reduction all integrated into operational workflows.\n\nThis also happens to be the working model behind our **[Validation Summit ’26](https://hubs.li/Q04x66s80)**.\n\n## **What Security Experts See and How Leading Enterprises Put Validation Into Practice**\n\nOn October 14 and 15, Picus Security will host The Validation Summit ’26 to bring together an independent view of what’s changed, our approach to validation, and lessons from security leaders who’ve already put it into practice.\n\n**Mikko Hyppönen** will open with why this shift is different from past ones. **Picus CTO Volkan Ertürk** will then lay out what security validation needs to look like when attackers are powering their attacks with AI, and why exploitability validation, security control validation, and agentic pentesting work better together than on their own. The Picus team will then show the validation workflow **live with a newly disclosed vulnerability.** It starts with no patch and no working exploit, moves through validation before a PoC exists, tests the exploit against live controls once it appears, and then re-validates after the fix.\n\nThen security leaders from **Chanel, Atlassian, and the NFL** will discuss what this looks like inside real enterprise environments: how mature security teams are adapting their validation programs, what they’ve changed, and the successes and failures they’ve experienced along the way.\n\n**Two hours. One validation blueprint.** [Join us for the Picus Validation Summit ’26.](https://hubs.li/Q04x66s80)\n\nNote: *This article was written by [Sila Ozeren Hacioglu](https://www.linkedin.com/in/silaozeren/), Security Research Engineer at Picus Security.*\n\n[Google News](https://news.google.com/publications/CAAqLQgKIidDQklTRndnTWFoTUtFWFJvWldoaFkydGxjbTVsZDNNdVkyOXRLQUFQAQ),", "url": "https://wpnews.pro/news/ai-changed-the-exposure-problem-validation-needs-to-change-with-it", "canonical_source": "https://www.swapupdate.in/ai-changed-the-exposure-problem-validation-needs-to-change-with-it/", "published_at": "2026-09-14 13:27:40+00:00", "updated_at": "2026-09-14 13:46:23.437178+00:00", "lang": "en", "topics": ["ai-safety", "ai-policy"], "entities": ["Picus Security", "Anthropic", "Mythos", "VulnCheck", "Omdia", "CVSS", "CVE"], "alternates": {"html": "https://wpnews.pro/news/ai-changed-the-exposure-problem-validation-needs-to-change-with-it", "markdown": "https://wpnews.pro/news/ai-changed-the-exposure-problem-validation-needs-to-change-with-it.md", "text": "https://wpnews.pro/news/ai-changed-the-exposure-problem-validation-needs-to-change-with-it.txt", "jsonld": "https://wpnews.pro/news/ai-changed-the-exposure-problem-validation-needs-to-change-with-it.jsonld"}}