cd /news/artificial-intelligence/you-can-t-out-patch-ai-you-can-out-r… · home topics artificial-intelligence article
[ARTICLE · art-77574] src=censys.com ↗ pub= topic=artificial-intelligence verified=true sentiment=↓ negative

You Can't Out-Patch AI. You Can Out-Reduce It.

AI advances have broken the traditional security model of patching vulnerabilities fast enough, according to a new analysis. Anthropic's Mythos, though not publicly available, demonstrates that LLMs make it dramatically easier to uncover and exploit software flaws, and open-source models lag frontier models by only 4-6 months. The 2026 Verizon DBIR found vulnerability exploitation became the #1 initial access vector into enterprises, accounting for 31% of breaches, a 55% year-over-year increase, while median time-to-patch rose 34% to 43 days and only 26% of CISA Known Exploited Vulnerabilities were fully remediated in 2025. The analysis argues that organizations cannot out-patch AI attackers and must instead focus on attack surface reduction—minimizing Internet-exposed assets through asset management, network segmentation, and exposure hygiene.

read5 min views1 publishedJul 28, 2026
You Can't Out-Patch AI. You Can Out-Reduce It.
Image: Censys (auto-discovered)

For two decades, defensive security has rested on the assumption that we can patch systems fast enough when vulnerabilities are disclosed. The model assumed that severe software vulnerabilities are relatively scarce and expensive to find, and that security teams have a reasonable window to react once a flaw goes public. Recent AI advances have altogether broken this model. Anthropic Mythos showed that LLMs make it dramatically easier both to uncover vulnerabilities in software and to build working exploits to target them. While Mythos is not publicly available, open source models have lagged frontier models by only 4-6 months: it’s only a matter of time until attackers have the same capabilities. This evolution will dramatically shrink both the cost and knowledge needed to uncover software vulnerabilities in Internet attack surfaces.

Implications for Defenders #

While today’s security model was already beginning to show cracks, the worst has yet to come. As attackers gain access to more sophisticated models, enterprises will be facing:

  • Greater number of vulnerabilities on their Internet attack surface;
  • Less time to respond to patch each vulnerability; and
  • Less time to contain a breach once an adversary gains initial access.

These are not distant projections. The 2026 Verizon DBIR found that vulnerability exploitation has already become the #1 initial access vector into enterprises, accounting for roughly 31% of breaches. This represents a 55% increase year over year, and the first time exploitation has beaten phishing and stolen credentials in the report’s history. Meanwhile, defenders are falling behind: median time-to-patch rose 34% from 32 days to 43 days, and only 26% of CISA Known Exploited Vulnerabilities were fully remediated in 2025, down from 38% the year prior.

AI-Driven Solutions #

AI will eventually help defenders block attacks against their Internet infrastructure in real time—but that day has not yet arrived. A model that finds bugs in source code will help us write more secure software, yet most of what enterprises run today was written years or decades ago. The systems meant to block attacks in real time are not yet dependable enough for production in most environments. For now, advances in AI capabilities help attackers more than they help defenders.

Attack Surface Reduction #

With exploitation of Internet-facing assets now the leading way into organizations and attackers able to exploit these Internet assets at record speeds, External Attack Surface Management has never been more critical. But organizations cannot win by simply responding to new vulnerabilities faster — that is a losing race. The most meaningful investment that organizations can make to protect themselves against AI-enabled attackers is reducing what those attackers can target.

The answer today to AI-driven attacks is a return to the basics: asset management, network segmentation, and exposure hygiene. The default must flip from exposing things unless there is a reason not to, to exposing nothing unless there is a strong reason to and a commitment to maintain and monitor it in real time. The priority has to be reducing Internet exposure so that only a small number of Internet-facing assets for which the security team needs to maintain perfect hygiene. Organizations need to focus their work on what’s Internet-facing to begin, considering:

  • What assets do we have publicly exposed?
  • What software and hardware is regularly found vulnerable and regularly exploited? Which parts of our expose are regularly showing up on CISA KEV and other vulnerability intelligence sources?
  • Which public-facing assets are most important to the business or would enable lateral movement into critical business operations?

Some systems have to be reachable from outside, and the goal there is to shrink how exposed. A spectrum of approaches exists, trading off transparency to users against how much surface remains visible to an attacker. Identity-aware proxies, such as Cloudflare Access or Zscaler Private Access, sit in front of an application and require the user to authenticate before any request reaches the backend, so the service is never directly addressable and every connection is tied to an identity. Broader zero trust network access platforms apply the same principle across whole sets of internal applications, replacing flat VPN access with per-application, identity-checked sessions.

Further down the stack are approaches that make a service invisible until a user proves who they are. Single-packet authorization and modern descendants like Knocknoc keep a service behind a default-deny firewall and only open a path to it, often just for that user’s IP and only for a limited window, after the user authenticates through an existing identity provider, preventing pre-authentication exploitation. For legacy systems, management interfaces, OT and ICS networks, and contractor or third-party access, where patching is slow and the software has a long history of bugs, this kind of just-in-time allowlisting collapses the attack surface to near zero without forcing a full re-architecture.

Censys Attack Surface Management #

Reducing your attack surface is only as effective as the discovery underneath it, and incomplete discovery means you are shrinking the exposure you can see while leaving the rest wide open. Most organizations operate with dangerous blind spots — Censys estimates that many organizations are unaware of up to 80% of their external attack surface — and every unknown asset is an open door to attackers leveraging AI. Organizations then need to prioritize taking systems offline that pose the greatest risk to their business. This is precisely where traditional tools fall short.

Censys ASM closes this gap and provides a blueprint for how to meaningfully reduce your attack surface, finding 65% more assets than competitors and prioritizing risk that needs to be addressed as attacks increase in speed and frequency. In an era where AI is compressing the time from vulnerability to exploit, Censys surfaces assets up to 6x faster than any other ASM solution and enables prioritization based on what services are being attacked in practice.

Censys Attack Surface Management

Most ASM tools infer your attack surface from DNS records and stale, external signals.

Censys maps the global Internet across all 65K ports to show what attackers actually see.

── more in #artificial-intelligence 4 stories · sorted by recency
── more on @anthropic 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/you-can-t-out-patch-…] indexed:0 read:5min 2026-07-28 ·