The Exploit Window Has Collapsed to Zero
The article presents a stark thesis: the time between vulnerability disclosure and exploitation has collapsed from years to effectively zero, driven largely by AI. Using “time-to-exploit” (TTE) data, it shows a shift from 771 days in 2018 to hours in 2024 and zero-day exploitation in 2025, where attacks often occur before disclosure. The root causes are structural—bad economic incentives, flawed disclosure models, and inherent asymmetry between attackers and defenders. AI amplifies this imbalance by making exploit generation instant, cheap, and scalable, rendering traditional patch-and-defend strategies obsolete and forcing a fundamental rethink of cybersecurity.
Comments
Post a Comment