An analysis by Sila Ozeren Hacioglu, Security Research Engineer at Picus Security, published by BleepingComputer, argues that artificial intelligence is compressing the time between vulnerability disclosure and exploitation.
The analysis cites PaperCut NG and MF servers as an example. On August 27, PaperCut warned that attackers were already exploiting servers, despite there being no CVE, exploit, or patch. The first emergency patch arrived a day later but was bypassed the same day. A third patch arrived on September 1, leaving six days without a patch that held or a public exploit to test.
Disclosure-to-exploitation averaged 21.5 days last year, the analysis says, but weaponization now takes hours. In its hypothetical example, a security team finds 20 affected assets and has 15 minutes to determine whether they are exposed. The example uses the made-up CVE-2026-1001 to show that version data marked “affected” is not an answer.
Without a working exploit, the team maps the vulnerability to an attack chain covering delivery, execution, privilege escalation, injection, and credential access. At 08:30, controls including NGFW, WAF, endpoint hardening, EDR, and SIEM reveal gaps. By 08:45, fixes change the results to detected, blocked, blocked, alerted, and alerted. At 12:00, a reported campaign adds lateral movement, persistence, and exfiltration to the testing.
Comments
0No comments yet. Be the first to comment.