AI Is Collapsing the Vulnerability Patch Window
### AI Vulnerability Management Gets More Urgent
AI vulnerability management is becoming a priority as attackers move faster after disclosure. In this Techstrong TV conversation, Mike Vizard talks with Andrew Obadiaru, CISO at Cobalt, about why the gap between vulnerability discovery and exploitation is shrinking.
Obadiaru says the change is already visible. More vulnerabilities are being reported. More exploits are active. Patches are also getting larger and more complex. AI is adding pressure because attackers can use it to accelerate research, automate steps and target more assets across cloud environments.
### Scheduled Patch Cycles Are Under Pressure
Traditional patching models were built for a slower environment. Many organizations still rely on scheduled patch cycles. That rhythm no longer matches the speed of modern attacks. When AI and human judgment are combined, exploitation can happen before teams finish normal testing and rollout routines.
That does not mean every patch should be rushed into production without review. It does mean security teams need better visibility into risk. They need to know which assets are exposed, which vulnerabilities are exploitable and which issues create the greatest business impact.
### Continuous Testing Becomes More Important
Obadiaru points to continuous penetration testing and authoritative asset inventory as important steps. Security teams need real-time insight into internet-facing systems and cloud assets. They also need a practical way to validate whether a vulnerability can actually be exploited.
AI vulnerability management is not just about scanning faster. It is about connecting discovery, validation, prioritization and remediation. That helps teams avoid wasting time on low-risk findings while attackers chain smaller weaknesses into more serious threats.
### Security Teams Need a New Response Model
The conversation also explores the changing role of CISA advisories, remediation deadlines and security leadership. Advisory models are evolving as agencies push for faster action. CISOs now need to balance urgency, testing and operational resilience.
For enterprise teams, the takeaway is clear. AI is changing the vulnerability timeline. Organizations that improve asset visibility, adopt continuous testing and modernize patch response will be better positioned to close the exploitation gap.
Transcript
Hey guys, thanks for the intro. We're here with Andrew Obadiaru, who is the CISO for Cobalt, and we're having a chat about, well, we've been talking about this vulnerability apocalypse for a couple of months now, I think, and if you look around, it's starting to happen. I think we're starting to see more exploits that are active.
We're starting to see more reports of vulnerabilities, and well, the patches are getting bigger than ever. So there's something happening here. The question is, how big is it going to get and for how long?
Andrew, welcome to the show. Thank you very much, Mike, and thanks for having me. My pleasure.
So what's your assessment and where are we right now? Because I kind of feel like everybody's been waiting for a shoe to drop and maybe it has dropped and it's just not dropped everywhere yet. That is a good assessment.
It has dropped. So it hasn't dropped everywhere, but it's already creating challenges across the board. And what we are observing and noticing is that the gap is starting to close between discovery or disclosure and exploitation.
And all of that is easily attributed to the increased adoption of AI and leveraging AI in how attackers carry out their attacks against not just internet-facing asset, but a number of assets across a cloud-based structure. So if you look at the recent KVI advisory from CISA, it kind of emphasized some of those concerns. And I've been following CISA, Mike, for I would say close to 10 years now, and we've never seen a situation where a release focuses on three different or four different environments at the same time addressing the same sort of vulnerability.
That's definitely new. Whether you are looking at the Microsoft piece or the Apple or the VMware, all of them, it's really driving to the point you made that the environment is changing. We're starting to see the effect of it.
Even before all this, we were kind of falling behind on the exploits were starting to show up faster than the patches. So is that going to continue to be the case or do you think we can close that gap? I expect it'll be the case, unfortunately.
The introduction of AI combined with human judgment makes patching cadence a lot more difficult the way we know it today. The organizations that are still running scheduled patch cycles operate on a kind of timeline that is no longer consistent or matches the way attackers behave today because all of them are leveraging AI. So the cadence as we know today is obviously not going to stand the test of time.
I think the CISO or the security practitioners that recognize that and take measures to mitigate some of that to the extent that it can, are the ones that will win this fight. But to your point, this is happening and it's happening at a very rapid pace. We haven't seen anything like this before.
Whether you're talking about Mithos or you're talking about these other different, anybody now can do stuff with the use of AI. So that creates a level of challenge, not just the discovery part of it. How quickly can those vulnerabilities be exploited leveraging AI coupled with human judgment?
And that makes it a lot more challenging for security practitioners. Are we going to just apply the patch and maybe skip the testing? What will be the process?
Because we're kind of in a rush when it comes in, and historically, the patch would come in and we kick it around for a while. We wait to see if somebody else deployed it and see if it broke anything, and then we might have gotten around to it in a couple of weeks or sometimes months. How is all that going to change?
It's going to change. Just patching is no longer sufficient. I think having some kind of continuous visibility is really the way to go, where there's continuous pen testing, and it gives you a real-time ability to evaluate all of your internet-facing assets and the true status of those assets, whether they are exposed or there's a vulnerability in place or can this actually be exploited?
And the only way you can make that identification is not waiting for something to happen, and you try to apply the patches to it. It's for you to continuously run this pen testing, and that's the only way today as I evaluate all of this, and that gives you a real-time insight. And the other measures you can take from a testing perspective, something that is done on a continuous basis is really the way to go because these things are moving so fast.
If you wait for traditional approaches to it, you're just going to miss the ball. But continuously running a loop of testing is really what gives you that level of insight. Well, even so, it seems like some folks are coming to the conclusion that the cure is not necessarily worse than the disease anymore because they were afraid of the patch.
" And it's just that the whole thing now is going to happen at machine speed. That's the thing. Most organizations don't have those capabilities to move at machine speed.
You can identify it, you can discover it, but you have to have the team and the capability to match that pace. So I think it's easier to destroy something than to fix it. So when you're coming up with ways to compromise an environment versus trying to prevent that from happening, I think it's a different set of skill set.
So leveraging AI on one hand, I think is a lot easier. Even the tools that we look at today, the tools out there, nothing is able to move at that same pace from a remediation standpoint. So I think it goes back to my initial point, autonomous testing, continuous pen testing.
I think having that discovery at least you know what's happening. It gives you the ability to put mitigating measures in place as you look to finally remediate this issue. But if you don't know, I think it becomes a lot more challenging for you as an organization.
" Does that ring a bell? Absolutely. How will the relationship between the security teams and the application development teams evolve as we kind of close this loop and we move down this path?
Because historically, there's always been a lot of tension. " But now I think the bad guys are daisy-chaining small, low-level vulnerabilities together to create more lethal ones, and at the same time, they're exploring legacy AppSec that are full of technical debt and discovering vulnerabilities that we didn't even know existed. So how does this conversation change?
That is, I think, the nail on the head. The ability to string a series of small vulnerabilities together to create a big one is where the challenge is. And you're able to do that with AI, in ways that you couldn't have been able to do before.
So in terms of that relationship with DevOp teams versus security, that tension remains. But I think there's an increased awareness now what that is because some of these developers are also leveraging AI for code development, so they understand what's possible. In the past, it was more like a phantom idea where you articulate a risk to them, they just say, "Oh my God, this is not possible.
" But today they understand. In some levels they are sort of like the ethical folks of it, so there are folks that can also take advantage of that. So I think from that perspective, why that tension still exists.
But there is an understanding that we have to recognize this risk. We have to work closely with our security partners and to address this risk. Now, how does that work out without creating bottleneck in the process becomes a challenge.
Where is the sweet spot? How do we work in a concerted effort to address this issue? But yes, that tension certainly still exists.
But it's also there's a wide level of recognition that something needs to be done, and the environment we live today is nothing like where we were many years ago prior to the increased adoption of AI and leveraging AI for all of these cybercrimes. Now, I think CISA and other agencies are moving down a path where they're trying to mandate- Remediations in three days, I mean, two hours. Is that feasible?
And what will it take to get there? It's not feasible. There are some cases I would say 24 hours, and some organizations already have that in place.
But where you are going against the kind of force we have today, and those levels of remediation are difficult, right? You don't remediate what you don't know, right? If you don't even know what level of internet or external-facing assets that you have, how do you go about reacting to a CISO advisory?
I think the first thing I would recommend, in addition to taking that advisory, but also do an authoritative asset inventory of your internet-facing assets, right? Knowing, I think, is the first step. And then, taking steps to run this series of pen tests against them to determine what's exploitable and where does the vulnerability actually exist.
So regardless of what CISO is saying, if you don't know where your assets reside, or which assets are exposed, which assets are susceptible to these types of vulnerabilities, you won't know how to react to it, right? You don't want to wait to the release of a KEV, and then you start trying to run all kinds of discoveries to see whether this technology even applies to us in the first place. And if it does, is it exposed to these types of issues?
So I think the key for me is to do that authoritative external asset inventory, and to first find out what you have, and then take the next step. Whether you're taking the advisory from CISO or you're doing your independent set of activities to ensure that all of these assets are, one, identified, owned, they're still relevant to you, how critical are these assets? What are they storing?
What are they doing? They no longer need it, get rid of them. What is the future of penetration testing going to look like?
Because it used to take quite a while, but we all saw what happened with OpenAI and Anthropic releasing these rogue AI agents. And while that was unfortunate, it also maybe is the kernel of a good idea, because am I going to take a bunch of AI agents and turn them loose on my enterprise to discover where all my weaknesses are? That is true.
Well, pen test, as we know, it has obviously evolved tremendously. We go through a lot of that here. There are PTAS, and there's autonomous testing, there's AI-driven testing, so there's a ton of different tests that are being done today leveraging AI to speed up the pace at which these pen tests are being deployed.
Not only how quickly you can deploy these tests, but also the identification of the assets, the scoping of those assets, and how quickly you can really do all of that identification. So, using AI, LLMs, as a foundation to piece some of these tests certainly does help. But I think, having human in the middle, human involvement, brings a level of expertise and judgment to the process that AI in itself just cannot do.
There are some organizations that are still locked into place 100% reliance on just AI. So having a combination of human judgment or human expertise, with machine speed and AI competencies, I think that helps a lot to get quicker to where you need to get to. " Well, the folks that are close to this enough are taking steps to mitigate some of the issues, right?
There's still some organizations that are so far off and waiting for things to happen. But every day, I'm seeing organizations recognize this as a legitimate risk, and they're looking for ways to leverage AI through multiple different ways. Whether it's building up different MCPs, different agents in your environment to help with your SOC operations, using AI to manage all of your pen test work, working closely with organizations like ours to deploy autonomous testing, AI-driven, AI-managed testing, and all of these different types of AI you can use to accelerate the pace at which you identify these vulnerabilities.
I think the organizations that take that approach certainly gets ahead of it. But the ones that are still kind of buried in the weeds and trying to figure out whether this is even applicable to them or not, I think those are the ones that are more susceptible to some of these issues. I think at this point, attacks are all but inevitable.
So the question I have is, are we going to maybe wait for a couple of cataclysmic events before everybody gets on the bus, or are we going to maybe suffer death by a thousand cuts for two years before we all get our act together? I think it's probably the latter, right? So, I think folks are taking steps.
I think the organizations that consider themselves to be critical elements of the organization, whether you are in the pharmaceutical space, you're in the financial space, you are in the manufacturing space, you're in the software development space, I think whether it's a compliance-driven effort or it's just something that you feel that you can't afford to have your environment compromised, the organizations that think like that are the ones that are taking the set up an issue measures to identify what we have out there, what assets are susceptible, and then how do we mitigate this risk, right? So if you recognize that folks are using AI to accelerate attacks, how do I combat that? What do I do?
Give me a fair share or a fair position in terms of being able to meet these types of challenges. And those organizations that, to the extent they can, are going to get ahead of some of this. But I think the first thing is to recognize that this is a legitimate risk, and what do I have to do to mitigate that?
Tons of organizations already have thousands of applications, some then half of that internet-facing, and those are the ones that are really, really worried about how do we deal with these kinds of challenges. So they're reaching to organizations like Cobalt and other organizations that are really expert in this field in terms of not just the identification of it, but also deploying the right set of tools to help you continuously look at these assets from a vulnerability standpoint. What should the role of the government be in all of this?
Because it seems like, you follow CISA pretty closely, but there seems to be still a lot of debate about should they just be advisory, more proactive? What is the right stance, do you think? I think we can do more.
The Europe governments are certainly doing a lot more than we are doing here. The CISA is definitely a good start, but they can take a higher position or a tougher stand. But certainly, CISA is a good start, and they're compelling folks to take this seriously.
Now it's no longer state-sponsored type situation. Before, it was only state-sponsored type vulnerability that they tend to focus in on. But the pace that some of these attacks are happening, and the technological advancement they're deploying, some organizations are just not equipped to operate in isolated cases.
So having a concerted effort from a government standpoint certainly would help. And I think CISA, I think they recently changed their leadership. But I think now they're taking much more of an aggressive position and to put some of these things out there.
I think that's great. I would also encourage a lot of organizations to take, if you're not subscribed to CISA, certainly do that. There's a lot of information you can get out of that.
But yeah, the government can definitely do more, and just from the perspective of cyber infrastructure, but also putting policies in place, building up our infrastructure in ways that we're not exposed to some of these crazy attacks. Is this kind of evolving into, we see drones out there, and we see swarms of drones, and they get launched back and forth at each other, and well, one way to think about this is the adversaries are going to launch swarms of AI agents, and the good guys are going to have swarms of AI agents to thwart them. Is this how that going to play out?
Well, ultimately, that might end up being what happen, right? So, the good guys are looking for ways to leverage AI and to fortify the environment. And the bad guys are doing the same thing.
How can we leverage AI to compromise these environments? So it's going to be that kind of situation, right? We expect that good is always going to overcome evil or bad because these guys have, their intentions are different.
But the challenge is these people have no parameters to go by, and they have no compliance requirement. They have no kind of threshold. They have no regulatory anything to worry about.
They're just out there looking for destruction, as I stated at the start of this. It's easier to cause damage than to fix, right? If I'm looking to compromise an environment, I think it's a lot easier than trying to prevent that from happening.
So I think for most organizations, it's no longer if, but it's just a question of when, right? So I think the key is to understand when your environment has been compromised, and so you can take immediate steps to mitigate that effect. But I think it's the idea of wanting to prevent it altogether, I think that's almost impossible now.
All right, my friends. Hey, the Chinese have one of those interesting proverbs. " Well, here we are.
Andrew, thanks for being on the show. Michael, it was a pleasure. Thank you so much for having me.
All right. And back to you guys in the studio.