Businesses are moving beyond an initial focus on faster patching in response to surging vulnerability discovery by frontier AI models and are increasingly rethinking how to identify and reduce security exposures in a broader way, according to Accenture’s Jason Lewkowicz in a report by CRN.
The advent of advanced AI models like Anthropic’s Claude Mythos and OpenAI’s GPT Cyber has accelerated the discovery of software vulnerabilities, leading to a significant increase in disclosed flaws. Microsoft's September security update, for example, included over 900 patches, a stark contrast to previous months. Initially, the industry's response focused heavily on accelerating patching efforts, a strategy Lewkowicz described as "whack-a-mole." However, the consensus is shifting towards a more comprehensive approach to exposure management.
This evolution involves customers reconsidering their security programs to address recurring issues and demonstrate ongoing effectiveness. Consequently, there's a growing interest in strategies such as continuous threat exposure management (CTEM), attack surface identification, penetration testing, and offensive security. While rapid patching remains crucial, the broader objective now encompasses reducing the volume of vulnerabilities and ensuring the long-term viability of security programs.
Source: CRN