AI is creating exploits faster than we can patch them

AI News


In production technology environments with long patching timelines, the velocity of AI-developed exploits poses significant risks to critical infrastructure.

The most important detail in recent reports about the VoidLink Linux malware framework is how quickly it was built.

An AI-assisted Linux malware project grew to nearly 90,000 lines of code in a matter of days. This will push security leaders, infrastructure operators, and policy makers all on that path. Not because the malware is new, but because the economics and timelines of exploit development have changed.

AI is now creating exploits faster than we can patch them.

This impact is especially severe for systems that cannot be updated quickly or regularly. For example, many operational technology environments are designed for long lifecycles and infrequent updates. These were never built to absorb rapid patch cycles. If artificial intelligence can help create exploit paths in days, but patch cycles take months, it leaves a structural imbalance of risk.

This is of great concern to anyone responsible for systems that cannot be patched overnight or at all.

Patch gaps are now a systemic risk

In traditional IT environments, speeding up exploit development is risky enough. In OT, embedded systems, and critical infrastructure, this is much more serious.

Industrial systems are not designed for rapid patching. Patch cycles are measured in months, not days. Downtime is unacceptable. Verification is slow. In some cases, a vendor may disappear, the hardware may freeze, or the software may no longer be supported and updates simply don’t exist.

Contrast this reality with AI-accelerated exploit development. When new exploit paths are generated in days and defenders need quarters to respond, we are dealing with a growing structural gap.

No amount of vulnerability scanning and patch prioritization will close this gap.

Addressing inevitable vulnerabilities

Vulnerabilities cannot be completely eradicated, especially in long-lived embedded systems and industrial control environments. When creating exploits becomes cheap and automated, attackers can iterate faster than defenders can react.

Successful exploits can be adapted and expanded over time. Once an exploit works reliably, it can be reused across different devices, products, components, and contexts. AI not only accelerates the discovery of vulnerabilities, but also the refinement and reuse of exploit techniques.

Defenders need to break that cycle. How can we prevent exploits if patching can’t keep up?

Rather than relying on patching, organizations should move toward architectural controls that reduce exploit reliability, limit reuse, and limit post-exploit impact.

Designed for a world where patching is competitive

Protecting critical infrastructure requires designing defenses that complement patching and achieve asymmetric changes in resiliency.

That is, assume there is a possibility of compromise and focus on:

  • Prevent successful exploitation of large classes.
  • Reduces the portability of exploits across systems.
  • Limit the operational impact when vulnerabilities are inevitably discovered.

It is necessary to assume that some vulnerability will be discovered and exploited, and to limit the actions an attacker can take once they have established a foothold. That means robust segmentation, least privilege architecture, controls that isolate critical functionality, and runtime exploit prevention to protect your software. If you wait for the perfect patch, you’ll always be late.

AI has forever changed the balance of attack and defense in cybersecurity. While the speed advantage favors attackers, defenders can change their strategies to defend against systems built in a different era.

The organizations that adapt will be the ones that accept this reality early and redesign their defenses accordingly. Those that don’t keep track of patches while the attacker moves on to the next automatically generated exploit.

AI is creating exploits faster than we can patch them. If we are serious about protecting the systems on which modern society depends, that statement should guide our strategy, investments, and urgency.

Joe Saunders Founder and CEO of RunSafe Security and Chairman of Ask Sage.

Copyright © 2026 Federal News Network. Unauthorized reproduction is prohibited. This website is not directed to users within the European Economic Area.





Source link