The cybersecurity math just broke. According to Mandiant’s M-Trends 2026 report, the average time-to-exploit now sits at minus seven days. Adversaries are weaponizing vulnerabilities a full week before vendors ship the patch. The median enterprise takes 43 to 55 days to deploy that same patch across its environment, per the latest Verizon Data Breach Investigations Report.
That is not a gap. That is a chasm. And it changes what defense actually means for any cyber security program built on a patch-first posture.
“Attackers are successfully weaponizing and exploiting vulnerabilities a full week before a vendor compiles and ships a patch.” — Vlad Korsunsky, CTO, Tenable
Frontier Models Broke The Cybersecurity Patch Cycle
For years, time-to-exploit was shrinking in a way that still gave defenders a fighting chance. 63 days in 2018. 32 days by 2022. Painful, but workable if your team had its act together. Then 2023 broke the trend. By 2024 the window went negative, and it has stayed there.
The reason isn’t mysterious. Frontier LLMs now perform vulnerability research at a scale that was science fiction two years ago. Anthropic’s Opus 4.6 surfaced more than 500 zero-days in widely deployed open-source software in February. Its successor model uncovered thousands more across operating systems, browsers, and cryptographic libraries, and chained low-severity logic flaws into end-to-end exploits with an 83 percent autonomous success rate.
The same automation is showing up in evasion. Dark Reading reported this week that attackers are running Python harnesses to test malware against Sophos, CrowdStrike, and Microsoft Defender, iterating each payload until it slips past every agent. Producing EDR-resistant malware used to require a senior offensive engineer with weeks of patience. Now it costs a script and a credit card.
The campaigns keep landing. A Chinese-speaking crew expanded into Europe this week deploying a previously undocumented Atlas backdoor against new targets, building on the same playbook of fast iteration and quiet persistence. None of this requires a state actor with infinite resources. It requires a laptop, an API key, and a target list.
Defense In Depth Stops Being A Buzzword
If the patch will not arrive in time, every other layer has to do more work. That is the actual definition of defense in depth, and most organizations have been treating it as a slide in a board deck rather than an operating model.
Verizon’s 2026 DBIR data is the gut check here. Vulnerability exploitation drives about 30 percent of initial access. The other 70 percent comes from misconfigurations, identity flaws, exposed services, and unforced human errors. The dry fuel sitting inside your network is what catches when an AI-driven hacking agent shows up looking for an ignition point.
That reframes the prioritization question. Patching faster will not save you on its own. Threat detection coverage on identity surfaces, brute-force controls on every authentication endpoint, firewall segmentation between internal zones, and credible incident response rehearsal will. The point is to make the post-exploit blast radius small enough that a one-week pre-patch window does not equal a full compromise.
Microsoft’s June updates lean into this. The company expanded MDASH, its multi-agent vulnerability discovery system, and shipped controls for governing AI agents and detecting compromised models before deployment. Useful tooling. The operational discipline still has to come from your team, and no vendor announcement substitutes for actually running the playbook.
Seven Things To Run This Quarter
Concrete, tool-agnostic steps that work in any environment. Pick the ones you have not done.
- Inventory your real attack surface. Edge appliances, exposed admin panels, forgotten cloud assets, shadow SaaS. The thing you have not catalogued is the thing that gets exploited before the patch ships.
- Move prioritization off raw CVSS. Use KEV, EPSS, and exploitability context to drive remediation order. A static severity score in a vacuum tells you nothing about your environment.
- Shrink session lifetimes and enforce MFA everywhere. Stolen credentials and long-lived tokens are still the cheapest initial-access path. Pair this with brute-force protection and IP-based rate limiting on every login surface, including internal ones.
- Segment east-west. Assume initial access happens. Make lateral movement noisy, slow, and bounded. Host firewalls and internal ACLs buy minutes you do not have otherwise.
- Baseline egress and alert on first-seen destinations. Most post-exploit activity phones home somewhere new. A simple first-contact alert catches more real intrusions than another EDR rule.
- Rehearse a pre-patch incident. Tabletop a scenario where a vulnerability is being exploited and no vendor patch exists. Who has authority to take systems offline? Who talks to legal? Who tells customers? Find the gaps now, on a quiet Tuesday, instead of at 2am.
- Treat identity infrastructure as Tier 0. Your IdP, your secrets manager, your CI/CD tokens. If any of these compromise, the patch cadence is irrelevant.
The uncomfortable truth is that security hardening and operational hygiene now matter more than vendor patch velocity. The attackers know it. The Mandiant numbers prove it. The defenders who close the gap will be the ones who stop treating the patch cycle as their primary control and start treating it as one layer among many.
Your patch window closed seven days ago. The question is what else you have running in those seven days.
Sources
- Tenable CTO Q&A: C-suite views AI as massive threat
- Attackers Use AI to Automate EDR Evasion Testing
- Chinese hackers use new Atlas RAT malware in European cyberattacks
- Microsoft responds to security challenges facing code, AI agents, and models
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
