Skip navigation EPAM

Finding Vulnerabilities Is Getting Easier. Fixing Them Is the New Security Battleground

AI is rapidly expanding the supply of security findings. The advantage now belongs to organizations that turn those findings into engineering action and build the governance to operate at enterprise scale.

For years, cybersecurity operated on a familiar assumption: finding the vulnerability was the hard part. Once a flaw was known, the organization could assess it, queue it and fix it through established processes. 

That paradigm is now overturned.

Frontier AI is making vulnerability discovery faster, cheaper and more accessible. It can inspect more code, surface more potential weaknesses and explore possible attack paths at a speed no human team can match. This gives defenders a powerful new capability. It also gives attackers leverage they did not have before. 

The challenge goes beyond cybersecurity; it’s a test of whether enterprise AI foundations are built for production pressure. Becoming AI-native isn’t about any particular tool. It’s about enterprises building an operating model that can scale and adapt to continuous change.

The number of common vulnerabilities and exposures, or CVEs, is expected to double this year compared with last. Mozilla reportedly saw a 164% increase in first-quarter flaws compared with the same period the previous year. 

Yet volume is the wrong measure of progress. More findings do not automatically create more security. They can just as easily create more noise, more tickets and a larger backlog. AI-generated findings only matter if the organization trusts the system producing, filtering and routing them.

The new security battleground is not discovery. It’s remediation.

Good governance, including trust and transparency, are still key to any successful cybersecurity program, but AI has sped up the clock, offering new challenges alongside opportunities for cyber resilience at scale.

The Clock Has Changed 

According to Verizon's 2026 Data Breach Investigations Report, only 26% of critical vulnerabilities were fully remediated last year, and organizations took up to 43 days to do so. At the same time, attacker speed has been described as negative seven days, meaning exploitation may begin before public disclosure. Defenders are working on a 43-day clock while attackers are not working on a clock at all. 

Patch volume makes the mismatch harder to ignore. In July, Microsoft issued patches for 570 Windows security bugs, compared with 164 security flaws in April. Each of those patches needs to be understood, prioritized, tested and deployed across a real application estate. 

Most security programs can’t absorb that pace. They generate findings faster than engineering teams can close them and the exposure window widens with every unresolved finding.

A vulnerability that remains unresolved for six weeks exposes a vastly larger risk than it did a year ago. AI has changed the economics of time. Responsible AI —that understands governance as an enabler, not a blocker— provides the path to a resilient cybersecurity program. 

Detection Is Becoming Abundant 

The Mythos announcement put a spotlight on a shift already underway. In April, Anthropic announced Project Glasswing after its then-unreleased Claude Mythos demonstrated vulnerability discovery and exploitation capabilities that Anthropic described as exceeding all but the most skilled humans. 

Read More

Project Glasswing gave a limited group of major technology organizations early access to understand those capabilities before they became broadly available. Frontier-level vulnerability discovery was moving out of the lab and into operational use. 

The model attracts the headlines, but the model is not the strategy. Models will keep changing and today’s frontier capability will become tomorrow’s baseline. Buying access to a more capable model will not, by itself, create resilience. 

The durable advantage comes from the system around the model. We call that system the harness, and it defines what the model can examine, constrains how it operates, validates what it produces and routes confirmed findings into engineering workflows. A well-designed harness turns model output into controlled action. A weak one turns model output into another source of noise. 

Frontier models produce candidate findings rather than a clean remediation backlog. Each finding still requires application context, dependency context, exploitability analysis, business context and accountable ownership. Strip away that contextual layer and speed only pushes the bottleneck further downstream.

Precision Beats Volume 

In our own vulnerability-discovery work, roughly 10% of initial findings survive validation as confirmed true positives. The low rate does not mean the model failed, it means the harness did its job. 

The purpose of a well-constructed harness is noise reduction before it reaches engineering. The goal is a short, prioritized and actionable list that teams can move on quickly. 

Smart triage does the real sorting. Triage can’t stop at a severity score, it must combine technical confidence, exploitability, business impact, application criticality and remediation feasibility. That decision layer is what converts AI capability into risk reduction. 

Security leaders should be skeptical of any proposition measured mainly by the number of vulnerabilities found. Finding more is easy to demonstrate. Closing the right vulnerabilities faster is the outcome that matters. That ability to fix, validate and govern at machine speed is what makes AI trustworthy in production and allows enterprises to achieve value at scale. 

Security Must Move into Engineering 

Curl offers a useful counterpoint. The open-source tool represents more than 20 billion installations across smartphones, tablets, cars, televisions, video games and medical devices. After receiving early access to Mythos through Project Glasswing, a full source-code scan produced one confirmed vulnerability. Its founder and lead developer attributed that result to curl’s diligent, AI-assisted security program. 

Security must operate inside engineering —and in lockstep with governance— from design and threat modeling through validation, prioritization and remediation. Governance is what makes engineering action defensible, repeatable and scalable.

Secure by design means security systems continuously learn, scale and recover, so organizations leverage AI better than would-be attackers. When threats move at machine speed, security added at the end of the release cycle is structurally late.

We have seen the same principle at enterprise scale. At one large software company, scan volume increased 3.5 times without increasing the remediation backlog. 

An AI-native remediation factory applied automated triage and risk prioritization across 5,229 products. The program was estimated to save approximately 300,000 hours and $7.5 million in annual operating costs.

The most important outcome was not the scan volume, it was that the backlog did not grow with it.

The winners will not be the organizations that find the most vulnerabilities. They will be the ones that close the right vulnerabilities fastest.

This Is an Operating Model, not a Tool Purchase 

Adding an AI tool to conventional vulnerability management does not create AI-native cyber resilience. What does? An operating model built for continuous discovery, continuous exploitation and continuous change. 

Building the operating model is hard. Every layer must connect. An organization needs a current view of its applications, dependencies, ownership and exposure. It needs a trusted decision layer to separate signal from noise, governance that links technical risk to business priorities and engineering capacity to fix what the system confirms. 

Most organizations already have more findings than they can close. Adding a frontier model without changing the operating model can make that imbalance worse. Security teams do not need more output. Enterprises need the capacity to absorb it and turn it into action. 

Secure by Design: A Durable Operating Model that Scales 

Governance and security have become intertwined more than ever before. To build an operating model that will truly be resilient, first, establish a continuous view of the application estate. Know what you have, who owns it, what it depends on and where the exposure sits. Without that transparent governance foundation, prioritization is guesswork. 

Second, build the decision layer. Frontier models generate candidate findings, but candidate findings do not reduce risk. A controlled harness and smart triage validate results, eliminate noise and connect technical findings to exploitability, business impact and remediation feasibility. Without this layer, organizations simply generate more tickets. With it, they create a prioritized backlog that engineering teams can act on.

Third, expand remediation capacity. Measure success by exposure reduced, time to closure and backlog contained, not by the raw number of findings generated. 

In an AI-native threat environment, resilience belongs to organizations that can reduce exposure faster than it accumulates with a model designed to adapt. That engineering discipline means business readiness and conveys competitive advantage.