AI Is Collapsing the Vulnerability Patch Window
18m
### AI Vulnerability Management Gets More Urgent
AI vulnerability management is becoming a priority as attackers move faster after disclosure. In this Techstrong TV conversation, Mike Vizard talks with Andrew Obadiaru, CISO at Cobalt, about why the gap between vulnerability discovery and exploitation is shrinking.
Obadiaru says the change is already visible. More vulnerabilities are being reported. More exploits are active. Patches are also getting larger and more complex. AI is adding pressure because attackers can use it to accelerate research, automate steps and target more assets across cloud environments.
### Scheduled Patch Cycles Are Under Pressure
Traditional patching models were built for a slower environment. Many organizations still rely on scheduled patch cycles. That rhythm no longer matches the speed of modern attacks. When AI and human judgment are combined, exploitation can happen before teams finish normal testing and rollout routines.
That does not mean every patch should be rushed into production without review. It does mean security teams need better visibility into risk. They need to know which assets are exposed, which vulnerabilities are exploitable and which issues create the greatest business impact.
### Continuous Testing Becomes More Important
Obadiaru points to continuous penetration testing and authoritative asset inventory as important steps. Security teams need real-time insight into internet-facing systems and cloud assets. They also need a practical way to validate whether a vulnerability can actually be exploited.
AI vulnerability management is not just about scanning faster. It is about connecting discovery, validation, prioritization and remediation. That helps teams avoid wasting time on low-risk findings while attackers chain smaller weaknesses into more serious threats.
### Security Teams Need a New Response Model
The conversation also explores the changing role of CISA advisories, remediation deadlines and security leadership. Advisory models are evolving as agencies push for faster action. CISOs now need to balance urgency, testing and operational resilience.
For enterprise teams, the takeaway is clear. AI is changing the vulnerability timeline. Organizations that improve asset visibility, adopt continuous testing and modernize patch response will be better positioned to close the exploitation gap.