Anthropic’s N-day findings should scare you

Anthropic’s latest research on AI-accelerated N-day exploits highlights a growing challenge for defenders: the window to patch before vulnerabilities are weaponized may be shrinking from days to hours. Which isn’t good.

You can read more here: https://www.anthropic.com/research/n-days

Yogita Parulekar, Founder & CEO, Invi Grid (https://www.linkedin.com/in/yogitaparulekar)

“Security teams are gearing up for the race to patch faster as AI compresses exploit timelines to hours. But to win, one needs a different strategy. 

“A strategy where the starting point is understanding that the ownership lies jointly with engineering and infrastructure teams who know and own their code and infrastructure. And winning the fight lies in identifying the risks jointly and correctly. The risk isn’t only what shouldn’t have been open, but also what is legitimately left open for app traffic and can get exploited. Misconfigured infrastructure and unnecessary exposure should be immediately closed. And correctly-scoped, legitimately open surfaces need mitigation layers before attackers can weaponize those paths.

“The real fix is not a faster security team. It involves forward thinking, with security and engineering owning and designing security into the pipeline itself and designing solid mitigation for exposure that legitimate traffic requires, rather than just inspecting after the fact. Security Day Zero to Day Z: a discipline built in collaboration from the moment infrastructure is designed.”

Corey Ham, Director of Continuous Pentesting, Black Hills Information Security (https://www.linkedin.com/in/coreyham)

“Defense in depth still matters. For example, with wp2shell, Cloudflare’s WAF was blocking the exploit as soon as it was published. Generic WAFs would likely have blocked some payloads regardless, since it relied on SQL injection.

“Auto-update is a must. Again, with wp2shell, clients who had that enabled were covered as soon as the patch became available.”

Kevin Surace, CEO, TokenCore (https://www.linkedin.com/in/ksurace)

“Anthropic’s findings show that AI can reduce exploit development from weeks to hours, with one working exploit reportedly created in under an hour. That means traditional risk reviews, monthly patch cycles, and human approval chains are no longer fast enough.

“Security teams need AI driven vulnerability prioritization, automated testing and deployment, continuous asset visibility, and the authority to isolate exposed systems immediately. But patching faster is not enough: organizations must also eliminate phishable MFA and protect access with hardware bound biometric identity, because in the AI era, humans cannot be expected to serve as the enterprise firewall.”

Seemant Sehgal, Founder & CEO, BreachLock (https://www.linkedin.com/in/s-sehgal)

“The patch-to-exploit window has been compressing for years, and what AI does is remove the skill floor from that process. Writing a working exploit used to require someone who understood memory corruption or authentication logic deeply enough to operationalize a CVE. Now that capability is accessible to a much wider pool of actors, which means organizations still running 30-day patching cycles have a structural exposure their risk models have not caught up to yet.

Bronwen Aker, AI Researcher & Strategist, Black Hills Information Security (https://www.linkedin.com/in/bronwenaker)

“It’s no secret that patch development has been under-supported by software developers for decades. Part of the problem is that developing patches is mind-numbingly detailed work, and fixing a vulnerability is much harder than just finding one. Add to that the fact that business is chronically unwilling to invest time and money to harden software, and it becomes obvious why we are losing the proverbial war in cybersecurity.

“Ultimately, what needs to happen is a sea change in attitude by those who dictate how software developers do their jobs. There are always going to be zero days and newly discovered vulnerabilities in software, but if we can leverage artificial intelligence to make the software being delivered tougher, more stable, and more resilient to attack before it ships, the game will change. That will not happen, however, until corporations decide that security is just as important as what the mascot looks like, if not more so.”

Jacob Krell, Sr. Director, Secure AI Solutions & Cybersecurity, Suzu Labs (https://www.linkedin.com/in/jacob-krell)

“Anthropic quantified what Mandiant’s M-Trends already established. Mean time-to-exploit went negative last year, and AI is accelerating the trend. A single operator can now turn a month of patches into working exploits in one afternoon for a few hundred dollars. That breaks the core assumption underneath every enterprise patching SLA.

“Most organizations can deploy patches fast once they decide to. The bottleneck I keep seeing is the decision layer, change advisory boards, risk assessment, approval chains calibrated for weeks of runway between disclosure and weaponization. That runway is gone. Compressing governance speed to match is the first shift. Where even that isn’t fast enough, architecture has to assume immediate weaponization and limit blast radius when the patch arrives too late.”

Ted Miracco, CEO, Approov (https://www.linkedin.com/in/tedmiracco)

“The core argument that ‘patch velocity no longer matters because exploitation has outpaced it’ is correct but incomplete, as it primarily addresses CVE-driven risk, while not accounting for zero-days. Mobile and API security are not primarily patch-dependent, as they rely on obfuscation and the assumption that manual reverse-engineering is too costly to justify against most targets. AI removes that cost asymmetry entirely, allowing automated discovery of authorization and business-logic flaws that are rarely assigned CVEs because they are not classified as bugs. The result is a second, quieter collapse alongside the CVE one. An entire defensive model built on attacker effort exceeding attacker patience has lost its foundational assumption in the increasingly important mobile and API sectors as well.”

Donald McFarlane, Xcape (https://www.linkedin.com/in/dmcfarlane)

“AI is changing the economics of defense. Patching and increasingly ephemeral infrastructure are table stakes, but defenders must assume exploitation will occur, making continuous detection, layered defenses, and effective containment just as important as rapid remediation. Governance should accelerate action, not become a substitute for it.”

Consider yourself warned. The time to patch is dropping. Which means that your defences need to reflect that reality. Otherwise you’re guaranteed to get pwned.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading