TL;DR: Mythos-class AI can autonomously discover and chain zero-days faster than enterprises can patch manually, while the average enterprise still takes more than 60 days to remediate critical vulnerabilities and leaves 45% of identified issues unpatched after twelve months, according to Cogent. Human-speed vulnerability management is now structurally mismatched to machine-speed exploitation, so remediation automation becomes the decisive control.
NHIMG editorial — based on content published by Cogent: The Mythos Zero-Day Flood Is Here. Only AI Can Fix It
By the numbers:
- The average enterprise takes over 60 days to remediate a critical vulnerability.
- Large enterprises maintain backlogs where 45% of identified vulnerabilities remain unpatched after twelve months.
Questions worth separating out
Q: What fails when vulnerability remediation is slower than AI-assisted exploitation?
A: Patch-first security fails when exploit generation outpaces validation, change control, and deployment.
Q: Why do AI-discovered zero-days change vulnerability management priorities?
A: They shift the priority from counting findings to reducing exposure duration.
Q: How do security teams know whether Teams remediation is working?
A: They should measure dwell time, removal latency, and the percentage of malicious messages removed before any user interaction.
Practitioner guidance
- Instrument remediation throughput as a security KPI Track mean time to remediate separately for critical internet-facing assets, identity infrastructure, and exposed secrets.
- Automate exposure validation before ticket creation Use asset context, exploitability signals, and environment data to determine whether a finding is reachable in your production stack before assigning it for manual review.
- Tie patching to secret and privilege cleanup When a vulnerable service or application is exposed, trigger companion actions that rotate credentials, revoke unused tokens, and reduce overly broad access for affected non-human identities.
What's in the full article
Cogent's full article covers the operational detail this post intentionally leaves for the source:
- The article's benchmark claims and timing comparisons for AI-driven exploit discovery versus human remediation cycles.
- Cogent's proposed automation approach for moving from vulnerability discovery to verified closure.
- The vendor's rationale for combining detection, scoring, and autonomous remediation in one workflow.
- The additional examples and product framing around frontier AI and enterprise security operations.
👉 Read Cogent's analysis of AI-driven vulnerability remediation under Mythos-class threats →
AI-driven remediation for zero-days: are your controls keeping up?
Explore further
AI-driven remediation is becoming a control plane problem, not a tooling problem. When exploitation windows compress to hours, the limiting factor is no longer whether defenders can see the vulnerability. It is whether they can translate discovery into verified closure fast enough to matter. That shifts the programme question from more scanning to better orchestration across asset, identity, and remediation systems. Practitioners should treat remediation throughput as a governed security capability.
A question worth separating out:
Q: Which control should organisations prioritise first when attack windows collapse?
A: Prioritise the control that removes attacker opportunity before it can be used, which is remediation backed by identity cleanup. Patching alone is not enough if service accounts, API keys, or certificates remain exposed. The strongest programmes combine fast fix deployment with automatic credential rotation and privilege reduction.
👉 Read our full editorial: AI-driven vulnerability remediation is becoming the new security baseline