TL;DR: AI is changing vulnerability economics by accelerating discovery, testing, and exploit weaponization faster than human triage can keep up, according to Cymulate. The operational shift is from counting exposures to proving which paths are reachable, relevant, and consequential before attackers do.
NHIMG editorial — based on content published by Cymulate: Post-Mythos Security: When Exploits Outpace the Patch Cycle
Questions worth separating out
Q: What breaks when vulnerability management is limited to scan results?
A: Teams end up triaging large numbers of findings without knowing which ones can be chained into a working attack.
Q: Why do AI-assisted attacks make reachable identity paths more dangerous?
A: Because attackers can test more paths faster, they are more likely to find a route from a technical weakness into a service account, privileged workflow, or delegated access chain.
Q: How do security teams know whether vulnerability assessment is actually working?
A: Teams should look for short triage cycles, high-confidence findings, and a clear link between scan results and remediation action.
Practitioner guidance
- Prioritise exploitable paths, not vulnerability counts Rank issues by whether they are reachable, whether they touch privileged identities, and whether exploitation would affect a critical service or regulated dataset.
- Validate controls against realistic attack paths Use exposure validation and attack-path testing to confirm whether preventive controls actually block the route an attacker would take in your environment.
- Shorten triage around identity-dependent exposures Escalate findings that involve service accounts, delegated access, or privileged workflows because those paths convert a technical bug into operational impact quickly.
What's in the full article
Cymulate's full article covers the operational detail this post intentionally leaves for the source:
- The webinar-specific reasoning behind moving from severity scoring to achieved impact as the primary prioritisation model
- The AI-assisted validation workflow used to test exposure relevance, reachability, and compensating controls
- The examples of how attack-path testing can help security teams decide what to remediate first
- The broader explanation of how the cited research informed Cymulate's exposure-validation approach
👉 Read Cymulate's analysis of AI-driven exploit discovery and patch prioritisation →
AI exploit discovery and patch cycles: what security teams must change?
Explore further
AI discovery creates a prioritization crisis, not just a scanning problem. The issue is no longer whether security teams can list exposures. It is whether they can prove which exposures are reachable, relevant, and consequential before an attacker tests them first. That is a shift in governance, reporting, and remediation logic. The organisations that keep treating vulnerability counts as the primary metric will keep missing the real question: what can actually be achieved in the environment. Practitioners should therefore make exploitability and business impact the centre of the decision model.
A question worth separating out:
Q: What breaks when organisations rely on patching as the main defence against AI-driven attacks?
A: The defence breaks when discovery and exploitation move faster than change approval, testing, and rollout. At that point, patching becomes necessary but insufficient, because attackers can traverse trusted paths before remediation is complete. Containment and path reduction become the real control plane.
👉 Read our full editorial: AI-driven exploit discovery is outpacing patch cycles and triage