TL;DR: AI-powered offensive tooling is compressing exploit development from months toward days and shrinking the detect-to-patch window toward hours, which makes full attack-surface coverage and continuous remediation the new baseline, according to Synack. The governance challenge is no longer only protecting crown jewels; it is maintaining visibility and response speed across every exposed asset.
NHIMG editorial — based on content published by Synack: Mythos Changes Everything and the risk to the entire attack surface
By the numbers:
- Time-to-exploit on zero days fell from 32 days to just five days in 2024, according to the article.
Questions worth separating out
Q: How should security teams contain AI-speed attacks once the first exploit lands?
A: Security teams should assume the first exploit is only the beginning and design for rapid isolation rather than manual investigation first.
Q: Why do legacy systems become more dangerous under frontier AI attack conditions?
A: Legacy systems are dangerous because they often remain reachable, unsupported, and difficult to patch quickly.
Q: How do organisations know whether detect-to-patch is actually fast enough?
A: They should measure the time from exposure discovery to validated remediation for their most critical assets, not just the time to ticket creation.
Practitioner guidance
- Map the full attack surface continuously Inventory internet-facing systems, internal reachable services, legacy infrastructure, and forgotten APIs together so exposure is not split across separate teams or tools.
- Prioritise identity-bearing exposures first Treat exposed credentials, service accounts, API keys, and privileged access paths as high-priority attack surface items because AI-led attackers can chain them quickly.
- Shorten remediation workflows for high-confidence findings Pre-approve emergency changes, owner escalation, and rollback paths so the detect-to-patch window can shrink from days to hours when needed.
What's in the full article
Synack's full analysis covers the operational detail this post intentionally leaves for the source:
- The specific reasoning behind its AI-led exploitation posture and how it maps to modern red team workflows
- The article's full guidance on prioritising legacy infrastructure, exposed services, and remediation timing
- The practical framing Synack uses to explain why continuous testing matters more than point-in-time assessment
- The business-risk language it recommends for communicating faster attack windows to leadership
👉 Read Synack's analysis of AI-powered exploitation and attack surface risk →
AI-powered attack surface mapping: is your remediation cycle fast enough?
Explore further
Attack surface management is becoming an identity problem as much as a vulnerability problem. AI-led exploitation does not stop at scanning ports and code paths. It also surfaces credentials, service accounts, and privileged interfaces that were previously ignored because they were hard to reach manually. Practitioners should treat access paths as first-class attack surface, not a separate IAM concern.
A question worth separating out:
Q: What should organisations do first when AI-driven attacks speed up exploitation?
A: Organisations should focus first on identities that already combine privilege, persistence, and secret access. Those are the fastest paths to compromise and the hardest to detect manually. The first 24 to 72 hours should be spent reducing exposure windows, validating revocation, and confirming which agents or service accounts can still reach sensitive systems.
👉 Read our full editorial: AI-powered exploitation shrinks the detect-to-patch window for all assets