Skip to content
The AI-First Web

AI lets attackers read a patch like an advisory, security experts say

Experts say quiet fixes now hide a flaw for less time. Defenders face a triage problem and an inventory problem.

W
WebPulse Newsroom
AI-assisted · 4 min read
Share on X LinkedIn
AI lets attackers read a patch like an advisory, security experts say
In brief
  • Experts told Dark Reading that AI helps attackers decode patches and automate campaigns, shortening the time between disclosure and exploitation.
  • In an Omdia survey, only 25% of organizations had complete real-time visibility of their attack surface, while 85% were raising offensive security spending.
  • Leaders should test patch speed, staged rollouts and asset inventories, and map who can access what before attackers do.

A patch now says what was broken

A vendor can fix a flaw quietly and hope nobody notices. Experts quoted by Dark Reading say that hope is weaker than it used to be.

Benjamin Harris, founder and CEO of watchTowr, said AI has "significantly lowered the bar for understanding what patches do, even if the vendor doesn't tell us." He was speaking about the recent NetScaler zero-day flaws and Citrix's lack of communication about them.

The idea of this story is simple. Vendors could hope that silence bought them time. Harris says that reliance on obscurity has "always been questionable", and AI makes it weaker. The attacker's speed increasingly sets the schedule.

How the mechanism works

Every patch changes software. The change points to the weakness it removes. Dark Reading reports that attackers can use large language models (LLMs, the AI systems behind chatbots) to work out what an update fixed. They do not need a public disclosure or full technical details.

In general terms, this means comparing the old and new versions of the code to see what changed. An LLM can read that difference quickly and suggest what the fix was for. This is a general explanation, not a claim from the source.

Dark Reading also reports that several high-profile flaws were exploited within hours of disclosure, not days or weeks. Experts attribute much of that shrinking window to LLMs. Frontier models, the most capable AI systems, are good at spotting new vulnerabilities.

Those are expert views reported by one outlet. They are not a measurement across all flaws. They do describe the direction defenders say they are seeing.

50%
Readers who named AI attacks versus AI defenses in the SOC as their top concern
Source: Dark Reading readership poll on Black Hat USA 2026 themes (October 5, 2026)

That poll covers Dark Reading readers. It is not a representative survey of all security teams. The next-highest answer, scaling security operations with automation, validation and trusted AI, drew 22%.

Automation adds persistence

Speed is one problem. Automation is another. Dark Reading notes that malicious agents do not need rest or holidays.

Independent researcher Justin O'Leary pointed to the Hugging Face breach. He said OpenAI agents followed familiar attack paths on a compressed timeline: "Nothing exotic, just faster." OpenAI presented preliminary findings of its investigation at Black Hat.

O'Leary said AI helps attackers quickly map an account's identity and access rules, and the trust links between its managed services. He said these tasks would typically take weeks.

That is where visibility matters. An Omdia report published this summer found that only a quarter of surveyed organizations can account for all their data and assets in real time. An agent that explores every route will find the ones nobody listed.

25%
Organizations with complete, real-time visibility of their attack surface
Source: Omdia report, as reported by Dark Reading (October 5, 2026)

The defender's dilemma: patch fast or patch safely

Ensar Seker, CISO at SOCRadar, said teams must now pick a select few vulnerabilities to fix from hundreds disclosed. Treating Patch Tuesday as a "deploy everything immediately" exercise no longer works. Some patches break things in some environments.

Joe Toomey of cyber insurer Coalition said automatic patching is worth considering, but only for mature organizations. He described release rings: patch a small group first, watch system health, then widen the rollout. He also said the shift will be painful in the short term.

Spending is moving. Omdia found 85% of surveyed organizations are raising offensive security budgets. That covers work such as penetration testing and red-teaming, where teams attack their own systems to find gaps first.

85%
Organizations increasing spending on offensive security
Source: Omdia report, as reported by Dark Reading (October 5, 2026)

Questions to put to your team

Ask how long it takes to go from a vendor patch to production for internet-facing systems. Ask who decides which flaws wait, and on what evidence.

Ask whether a quiet vendor update triggers your own review, or whether you wait for an advisory. Ask what share of your assets, accounts and trust links appear in a current inventory.

Ask whether anyone has mapped who can do what in your cloud accounts. O'Leary argues defenders can use AI for that before an attacker does. Faster alert triage alone, he said, will not catch attack chains that raise no alarms.

The lesson: the vendor's silence buys you less time than it used to. Your inventory and your patch process now decide how much time you have.

Produced by the WebPulse Newsroom with AI assistance from the original reporting credited below, and checked against that source by our editorial review. How we use AI.
Original reporting: Dark Reading.

Share this insight