Skip to content
Security & Trust Talking point

When exploits come fast, exposing fewer things is the first defence

Wiz's Alon Schindel argued that cutting what is public matters first when AI speeds up exploits.

W
WebPulse Newsroom
AI-assisted · 2 min read
Share on X LinkedIn
When exploits come fast, exposing fewer things is the first defence
In brief
  • Alon Schindel of Wiz argued that as AI speeds up exploits, the first step is reducing what is exposed to the internet.
  • He did not say patching is dead. He called automated patching hard, and he argued defenders still hold an advantage.

Alon Schindel, VP of AI and Threat Research at Wiz, made a simple argument on Software Engineering Daily. AI has shortened the gap between a public vulnerability report and a working exploit. So the first step is to reduce what you leave exposed. Patching still matters, but he put exposure first. The episode, "Security in the Age of Instant Exploits," was published on 6 October 2026.

What was said

Schindel owns Wiz's response to new vulnerabilities. He said his team spent the past year in back-to-back responses, because exploits now show up faster.

He gave a contrast. Soon after he joined, a critical Apache web server flaw took, as he recalled it, about two or three days to see an exploit. For a recent MongoDB flaw, he said, you could take the public report, send it to Claude and get the full exploit back.

He described the shift this way: "hacking has been democratized, that's what I mean, that it's becoming easier to hack a website."

From there he turned to exposure. In many cases, he said, the real problem is not the flaw itself. It is a resource that should never have been public. Reducing exposure, he argued, is now critical and comes first. He also urged continuous AI scanning of web assets, code repositories and build pipelines, to find weak spots before attackers do.

Why it matters

Our reading: a patch queue is a race, and a fast exploit means you may start it already behind. Every public service adds another race.

That gives managers a question they can act on now. What do we expose that nobody needs to reach? Think test servers, old admin pages, open repositories and forgotten pipelines. Buyers can ask vendors the same thing about what their products leave public.

Removing an exposure also removes the patch work that would have followed it. That is why Schindel's ordering is worth noting.

The other side

Schindel did not say patching is dead. He described Wiz's agent as able to plan fixes, and users can tell it to prefer patching or to prefer reducing exposure. He called automated patching "not an easy thing to do." Code must be tested after a patch, and he said the industry still has work to do there.

He also argued the race is not lost. "The defenders have better context," he said, and he believes that gives them the advantage. He added that most vulnerabilities Wiz finds with AI cannot really be exploited. That tempers the alarm. The host himself noted that much news on this topic is doomsday.

Two cautions apply. Wiz sells scanning tools, so it has an interest in this framing. And the claim that exposure reduction is the only defence that scales is not one Schindel made. He called it the first step.

Written by the WebPulse Newsroom with AI assistance, and checked by our editorial review: every quotation was verified against the recording's transcript. How we use AI.

The conversation this talking point comes from

Share this insight