VMTech
Discuss a project

Frontier AI Calls for a New Vulnerability Management Model

Frontier AI Calls for a New Vulnerability Management Model

Frontier AI models, including Anthropic's Mythos, are changing the assumptions behind vulnerability management, Kevin Garvey writes in a contributed SANS article. The models can identify zero-day flaws, chain complex exploits and adapt in real time, creating pressure on security and patching programmes that already carry extensive remediation backlogs.

Garvey argues that many organisations have plans to move towards a continuous threat exposure management, or CTEM-style, approach but have not yet made that transition. The result is a widening mismatch between traditional remediation cycles and vulnerabilities that may be discovered and developed into exploits at machine speed.

Prioritisation must move beyond severity scores

CVSS remains useful, but a CVSS score alone cannot provide the risk-based view needed to distinguish the most urgent issues from the broader volume of findings. The Exploit Prediction Scoring System, or EPSS, and CISA's Known Exploited Vulnerabilities, or KEV, catalog have become baseline tools for prioritising and governing remediation.

The article calls for an exposure management function that assesses risk across the organisation's attack surface. Rather than focusing only on open vulnerabilities, that function can incorporate misconfigurations, reachability and additional threat-intelligence inputs. It is intended to identify the exposures where remediation offers the greatest reduction in organisational risk, based on exploitability and business impact.

Continuous monitoring, breach attack simulation and automated penetration testing are cited as tools that can validate exposures and broaden the evidence available to vulnerability teams. This approach is presented as a way to articulate more clearly which vulnerabilities require action first when exploit development is accelerating.

Patching must match a faster threat cycle

Patch management faces a corresponding operational shift. Instead of relying primarily on Patch Tuesday processes and a separate zero-day response, Garvey says teams need faster remediation supported by automated patch identification, testing and deployment.

A ring-based methodology can advance a patch to the next deployment group only after the preceding ring has been validated for stability. Automation throughout the patching lifecycle can reduce the period in which a vulnerability remains unmitigated, while maintaining a structured path for testing.

The trade-off is that increased patching velocity can affect established availability and uptime expectations. Security and patching teams may need to engage stakeholders on downtime requirements, resiliency investment and the role of business continuity and disaster recovery teams before higher incident velocity forces those decisions.

A practical programme implication

For businesses, the immediate task is to examine whether vulnerability prioritisation reflects actual exposure and whether patch workflows can safely accelerate. Bringing vulnerability, patch, resilience and business stakeholders into one operating model can help organisations make remediation decisions before faster exploit development turns known risk into an operational incident.

#cybersecurity#vulnerabilitymanagement#exposuremanagement#patchmanagement
Open analytics
On the site 2 views
min read 4 25.08.2026
Instagram

Frontier AI Calls for a New Vulnerability Management Model

Open the post on Instagram ↗