The Patch Cycle Is the Vulnerability Now
Everyone framing AI cybersecurity as "attackers now have a superweapon" is reading the board wrong. AI didn't hand offense some exclusive new capability. It sped up offense and defense by roughly the same factor. Both sides got the same engine. The problem isn't that one side got faster — it's that the slow, human-paced step wedged between them didn't get faster at all, and that step is where you live.
Start with the number, because the number is the whole story. The gap between a vulnerability being disclosed and a working exploit existing for it used to be measured in months — one tally put the January 2025 average north of 120 days. By this spring the same measure had collapsed to under a day. Not shortened. Collapsed. What used to be a comfortable season to test and stage a patch is now shorter than a single change-management meeting.
That collapse is what agentic tooling does to the offense side. Finding a bug, chaining it to another, validating that the chain actually works — that used to be skilled manual labor, the reason zero-days were scarce and mostly reserved for nation-states. Now it's a loop you point at a target and let run. Automated reconnaissance against firewall fleets, multi-agent frameworks that discover and confirm exploitable paths with almost nobody at the keyboard. The scarcity that quietly protected everyone is gone.
The symmetry that isn't one
Here's where people stop thinking too early. They hear "defenders get the same AI" and assume it washes out. It doesn't, and the reason is structural, not technological.
Offense and defense are not mirror images playing the same game at the same speed. The attacker needs one path that works. The defender needs every path closed. Hand both sides a tool that's ten times faster and you haven't leveled anything — you've multiplied an asymmetry that was already lopsided. The attacker's ten-times-faster search finds the one hole ten times sooner. The defender's ten-times-faster scan finds more holes, sure, and then hands every one of them to the part of the pipeline that AI didn't touch: a human deciding when it's safe to deploy the fix.
That handoff is the actual vulnerability now. You can detect at machine speed and it buys you almost nothing, because detection was never the bottleneck. Response latency is. The window between "we know" and "it's patched in production" is governed by change tickets, maintenance windows, regression testing, and somebody's risk tolerance — all of it paced by people, none of it moved an inch by the model that just found the problem in four seconds. Run the inversion Munger would run: don't ask how to detect faster, ask what guarantees you get breached anyway. The answer is a fast detector wired to a slow remediation path. You built a race car with the parking brake on.
The government just conceded the point
Watch what happened this week, because it's a policy admission dressed as a licensing decision. A month ago Mythos 5 — described by its own maker as its strongest cybersecurity model — was too dangerous to let out of the country. National security risk, export blocked. This week the license got revised to allow release to a narrow set of "cyber defenders and infrastructure providers." Same model. Same capability. The only thing that changed is who's allowed to hold it and why.
Read that as an architectural statement, not a bureaucratic one. The government is implicitly saying defense now requires the same frontier capability as offense — that you can't meet a machine-speed attacker with a signature database and a quarterly scan. You have to bring an agent to an agent fight. That's the same logic driving the June executive order's push toward AI-enabled cyber defense: the defensive side of the ledger has to run at attacker speed or it isn't defense, it's forensics.
And the arms race is already global — Chinese firms are shipping frontier cyber models to match. This isn't a capability the US gets to fence off. It's a capability everyone gets, which loops right back to the point: when both sides have the engine, the differentiator is the slow link, and the slow link is yours to fix.
Threat-model the clock
So the discipline shifts. For years threat modeling meant mapping the attack surface — the doors, the trust boundaries, the exposed edges. That's still necessary and it's no longer sufficient, because the surface isn't the thing that changed. Time is.
Model the clock. From the minute a vulnerability affecting you goes public, how long until it's closed in production? If that answer is measured in days, you're already exposed for a window the attacker measures in hours. The uncomfortable work is compressing that gap — automating the response path, not just the detection, so remediation moves at something closer to the speed of the thing hunting you. Assume the disclosure-to-exploit window is now zero, because for practical purposes it is, and build backward from there.
None of this is a reason to panic-buy an AI security product. It's a reason to look honestly at your own middle. The model on offense got fast. The model on defense got fast. The human deciding when to deploy the patch did not — and until you fix that, that person is your entire attack surface, whether they know it or not.
The attacker automated the break-in. If you didn't automate the response, you're not defending — you're just watching in higher resolution.
— Dustin