[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fv8lUNNGVmkhTXHohwgjvncDn1MUR3a-6h9oAB3vIKxk":3},{"article":4,"iocs":52},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":29,"category":30,"article_tags":34},"9c659bb7-e609-4f42-8d1e-bdbc62fb9a3d","CISO perspectives on managing vulnerability risks in the age of AI","ciso-perspectives-on-managing-vulnerability-risks-in-the-age-of-ai-9e9afd","Learn how CISOs can mitigate cybersecurity risks and increase resilience in the age of AI-powered vulnerability management. The post CISO perspectives on managing vulnerability risks in the age of AI appeared first on Microsoft Security Blog.","AI is accelerating vulnerability discovery and exploitation, presenting CISOs with a larger volume of findings than ever before. The challenge lies not just in patching speed, but in maintaining accuracy and scale. While AI aids defenders in identifying exposures and automating remediation, CISOs need to allocate more resources to patching critical on-premises software and rethink patch timing due to the reduced window between patch release and exploitation.","CISOs must balance rapid patching with accuracy as AI increases vulnerability findings.","Share Link copied to clipboard! Content typesBest practicesTopicsAI and agentsOffice of the CISO Most of what has been written about AI and vulnerability management focuses on speed: how much faster frontier AI models can scan code, find weaknesses, design patches, and build exploits than any human team. That part is true, and it matters to how we remediate vulnerabilities. The more challenging question is what happens after the scan? Frontier AI models are about to hand every security team a far larger set of findings than they have ever had to work through. The real test for chief information security officers (CISOs) and IT security leaders is not how fast they can patch. It is whether they can keep the balance between patching quickly and patching correctly, at a scale no human review process was built for. This shift creates both new challenges and new opportunities. The same AI capabilities accelerating cyberattackers are also enabling defenders to identify exposures earlier, automate remediation, and build more resilient security programs. Not every vulnerability will be patched in time, so the controls that limit what an attacker can do by defense in depth matter more than ever. CISOs can dramatically improve the security posture of their Microsoft infrastructure by deploying Microsoft Baseline Security Mode (BSM), building on how Microsoft protects Microsoft. Learn more about Microsoft Baseline Security Mode How do frontier AI models change vulnerability management for CISOs? Microsoft uses frontier AI models to find vulnerabilities in its code base and mitigate them at controlled pace. Potential vulnerabilities are reviewed on validity, severity, and potential impact. As we have explained in previous blogs, many steps in our vulnerability handling and disclosure processes now are AI-powered, allowing them to scale. Most vulnerabilities in cloud software are being mitigated by Microsoft without customer intervention. For on-premises Microsoft software, customers should continue to expect a substantial increase in the number of vulnerabilities released on Patch Tuesdays relative to historic volumes before the advent of frontier AI models earlier this year—September 2026 saw a record number, close to 1,000.1 Due to the non-deterministic nature of AI models, different runs by the same model or with different models may yield different results. With better models becoming available over time, AI-powered vulnerability scanning of our existing code base and new code should become part of our standard security assurance. We use a ‘harness’ layer around AI models in vulnerability scanning for better results. This layer controls how models access code, validate outputs, and integrate findings into triage and remediation workflows. Microsoft has expanded the use of harnesses in scanning its code bases across all the engineering groups. One of these harnesses, codename MDASH, has now also been made available to customers. In addition to AI-powered vulnerability scanning, our internal Red Teaming engagements now leverage AI, enhancing the team’s capacity to find weaknesses in controls and boosting the efficiency and speed of the operations. What can CISOs do to mitigate the risk of vulnerabilities to their organization? How can CISOs prepare for what’s coming, as new AI models in the hands of threat actors increase the risk and pace of cyberattacks using unknown or unpatched vulnerabilities? CISOs should increase the resources allocated to Microsoft on-premises software patching, prioritization, and timing as they should continue to expect a high volume of patches on future Patch Tuesdays, at least over the coming period. CISOs should rethink patch timing for their most critical systems. Traditionally, critical components such as domain controllers and edge devices have been patched when downtime is least disruptive, such as weekends or holidays. As AI shortens the time between patch release and exploitation, that trade-off may need to change. Consider deploying fixes to these systems within 24 hours rather than waiting for the next maintenance window. CISOs should use harnesses to scan and remediate vulnerabilities in the code base of their organizations. They should do so without delay, rather than wait for access to frontier AI models. They should allocate appropriate resources for tokens and human resources to triage and remediate bugs. CISOs should focus, more than ever, on defense-in-depth and monitoring of the state of health of their critical controls. As governments and regulators around the world raise expectations for cyber resilience through legislative frameworks, these authorities are compelling organizations to strengthen their security posture, operational resilience and regulatory readiness. Extensive guidance can be found in a new Microsoft Security Exposure Management page with capabilities customers can use to act. Microsoft helps by tackling open-source vulnerabilities with industry peers Many organizations use open-source software in their infrastructure or their products. As governments and regulators increase expectations around software security, the ability to find and fix open-source vulnerabilities is becoming more important, but many open-source maintainers don’t have the tools or resources to respond quickly, which increases supply chain risk in the face of AI-supported vulnerability discovery. Microsoft has teamed up with industry peers to coordinate the scanning and patching of vulnerabilities in critical open-source components before cyberattackers find them. Participating organizations are pooling resources to prioritize and scan open-source packages and remediate in cooperation with the maintainers. Microsoft helps by offering Secure by Design and Secure by Default to customers The implementation of defense in depth by organizations worldwide can be vastly improved by implementing baseline security controls by default across their estate. The implementation of Secure by Default requires to carefully balance useful features and fast innovation with security controls and guardrails. Microsoft is committed to implementing Secure by Design and Secure by Default across its products, thereby removing part of the burden of implementing critical controls from customers. See our latest Secure Future Initiative (SFI) report for more details. With Secure by Design, security comes first when designing a product or service. Customers do not need to opt in and cannot opt out. Recent examples where we have implemented Secure by Design changes in Microsoft products are: Mandatory multifactor authentication for Microsoft Azure administrators.2 Enforcing Conditional Access policies to Windows Hello for Business and macOS Platform single sign-on (SSO) registration.3 Secure-by-design under the hood in Azure.4 Secure by Default means that security protections and secure configurations are enabled by default, requiring no extra effort. Recent examples where we have implemented Secure by Default changes in Microsoft products are: Azure Backup soft delete enabled by default.5 Azure VNet default outbound access disabled.6 Customers can opt out of certain controls if they accept a higher risk posture. Customers may also create a better risk posture by opting in to more demanding or more sophisticated controls. CISOs can dramatically improve the default security posture of their Microsoft infrastructure by deploying Microsoft Baseline Security Mode (BSM). BSM helps organizations to implement and monitor secure configurations at scale, based on “How Microsoft protects Microsoft.” Scenario analyses are available to assess the impact of additional controls in existing tenants, allowing a staged and controlled rollout. Controls can be turned on and off, and exceptions can be made and removed. Microsoft Baseline Security Mode is available to existing customers within their current license agreement. We highly recommend CISOs to use BSM to increase ","https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002F2026\u002F10\u002F06\u002Fciso-perspectives-on-managing-vulnerability-risks-in-the-age-of-ai\u002F","https:\u002F\u002Fwww.microsoft.com\u002Fen-us\u002Fsecurity\u002Fblog\u002Fwp-content\u002Fuploads\u002F2026\u002F10\u002FCISO-managing-risks.jpg","2026-10-06T16:00:00+00:00","2026-10-06T18:00:28.107212+00:00",7,[18,21,24,27],{"name":19,"type":20},"Microsoft Baseline Security Mode","product",{"name":22,"type":23},"Microsoft","vendor",{"name":25,"type":26},"AI","technology",{"name":28,"type":26},"vulnerability management","839da5c1-3c34-47e2-9499-f7201640e3ac",{"id":29,"icon":31,"name":32,"slug":33},null,"AI Security","ai-security",[35,40,42,47],{"category":36},{"id":37,"icon":31,"name":38,"slug":39},"80544778-fabb-4dcd-aa35-17492e5dcf4f","Vulnerabilities","vulnerabilities",{"category":41},{"id":29,"icon":31,"name":32,"slug":33},{"category":43},{"id":44,"icon":31,"name":45,"slug":46},"c5c77cdb-f7d7-4990-9436-c81dcbff1163","Policy","policy",{"category":48},{"id":49,"icon":31,"name":50,"slug":51},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[53],{"type":54,"value":55,"context":56},"malware","MDASH","Codename for a harness layer used by Microsoft for AI-powered vulnerability scanning, now available to customers."]