[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fRd5npP_gRreLgvHCJlnfnUm4dPC_NdaMJ2cU02D4oJM":3},{"article":4,"iocs":44},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":21,"category":22,"article_tags":26},"87aab6dd-7f7d-4e80-9abe-94586cdcef9c","Rethinking Application Security for the AI Era","rethinking-application-security-for-the-ai-era-8d87a4","As AI dramatically shortens the time from vulnerability disclosure to exploitation, enterprises must look beyond patching to reduce application risk. The post Rethinking Application Security for the AI Era appeared first on SecurityWeek.","The article highlights how AI is drastically reducing the time attackers take to weaponize vulnerabilities, from 771 days in 2018 to an estimated 4 hours by 2026. This rapid pace makes traditional patching cycles impractical. Enterprises are urged to adopt strategies like accurate application inventory, continuous risk assessment and vulnerability scanning, streamlined patching processes, and robust threat intelligence to mitigate risks in the AI era.","AI dramatically accelerates vulnerability exploitation, forcing enterprises to rethink application security beyond","In my previous column, I discussed the topic of Frontier AI and how enterprises can separate genuine AI capabilities from marketing hype when it comes to their vendors. In that piece I also noted that, regarding their own applications, enterprises are concerned they will not be able to keep up with the increased pace of identifying, mitigating, and patching vulnerabilities. I’d like to discuss that topic in this piece. In 2018, it took attackers an average of 771 days to weaponize vulnerabilities. In 2026, that number is due to fall to just 4 hours! In other words, attackers are leveraging AI and other technologies to vastly increase the speed with which they can exploit vulnerabilities. Given the increased pace at which attackers can find vulnerabilities, develop exploits, and attack enterprises, what are some ways that enterprises can protect themselves and the applications they serve to their end-customers? Simply put, it is not practical for enterprises to think that they will be able to keep up with a patching cycle measured in minutes and hours rather than in months and years. That being said, there are still many things enterprises can do to limit their exposure and mitigate their risk around the security of their own applications. While not an exhaustive list, I have put together a few recommendations here that I believe will help enterprises manage the exposure and risk that this new reality presents: Accurate inventory: We cannot protect what we do not know about and what we cannot see. This is why visibility and discovery are so important and foundational in this process. Once we are aware of our applications, their APIs, and their AI components, we must track, manage, and secure that inventory meticulously. Many of the following recommendations are dependent on that inventory, as are many other things when it comes to securing applications in the enterprise. Continuous risk assessment: Many of us have grown up in a world where an application’s risk to the enterprise is assessed quarterly, semi-annually, or even annually. That may have been reasonable once upon a time, but that time scale is far too slow in today’s world. When we can’t keep up with the pace of patching, we need to supplement our risk mitigation efforts using other measures. Continually assessing and understanding an application’s risk profile is fundamental to understanding what other levers we can pull on to mitigate that risk. Continuous vulnerability scanning: Before we can even think about patching an application, we must be aware of and understand what vulnerabilities exist. From there, we can triage and prioritize them to maximize the amount of risk we can mitigate using available resources. Yet, this requires having a continual flow of information around our applications’ vulnerabilities. If we are not scanning our applications regularly to look for vulnerabilities, then we are losing both ground and time in the battle to keep up with the ever-quickening pace of attackers. Patching cycles: When we do have the ability to apply one or more patches, we need to make that process as painless and efficient as possible. That means streamlining processes, removing technical and organizational hurdles, and ensuring that our teams are set up for success. It certainly looks like the industry will be moving to more regular patching cycles. As that happens, any time lost becomes even more pronounced, noticeable, and painful than it would have been in years gone by. Enterprises need to pre-empt this pain and ensure they are prepared to patch more frequently. Threat intelligence: Getting blindsided or surprised always makes security (and most other professions) harder. This is all the more so given the rapid rate of change around vulnerabilities and patching in our industry. While there will always be times when an enterprise will be caught unprepared, the enterprise should try to minimize these occasions. A mature, rigorous threat intelligence program (whether in-house or outsourced) can help an enterprise be aware of emerging trends and impending changes. This, in turn, can help the enterprise prepare ahead of time and minimize the number of times they are caught by surprise. Tighten preventive controls: As noted above, when an enterprise cannot keep up with the pace of patching, that enterprise needs to pull on other levers to compensate. One such lever is a tried and true one – preventive controls. Now is a great time for enterprises to review their preventive controls to ensure that they are adequately tightened. Doing so can help reduce their exposure and mitigate the potential risk that an unpatched application will be exploited. Runtime security: Similarly, detective controls and runtime security can also help compensate for the enterprise’s inability to keep pace with patching. It is important to remember to cover all layers of the application stack to ensure that runtime security mitigations are thorough. This is where moving away from a reliance on signatures and toward the ability to detect novel attacks becomes important. This capability is required at the application, API, and AI layer, including runtime protection for large language models (LLMs) and natural language prompts. Agents: There is quite a bit of discussion around the industry regarding the impact of agentic AI. While the full extent of the impact remains to be seen, the rapid rate at which agents can discover capabilities, vulnerabilities, exposures of sensitive data, and other such things is clear. Enterprises need to make sure that they’ve used the options above to help mitigate their application security risk in general. In addition to that, they should ensure that they have proper protection against agents going rogue. This could be a combination of application layer DDoS protection, bot protection, malicious user detection, visibility into what agents are doing, and continuous monitoring of their activities. Frontier AI has accelerated a trend we have been seeing in the security industry for quite some time now. The time from vulnerability disclosure to exploit is now measured in minutes and hours, rather than months and years as it was not too long ago. While it is impractical for enterprises to patch this frequently, there are a number of levers they can pull on to mitigate their risk and exposure. With proper planning and execution, enterprises can continue to protect their applications, even with the accelerated pace of vulnerability discovery, disclosure, and exploitation. Related: Frontier AI: Six Questions Every Enterprise Should Ask Security Vendors Related: Is Patching Dead? Vulnerability Management in the Post-Mythos Era Advertisement. Scroll to continue reading. Written By Joshua Goldfarb Joshua Goldfarb (Twitter: @ananalytical) is currently Field CISO at F5. Previously, Josh served as VP, CTO - Emerging Technologies at FireEye and as Chief Security Officer for nPulse Technologies until its acquisition by FireEye. Prior to joining nPulse, Josh worked as an independent consultant, applying his analytical methodology to help enterprises build and enhance their network traffic analysis, security operations, and incident response capabilities to improve their information security postures. He has consulted and advised numerous clients in both the public and private sectors at strategic and tactical levels. Earlier in his career, Josh served as the Chief of Analysis for the United States Computer Emergency Readiness Team (US-CERT) where he built from the ground up and subsequently ran the network, endpoint, and malware analysis\u002Fforensics capabilities for US-CERT. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Joshua Goldfarb Frontier AI: Six Questions Every Enterprise Should Ask Security VendorsAfter AI Reaches Production: 12 Ways Security Teams Can Take ControlCaught Off Guard: Securing AI A","https:\u002F\u002Fwww.securityweek.com\u002Frethinking-application-security-for-the-ai-era\u002F","https:\u002F\u002Fwww.securityweek.com\u002Fwp-content\u002Fuploads\u002F2026\u002F06\u002FAgent-AI-Security.jpg","2026-08-24T10:00:00+00:00","2026-08-24T10:00:05.561558+00:00",8,[18],{"name":19,"type":20},"AI","technology","839da5c1-3c34-47e2-9499-f7201640e3ac",{"id":21,"icon":23,"name":24,"slug":25},null,"AI Security","ai-security",[27,32,34,39],{"category":28},{"id":29,"icon":23,"name":30,"slug":31},"80544778-fabb-4dcd-aa35-17492e5dcf4f","Vulnerabilities","vulnerabilities",{"category":33},{"id":21,"icon":23,"name":24,"slug":25},{"category":35},{"id":36,"icon":23,"name":37,"slug":38},"c5eccf7c-abbc-4bd3-bbed-e6da5cba8e73","Incident Response","incident-response",{"category":40},{"id":41,"icon":23,"name":42,"slug":43},"e7b231c8-5f79-4465-8d38-1ef13aea5a14","Threat Intelligence","threat-intelligence",[]]