Vulnerability Management, AI/ML, Exposure management

Why Mythos is the cybersecurity crisis we need

(Adobe Stock)

Artificial intelligence is ready to completely change vulnerability management — but not in the way many organizations expect. Rather than simply helping defenders find software flaws faster, next-generation AI models such as Anthropic's Claude Mythos are expected to dramatically increase the number of disclosed vulnerabilities while simultaneously shortening the time attackers need to weaponize them.

In a recent CRA webcast, host Adrian Sanabria spoke with IDC Research Vice President Michelle Abraham and Tanium VP of Product Management Julia Grunewald about why this shift requires organizations to rethink exposure management, prioritization and remediation workflows.

The panel agreed that the most immediate consequence of AI-powered vulnerability discovery will be volume. Organizations already struggle to keep pace with existing vulnerability backlogs, and models like Mythos will only accelerate disclosure rates.

"Organizations were already overwhelmed by many of the exposures and the findings they had," Abraham noted. "So it really makes prioritization a requirement, not just something that's nice to have."

Grunewald identified three major consequences of AI-driven vulnerability discovery: a dramatic increase in vulnerability counts, a shorter window between disclosure and exploitation, and the ability for attackers to chain together seemingly minor vulnerabilities into high-impact attack paths.

These trends mean organizations can no longer focus exclusively on critical CVEs while ignoring lower-severity issues that may become stepping-stones in AI-assisted attacks.

"I know a lot of organizations will really focus on critical vulnerabilities, high vulnerabilities. I think this is a time to revisit some of those assumptions," Grunewald said, "and look at patching some of that low-hanging fruit that might have been in an environment for a long time."

Rather than viewing exposure management as an update to vulnerability management, the speakers described it as a broader, more proactive discipline.

"Exposure-management solutions aggregate, contextualize exposures across domains," Abraham explained. "It's your traditional CVEs, but it can also be unknown assets, misconfigurations in other systems like your cloud system or your identity system. Or potentially you're missing an agent on an endpoint, and that could be an exposure."

Combining these data sources into a unified, risk-based view lets organizations prioritize remediation according to exploitability and business impact rather than by raw vulnerability counts.

The discussion also emphasized Gartner's Continuous Threat Exposure Management (CTEM) framework as the operational model best suited to the AI era.

Grunewald explained that CTEM replaces linear vulnerability management with a continuous cycle of scoping, discovery, prioritization, validation and mobilization. That approach allows organizations to evaluate new vulnerabilities continuously while remediation efforts are already underway elsewhere in the environment.

"The linear process of looking at vulnerabilities, prioritizing them, mapping them to patches, remediating them — that's not going to be as fast as we need it to be in this new age," she said.

Accurate asset inventories emerged as another recurring theme. The speakers argued that organizations cannot prioritize or remediate exposures they do not know exist.

External Attack Surface Management (EASM), continuous asset discovery, ownership mapping and business context all become increasingly important as AI compresses attacker timelines. Forgotten internet-facing systems, legacy infrastructure acquired through mergers and shadow AI deployments can all create dangerous blind spots.

The panel also challenged traditional approaches to vulnerability prioritization. While CVSS remains useful, Grunewald recommended combining three factors: objective severity, exploitability and business context.

Information such as CISA's Known Exploited Vulnerabilities catalog, EPSS scores, exploit maturity, internet exposure, asset criticality and attack-path analysis provides a much richer picture of risk than severity scores alone. Automating those calculations allows organizations to focus scarce remediation resources on exposures most likely to be exploited.

Finally, the discussion concluded that automation will become essential as AI increases both the volume of vulnerabilities and the speed of attacks. AI-assisted prioritization, confidence scoring for patches, phased deployments and autonomous remediation can help organizations accelerate patching without sacrificing stability.

As Grunewald summarized, the goal is to prepare now rather than wait for AI-generated vulnerability floods to arrive:

"Start reducing your attack surface today," she recommended. "If you can get ahead of that mobilization and remediation so that you have up-to-date patches, you have only the assets you expect to be exposed to the internet exposed."

"Doing those types of hygiene things now and upfront," Grunewald added, "will set organizations up really well for the future of vulnerability management and potentially an influx of more exploitable vulnerabilities to come."

An In-Depth Guide to AI

Get essential knowledge and practical strategies to use AI to better your security program.
Paul Wagenseil

Paul Wagenseil is a custom content strategist for CyberRisk Alliance, leading creation of content developed from CRA research and aligned to the most critical topics of interest for the cybersecurity community. He previously held editor roles focused on the security market at Tom’s Guide, Laptop Magazine, TechNewsDaily.com and SecurityNewsDaily.com.

Related Events

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds