Opens in a new tab

NEW ARTICLE: The Zero-Day Clock and AI’s Impact on Security Read Now

Supporting organizations across the entire U.S.

The Zero-Day Clock and AI’s Impact on Security

Cybersecurity

Written by

David McBride

Published on

Cybersecurity Awareness Month is right around the corner, and it gives businesses something rare on the calendar: a deliberate moment to step back, take stock of what has actually changed, and move into the next year with confidence instead of guesswork. We’re marking this year’s observance with Racing the Zero-Day Clock, a five-part series built around one question: what shifted in cybersecurity risk over the past year, and what does a business do about it now?

For nearly two decades, stolen credentials sat at the top of the list of ways attackers broke into business networks. That changed this year. The 2026 Verizon Data Breach Investigations Report found that 31% of breaches now start with software vulnerabilities, overtaking stolen passwords as the leading way attackers get in. For business leaders who have spent years treating password hygiene as the front line of cybersecurity, that shift is worth pausing on.

Part of the explanation is timing. Mandiant’s M-Trends 2026 report found that the mean time to exploit newly disclosed vulnerabilities has dropped to an estimated -7 days, meaning exploitation is, on average, already underway before a vendor even ships a patch. Call it the zero-day clock: a countdown that, for a growing share of vulnerabilities, starts before defenders know it is running.

Artificial intelligence is accelerating that clock from both directions. Security researchers are using AI to find and fix flaws faster than ever. Attackers are using the same category of tools to find and weaponize them just as fast. The businesses that come out ahead will be the ones with the visibility to know which risks in their own environment actually matter, and the process to act on that knowledge quickly.

That is a different discipline than trying to patch every vulnerability the moment it is disclosed. Most vulnerabilities are never exploited at all. A small number are exploited almost immediately, often before anyone outside the attacker’s circle knows they exist. The rest of this article looks at why that gap is widening, what AI is doing to both sides of it, and what it means to be ready before the clock starts rather than after.

When the Exploit Outruns the Patch

A negative mean time-to-exploit is a striking number, but it is consistent with how modern attack operations actually run. Mandiant’s same research found that the handoff between an initial access broker and the secondary group that monetizes the breach, often a ransomware operator, has compressed dramatically. In 2022, that handoff took a median of more than eight hours. By 2025, Mandiant found it had fallen to just 22 seconds, with initial access groups pre-staging the next group’s malware and infrastructure before the intrusion even completes.

For a business, the practical effect is that the old model of detect-then-respond assumes a gap between those two steps that increasingly is not there. A single unpatched, internet-facing system is a risk that may already be in use, not one to leave for the next maintenance window.

That does not mean every organization needs to treat every disclosed vulnerability as an emergency. VulnCheck’s 2026 Exploit Intelligence Report found that only about 1% of vulnerabilities disclosed in 2025 were confirmed as exploited in the wild by year’s end. The same report found that 56.4% of the CVEs behind 2025 ransomware attacks were discovered specifically because they were being exploited as zero-days, before a patch existed at all. Put together, those two figures describe the real challenge: the overwhelming majority of vulnerabilities never matter, but the small share that do are frequently the ones nobody had a patch for yet. Knowing which category a given flaw falls into, and having a way to act on that judgment quickly, matters more than trying to close every gap on the list.

AI Is Rewriting Both Sides of the Clock

Artificial intelligence has changed how quickly that judgment can be made, and it has changed it for attackers and defenders at nearly the same time.

On the offensive side, Google’s Threat Intelligence Group reported what it describes as the first confirmed case of a threat actor using an AI model to help discover and weaponize a zero-day vulnerability, a two-factor-authentication bypass built into a widely used, open-source system administration tool. The group planned to use it in a mass exploitation operation; Google says its own detection work likely prevented that from happening. Separately, Anthropic disclosed that it disrupted an espionage campaign in which a state-linked group used its Claude Code model to run an estimated 80–90% of the operation autonomously, including reconnaissance, vulnerability testing, exploit writing, and credential harvesting, with human operators stepping in only at a handful of decision points. At peak activity, Anthropic said the system was making thousands of requests, often multiple per second, a pace no human hacking team could match.

The same capability is showing up in defense. Google’s Big Sleep AI agent identified a critical SQLite vulnerability, tracked as CVE-2025-6965, that Google says was known only to threat actors and was at risk of being exploited. Google intercepted it before that could happen, in what it calls the first time an AI agent has directly stopped a real-world exploitation attempt rather than simply flagging a flaw after the fact.

The pace of discovery has increased by roughly the same amount on both sides. The businesses that benefit are the ones that already know what is running in their environment, well before an attacker or a defender’s AI model finds a reason to look.

Why Visibility and Prioritization Beat Volume

This is where the business decision actually lives. An SMB leadership team needs a process for knowing, quickly, which handful of disclosed issues in its own environment resemble the ones attackers are actually using, rather than a process for patching every vulnerability that gets disclosed.

CISA has been moving its own federal guidance in that direction. Its Known Exploited Vulnerabilities catalog has, since 2021, given organizations a running list of vulnerabilities confirmed as exploited, rather than a raw feed of every disclosed flaw. In 2026, CISA went further with Binding Operational Directive 26-04, which moves federal agencies away from patching on a fixed schedule and toward prioritizing updates based on exposure, exploitability, and evidence of active exploitation. The direction of travel matches what private-sector data already shows: closing the vulnerabilities that are live risks matters more than closing every vulnerability that exists.

The cost of getting that judgment wrong, or getting to it too slowly, is measurable. The 2026 IBM Cost of a Data Breach Report put the average global cost of a breach at $4.99 million, up 12% from $4.44 million the year before. The same report found organizations took a mean of 247 days to identify and contain a breach in 2026, the first increase in five years after a run of steady improvement, still roughly eight months of exposure while a compromise plays out. Set against a mean time-to-exploit that has gone negative and a criminal handoff window measured in seconds, that gap between attacker speed and defender speed is the real business risk. Most vulnerabilities are not dangerous, but the ones that are move faster than most organizations’ current processes can follow.

Readiness Begins Before the Clock Starts

The throughline across all of this data is timing. Vulnerabilities are being found faster, weaponized faster, and in the worst cases, exploited before a patch exists at all. AI has sped up that process for attackers and defenders alike, so the deciding factor is not which side has access to more advanced tools, but which organizations already know what is running in their environment, which of it actually matters, and how quickly they can act once something changes.

Treating that as a project to revisit once a year, rather than a capability an organization maintains continuously, is a choice that carries a growing cost. The businesses least exposed are the ones that know, at any given moment, which of their systems would matter most if a new vulnerability appeared tomorrow, not necessarily the ones that patch everything.

That kind of visibility is difficult to build and maintain without dedicated support, particularly for organizations without a full-time security team watching disclosures, exploit activity, and their own environment at the same time. A technology partner that specializes in this work can bring the monitoring, the assessment discipline, and the response speed that the current pace of exploitation now demands.

Cybersecurity: Identifies which vulnerabilities in your environment are genuine risks before attackers find them first. 

IT Consulting & Strategy: Builds a prioritization plan that closes the gaps most likely to be exploited, not just the longest list of them. 

AI Integration & Governance: Puts guardrails around how your business adopts AI tools while that same technology accelerates threats on the outside.

👉 If your organization is ready to know which vulnerabilities actually put it at risk, our team is ready to help you take the next step.