AI is speeding up exploits. Vulnerability spreadsheets can’t keep up.
The New Stack Russ Andersson
AI is speeding up exploits, and old CVE spreadsheets can’t keep up. Security teams now need to chase real risk, not just big lists of bugs.
Based on reporting by The New Stack, Russ Andersson — read the original for the full story.
Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error
AI has changed software development and cybersecurity, but the less glamorous shift may be in vulnerability management. The old routine was simple: scan, score, sort, hand off. It was never a great picture of risk, and the gap between “we found it” and “we can actually fix it” is getting wider.
That’s because the problem is no longer just volume. More software is being built, vulnerability discovery is moving faster, and exploit development is getting shorter and shorter. AI can also help attackers combine weaknesses into paths that are hard to spot by hand. A spreadsheet full of CVEs looks organized right up until it stops being useful.
The article makes a sharp point about severity versus risk. A CVSS score can describe technical impact, but it does not tell you whether a vulnerability is exposed, reachable, in use, or even relevant in a given environment. The same CVE can be a nuisance in one system and a serious problem in another. That’s why teams that keep celebrating the number of findings they closed can end up doing “CVE theater” instead of reducing actual exposure.
The answer is to shift the work upstream and keep it continuous. Harden base images and language libraries, scan first-party code with tools like SAST and AI-assisted code scanning, and check configurations with frameworks such as STIGs. Then, in production, look at what is really running, not just what was in a registry yesterday. Reachability matters. Network exposure matters. So does whether the vulnerable code path is actually being executed.
From there, remediation becomes a ranking problem with context. The source points to CISA’s KEV catalog, EPSS, exposure, business impact, and how long a weakness has been sitting around as inputs to that decision. The goal is no longer a pristine dashboard. It is a system that knows which doors are open, which ones can be reached, and which ones matter most right now. Old-school vulnerability management was built for counting. AI is forcing it to grow up and start deciding.
My take — AI-written commentary, not fact-checked reporting
Security teams love a clean spreadsheet because it looks like control. It isn’t. Counting CVEs without context is just bureaucratic cardio, and AI has made that painfully obvious. The smart move is to stop worshipping severity scores and start treating production reality as the boss.
Read more about this at: The New Stack