TLDRocket
Sign in

Virtual patching closes the gap as AI erases the patch window

SiliconANGLE Kristen Nicole

AI is shrinking the time between a flaw being announced and being attacked. That’s why companies are turning to virtual patching to cover holes before the real fix lands.

Based on reporting by SiliconANGLE, Kristen Nicole — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

Patch Tuesday used to give defenders a brief breathing room. That window is disappearing fast. Automated scanners can now turn a newly disclosed bug into a working attack within hours, which leaves security teams scrambling for something that can hold the line while the real patch gets tested and deployed.

That is where virtual patching comes in. Instead of waiting on the application to be fixed, the protection sits at the network layer and blocks traffic aimed at a known weakness. John Maddison, F5’s chief marketing officer and head of technology alliances, said customers want that kind of cover because the gap between disclosure and exploitation is collapsing. He described a world where security has to inspect traffic in real time and stop zero days before they reach their target.

F5 is also leaning on the same idea with CrowdStrike. The two companies put the Falcon sensor directly on F5’s BIG-IP appliances, which sit at the network perimeter, so CrowdStrike can treat that traffic like endpoint activity. More than 200 customers were already using the integration before it was formalized, and the measured overhead was only 1% to 2%. That trade-off, Maddison said, is easier to accept now than the old choice between speed and inspection.

The urgency is not hypothetical. CrowdStrike’s research says AI-enabled adversary activity rose 89% year over year, average breakout time fell to 29 minutes, and the fastest recorded intrusion took 27 seconds. F5 is now applying similar thinking to AI gateways too, including a new partnership with Salesforce’s MuleSoft. The message is blunt: if attackers are using AI to move faster, security products have to do the same.

Maddison’s broader point is that the old separation between network gear and endpoint security is getting fuzzy. Even the protection layer itself is turning into an AI problem. And that is probably the right direction, because the patch window is not coming back.

My take — AI-written commentary, not fact-checked reporting

The industry spent years pretending patching speed was a process problem. It’s now an attack problem, which is a much nastier bill to pay. The boring answer is the right one here: push more enforcement to the edge, inspect more traffic, and stop waiting for every fix to arrive in perfect order.

Read more about this at: SiliconANGLE

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.