October 10, 2026
The time to close the cyberattack door is shrinking fast
I’ve been speculating about the impact of AI on cybersecurity for a while now: the infinitely patient hacker working at light speed to find…

By Enrique Dans
2 min read
I've been speculating about the impact of AI on cybersecurity for a while now: the infinitely patient hacker working at light speed to find a way in to a system (and there's always a way). Matteo Wong shares my concerns ("How long until AI hacks everything?"), pointing out that organizations previously had about a month to patch over a newly disclosed vulnerability, but that time has been reduced to 24 hours and could soon be as little as 30 minutes.
AI is making it much harder and costlier to manage the vulnerabilities we've always known existed. Traditionally, launching an attack on a system required not only very specialized knowledge, but a lot of time and patience. Now, a specialized agent is increasingly within anyone's reach, and that agent is perfectly capable of analyzing software, generating code to exploit a vulnerability and testing it against a few thousand targets. Suddenly, anyone, be it a small company, a city council or even a specific user, can become potentially profitable targets, because the marginal cost of attacking them tends to zero.
The number of vulnerabilities disclosed has more than doubled from 5,045 in January 2026 to 10,740 in August, and although only 0.23% of them were exploited, that already means going from a monthly average of 10.5 in 2025 to 18 in 2026. And this is only the beginning. The real game changer is the time organizations have to react: 88% of attacks against vulnerabilities with a public proof of concept took place within 48 hours, and some groups linked to China acted in less than 24 hours. Google even documented an automated campaign built and executed in under six hours.
For someone who wants to launch an automated attack, the consequences are practically nil. But for those who try to defend against it, it can mean having to launch updates in a hurry, stop systems and cause critical functionalities to stop. In a hospital, for example, it can involve interrupting diagnoses, dispensing medication or treating cancer. In fact, the American Hospital Association recommends that hospitals prepare to maintain patient care for up to 30 days without connected systems. Would your company be able to? Most companies' weakest link is their internet connection.
To make matters worse, it turns out that organizations themselves are also dramatically increasing their attack surfaces by deploying loosely credentialed agents, chatbots connected to internal data, employees using AI accounts outside of corporate control and vibe-coding apps. Corporate AI has gone from being a tool to being a target and access channel.
OpenAI's "access" to Australian government websites and services in June show that the problem will not be solved simply by installing the umpteenth security product. As a result of these incidents, the Australian government ordered all its agencies to identify and retire all obsolete systems: now, technical debt is no longer simply an accounting nuisance, it is national threat.
Wong concludes his piece by saying the only way to protect ourselves from AI is with more AI. It's a catchy phrase, but the reality is much more complex: as well as defensive agents, we're going to need reliable inventories, redundant systems, segmentation, the ability to continue working offline and products that are secure by design and default. The time it takes to close a door in our system is getting shorter and shorter; we can't put finding a solution off any longer.
(En español, aquí)