Close Menu
NCIJ Network NCIJ Network
    What's Hot

    New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

    August 11, 2026

    Nvidia’s $500 billion AI infrastructure push leaves crypto compute further behind

    August 11, 2026

    Voyager 2 was running out of power. NASA just bought it more time

    August 11, 2026
    Facebook X (Twitter) Instagram
    Trending
    • New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA
    • Nvidia’s $500 billion AI infrastructure push leaves crypto compute further behind
    • Voyager 2 was running out of power. NASA just bought it more time
    • Permian Basin Community Seeks Fix for Radium in Its Drinking Water
    • Expro scores ‘major’ North Sea plug and abandonment win in UK waters
    • Is There Anyone Who Can Respond to My FOIA Requests? — ProPublica
    • MPs shouldn’t face abuse. Neither should their staff – but here’s what we deal with every day | Estelle Warhurst
    • Did Albert Einstein marry one of his cousins?
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, August 11
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Artificial Intelligence

    How AI is changing the vulnerability response timeline

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 11, 2026 Artificial Intelligence No Comments5 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Artificial intelligence is giving security researchers new ways to examine code, trace unusual behaviour and identify flaws that conventional tools may overlook. The pressure is particularly visible around Zero-day vulnerabilities, a recent Minimus analysis considers how container composition, dependency records and rebuild speed affect the response after an unknown flaw is exposed. Faster analysis helps only when organisations can also establish where the vulnerable software is running.

    In May 2026, Google Threat Intelligence Group reported the first case in which it believed a threat actor had used AI to help develop a zero-day exploit. The exploit appeared in a Python script and bypassed two-factor authentication on a widely used open-source system administration tool when valid credentials were already available.

    Researchers said they had high confidence that an AI model assisted with both discovery and weaponization. Their assessment drew on the script’s unusually detailed instructional comments, a fabricated vulnerability score and a highly structured coding style associated with generated output. Google did not claim that the wider operation was autonomous or attribute the code to a particular model.

    The flaw itself is what makes the case significant. It involved a hard-coded trust assumption rather than a crash, memory error, or unsafe input. Fuzzers and static-analysis tools are well suited to finding many conventional implementation problems. A language model can also examine how permissions, functions and expected behavior interact across a codebase. That creates another route to finding logical contradictions that leave no obvious technical trace.

    Google’s wider data suggests this was not an isolated concern. According to Google Threat Intelligence Group’s 2025 analysis, researchers tracked 90 zero-days exploited in the wild during 2025, compared with 78 in 2024. Enterprise software and appliances accounted for 43 cases, or 48% of the total. Both figures were records in Google’s dataset.

    Complex containers make exposure harder to trace

    Once a flaw becomes public, security teams first have to work out where it is running. That can be difficult inside a container environment. An image may contain operating-system packages, application libraries and dependencies inherited from its base image, alongside shells or utilities with little connection to the workload’s visible purpose.

    A vulnerable component can therefore sit several layers below the application itself. It may appear across numerous images even when the organisation never added it directly.

    Log4Shell exposed this problem at scale in 2021. The affected Log4j library had been incorporated into a wide range of products and services. For many organisations, obtaining the patch was only the beginning. They still had to identify every server, application and container carrying a vulnerable version before they could complete remediation.

    Software bills of materials provide a clearer record of what each image contains. Smaller images can also reduce the search by excluding packages that the workload does not need. Minimus examines the issue through package reduction, dependency visibility and the rebuilding of images after an affected component is disclosed.

    The benefit is simpler than preventing zero-days altogether. A minimal image can still contain an unknown flaw. It gives teams fewer packages to investigate, fewer possible exposure points and less software to replace or retest once the problem becomes known.

    AI-generated fixes still need software context

    AI is also being used to shorten the time between disclosure and patch development. Models can inspect source code, compare vulnerability reports with package records and propose changes for affected versions. None of that is especially useful when package records are outdated or nobody knows which images contain the vulnerable component.

    Earlier coverage of an AI agent designed to automate vulnerability fixes detailed how Google DeepMind’s CodeMender contributed 72 security fixes to established open-source projects during its first six months. The system combines model reasoning with static analysis, runtime testing and fuzzing to produce and assess proposed patches.

    Those patches were not accepted automatically. Human researchers reviewed each change before it was submitted, checking for regressions and confirming that it addressed the underlying cause rather than only the visible symptom.

    Even an approved code change does not finish the job. Teams must identify the affected images, rebuild them with the corrected dependency and test the result before deployment. In a poorly documented environment, locating every instance may take longer than producing the patch itself.

    Accurate inventories give automated tools something concrete to work with. They connect a newly disclosed flaw to the package version, image and workload that actually require attention.

    Finding the flaw may no longer be the slowest step

    AI is speeding up code analysis for both attackers and defenders, but many delays still occur after a vulnerability has been identified. One team may spend hours opening images and checking package lists by hand. Another can search a current inventory and see almost immediately which workloads contain the affected version.

    That difference has little to do with the sophistication of the discovery tool. It comes from decisions made earlier about software inventories, image composition and how containers are built and replaced. As vulnerability research moves faster, the practical advantage belongs to organisations that can establish exposure and deploy a tested repair without first trying to reconstruct what their systems contain.

    changing Response Timeline Vulnerability
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    Implementing a MiniMax-H3 Multimodal Video and Audio Generation Pipeline with ComfyUI APIs

    webAI Releases TwIL-LM: A 1.7B and 3B Formal-Logic Model Family for Autoformalization on Local Hardware

    Premium seats are coming to ChatGPT Business

    Putting frontier cyber models in more trusted hands

    Meta AI Releases Muse Glimmer: A 30B Open-Weights Agentic Model That Runs on One Consumer GPU

    Siemens’ physics AI can run 1,000x faster. It still won’t sign off your airbag” for the meta field

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

    August 11, 2026

    Nvidia’s $500 billion AI infrastructure push leaves crypto compute further behind

    August 11, 2026

    Voyager 2 was running out of power. NASA just bought it more time

    August 11, 2026

    Permian Basin Community Seeks Fix for Radium in Its Drinking Water

    August 11, 2026
    Latest Posts

    Harbour Energy’s US arm advances repair plan after riser leak at Gulf of America oil & gas asset

    July 24, 2026

    Beavers restored a volcano-scarred river. Now it’s at risk again

    July 24, 2026

    China’s Tianwen-1 captures interstellar comet 3I/ATLAS near Mars

    July 24, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

    August 11, 2026

    Nvidia’s $500 billion AI infrastructure push leaves crypto compute further behind

    August 11, 2026

    Voyager 2 was running out of power. NASA just bought it more time

    August 11, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.