Skip to main content
Cybersecurity

How cybersecurity pros can handle a tide of AI-discovered vulnerabilities

One expert suggests cybersecurity pros “will not and cannot get to everything.”

• less than 3 min read

TOPICS: Cybersecurity / Endpoint & Device Security / Patch Management

AI agents are starting to do more than access systems. They can invoke tools, execute workflows, and take action across business applications. As that autonomy grows, IT needs visibility into what each agent is allowed to do, what it actually did, who owns it, and how to revoke access when needed. Learn how JumpCloud helps govern AI agents alongside human and device identities.

Over the past several months, AI tools have uncovered a tide of vulnerabilities within IT infrastructure. While that has alerted organizations to lurking zero-day exploits and other issues, it presents an issue for cybersecurity teams: What’s the best way to handle this deluge of problems to address, especially with limited staff?

In September, the Google Threat Intelligence Group (GTIG) reported that AI is “measurably changing not just the pace of vulnerability discovery and exploitation, but also the types and typical risk profiles of vulnerabilities that are being discovered.” According to the report, vulnerability disclosures doubled between January and July 2026.

When it comes to this increase in vulnerabilities, experts like CDW CISO Aaron McCray also caution about false positives and alert fatigue.

“False positives are generating more alerts that a human could actually review and take a look at,” McCray said. “The thing about AI, it’s really going to be determined on the provider of that solution now.”

Patching with haste. Stephen Boyer, co-founder and CIO at cybersecurity company Bitsight, said that while IT and security professionals “will not and cannot get to everything” that needs to be fixed, they can prioritize vulnerabilities that attackers are exploiting.

“If the threat actors are exploiting systems that I don’t have, okay, that’s the context, I don’t have to worry about those,” Boyer said. “But if I have them, and the threat actors are exploiting, those are the ones I want to prioritize first.”

Best buds. Cybersecurity pros can also prioritize vulnerabilities by implementing third-party cyber threat intelligence, which offers information about attackers’ current targets. Boyer suggested those intelligence partners can help organizations stay ahead of new exploits by surveying underground forums and looking for trends within cyberattacker communities.

“Depending upon what kind of information you get there is where you would want to focus on the vulnerability-specific side,” Boyer said. “That is where you want to understand what are the systems now being exploited or targeting and impacting me, and then how would I prioritize it from there.”

About the author

Caroline Nihill

Caroline Nihill is a reporter for IT Brew who primarily covers cybersecurity and the way that IT teams operate within market trends and challenges.

From cybersecurity and big data to cloud computing, IT Brew covers the latest trends shaping business tech in our 4x weekly newsletter, virtual events with industry experts, and digital guides.

By subscribing, you accept our Terms & Privacy Policy.