Adapting app security for an AI-accelerated threat timeline
Attackers now weaponize flaws in hours — about four hours in 2026 versus 771 days in 2018 — and experts urge continuous inventory, scanning and runtime protections.
Attackers are exploiting software vulnerabilities in hours rather than months. Joshua Goldfarb, Field CISO at F5 and former chief of analysis at US-CERT, cites a decline from an average of 771 days in 2018 to roughly four hours in 2026.
Goldfarb wrote that attackers are using AI and automation to find flaws, develop exploits and launch attacks much faster. He warned that organizations relying on quarterly or annual risk reviews will be unable to keep pace.
He recommended maintaining an accurate, up-to-date inventory of applications, APIs and embedded AI models so security teams know what needs protection. “We cannot protect what we do not know about and what we cannot see,” he wrote.
Goldfarb urged a shift from periodic to continuous risk assessment and continuous vulnerability scanning so threat profiles and exposures are refreshed as code, dependencies and configurations change.
When patches are available, he called for streamlined patching workflows that remove organizational and technical obstacles. He added that enterprises should tighten preventive controls such as access restrictions and input validation when immediate patching is not possible.
Goldfarb highlighted runtime protections that detect and block attacks in real time across applications, APIs and AI layers, and said signature-based detection alone is insufficient given the shortened exploit timeline.
He also recommended building or buying threat intelligence to identify emerging techniques and imminent attacks, and suggested protections against agentic AI, including bot and DDoS defenses, mechanisms to detect automated or abusive users, and continuous monitoring of agent activity.
Goldfarb noted that wider deployment of machine learning models and large language models in customer-facing services increases the attack surface, and he recommended runtime protection specifically for models and natural language prompts.
His experience in incident response and analysis, including roles at FireEye and US-CERT, informed his guidance. He wrote that organizations will need to reassess budgets, operations and tooling to support continuous security practices as exploit timelines compress.








