What happens when artificial intelligence can find vulnerabilities faster than businesses can patch them?

That is no longer a theoretical question. Palo Alto Networks Unit 42 recently reported that its autonomous AI vulnerability research system, NOVA, analyzed 3,915 open-source projects in two months and uncovered 14,090 confirmed vulnerabilities. According to Unit 42, 99.4% were previously unreported, and 39.7% scored High or Critical under CVSS 4.0.

For business leaders, the issue is bigger than another surge in CVEs. AI is compressing the time between vulnerability discovery, proof-of-concept development and potential exploitation. That puts more pressure on patching, detection and response processes that already operate under significant time constraints.

Key Takeaway: AI can dramatically accelerate vulnerability discovery and exploit development, making it increasingly difficult to depend on patching and detection alone. Businesses should continue both, but also consider controls that restrict what an attacker can do after a vulnerable Windows application is exploited, even when the vulnerability was previously unknown.

So what exactly did Unit 42 discover?

Unit 42 demonstrated that agentic AI can autonomously find and validate vulnerabilities at substantial scale. Its NOVA research system reviewed source code, identified vulnerability candidates, created working proofs of concept, validated them in clean environments, generated patch candidates and produced disclosure reports.

The numbers are significant: 14,090 confirmed findings across 3,915 open-source projects. Only 85 matched vulnerabilities already in public sources when Unit 42 checked the findings against the public record.

The research also exposed supply-chain implications. Unit 42 reported 5,421 supply-chain findings, including 4,141 downstream exposures. In 2,776 of those downstream exposures, NOVA validated exploitability from the downstream application using a working proof of concept.

Why does this matter to businesses?

It changes the economics and speed of vulnerability discovery. Tasks that historically required specialized researchers and substantial time can increasingly be automated and run across thousands of software targets.

Unit 42 describes the result directly: “the patch window has collapsed.” The company notes that the industry average to deploy a traditional patch is 55 days, while AI-assisted discovery can move much faster.

That gap creates practical business risk. Organizations still need time to identify affected assets, prioritize vulnerabilities, obtain vendor fixes, test patches and deploy them without disrupting operations. In manufacturing, healthcare, professional services and other uptime-sensitive environments, immediate patching is not always operationally possible.

Does this mean patching and EDR are no longer important?

No. Vulnerability management, patching, EDR and network security remain important layers. Unit 42 itself recommends vulnerability management, zero-trust network architecture, software supply-chain security and attack-surface reduction, while highlighting network-level virtual patching as a way to reduce exposure before conventional patches can be deployed.

But the research raises another question for security leaders: what protects the organization during the period when nobody knows a vulnerability exists?

Detection has a similar challenge. EDR can identify and respond to a great deal of malicious activity, but security strategies should assume some novel, polymorphic, fileless or AI-generated activity may not be recognized quickly enough to prevent every damaging action.

What if you did not have to detect the attack in order to stop it?

This is where Isolation and Containment changes the security question. Instead of asking only whether security tools recognize the exploit, organizations can also restrict what applications and processes are allowed to do on the endpoint.

A zero-day may be unknown, but exploiting the vulnerability is usually not the attacker's final objective. The attacker still needs the compromised environment to do something useful, such as launch processes, manipulate files, access memory, establish persistence, abuse trusted applications, reach sensitive resources or encrypt data.

Changing the attack does not necessarily change the endpoint actions the attacker ultimately needs in order to succeed.

This is particularly relevant as AI makes it easier to generate new code, modify attacks and iterate rapidly. We explored the same broader issue in AI Built a Worm: What Happens When It Targets Windows?

Where does AppGuard fit?

AppGuard adds a prevention layer focused on restricting endpoint behavior rather than first identifying an attack as malicious. It does not patch the vulnerable software, replace EDR or eliminate the need for vulnerability management.

AppGuard is a proven endpoint protection solution with more than a decade of production history focused on prevention through Isolation and Containment. On Windows endpoints, its policies can restrict unauthorized application behavior and constrain trusted applications from performing actions outside their intended boundaries.

That distinction matters in a zero-day scenario. AppGuard does not need to know the name of every attack to restrict endpoint behaviors the attack may require. Depending on the application, policy and attack path, containment can limit access to protected files, memory and system resources, restrict unauthorized process activity and reduce the ability of a compromised process to turn initial exploitation into broader endpoint compromise.

The attack may be new. The actions it needs to perform on a Windows endpoint often are not.

Can Isolation and Containment replace virtual patching?

No. These controls address different parts of the problem and can be complementary. Virtual patching seeks to prevent exploitation of a known or newly discovered vulnerability before a software patch can be deployed. Isolation and Containment seeks to restrict what an application or process can do if exploitation reaches the endpoint.

That layered approach becomes increasingly relevant when AI is accelerating both vulnerability discovery and exploit development. Organizations should not assume any single technology will stop every attack.

The larger objective is resilience: reduce the number of paths available to an attacker and reduce the damage possible when another defensive layer fails.

What Should Businesses Do Next?

Businesses should plan for a world in which some vulnerabilities will be discovered and weaponized faster than traditional remediation processes can respond.

  • Continue disciplined vulnerability management and prioritize high-risk, internet-facing and actively exploited systems.
  • Use network segmentation and virtual patching where appropriate to reduce exposure while patches are tested and deployed.
  • Assume some unknown threats may evade initial detection and add prevention layers that do not depend entirely on identifying malicious code.
  • Reduce endpoint execution freedom and unnecessary application privileges.
  • Review which trusted applications can access memory, files, credentials and critical system resources.
  • Test ransomware, zero-day and endpoint-control failure scenarios, not just known malware samples.
  • Evaluate Isolation and Containment where reducing usable Windows attack surface can complement EDR, patching and network defenses.

Unknown does not automatically mean unstoppable

Unit 42's research is an important warning about the scale AI brings to vulnerability discovery. Defenders will need faster discovery, faster remediation and faster protection.

But there is another way to think about the problem.

The objective is not to predict every attack. It is to restrict the actions an attacker needs in order to succeed.

As AI makes attacks easier to change and vulnerabilities easier to discover, that distinction becomes increasingly important. Detection and response remain necessary. Patching remains necessary. But organizations should also ask what happens when both are too late.

For additional perspective on AI-driven attacks and prevention, read The Agentic AI Cyberattack Isn't Coming. It's Here.

Tony Chiappetta
Post by Tony Chiappetta
September 29, 2026