{"id":2824,"date":"2026-09-14T13:20:33","date_gmt":"2026-09-14T13:20:33","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2824"},"modified":"2026-09-14T13:20:33","modified_gmt":"2026-09-14T13:20:33","slug":"ai-changed-the-exposure-problem-validation-needs-to-change-with-it","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2824","title":{"rendered":"AI Changed the Exposure Problem. Validation Needs to Change With It."},"content":{"rendered":"<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEid_ratIPK3F0IGyzyDTTPaV26Nnh4gQoFjS0ejR49J_tbGb92GgukT-Mnr9xv9mK7h0QSdeXujxiEtD0AqVKNmrKoG9BMEuut7CB1368iyt3Gr6Xu5mAdkDsUQC86K9GZ-Uw6qfPvYYr9BUvHzn014_rzQeMS5dCVXEwkRLs3eViylo5ChmZs6QQygxE4\/s1700-nu-rw-lo-l85-e365\/picus-main.jpg\" style=\"clear: left; display: block; float: left;  text-align: center;\"><\/a><\/div>\n<p>There&#8217;s a lot of noise around AI and cybersecurity right now. What\u2019s actually important is far simpler, if often lost in the hubbub. <strong>Vulnerability discovery is getting faster and happening at a much greater scale, while defenders still have to work out which findings actually deserve their action.<\/strong><\/p>\n<p>In the first half of 2026, a whopping 35,853 CVEs were published, <a href=\"https:\/\/zerodayclock.com\/\" target=\"_blank\">roughly 49%<\/a> more than in the year before. Yet only <a href=\"https:\/\/www.vulncheck.com\/blog\/state-of-exploitation-1h-2026\" target=\"_blank\">495 were catalogued<\/a> as exploited in the wild during that same period, and 116 were already under attack on the day they became public. Meanwhile, Anthropic\u2019s own <a href=\"https:\/\/red.anthropic.com\/2026\/cvd\/ledger\/\" target=\"_blank\">disclosure data<\/a> shows Mythos-class models surfacing 26,153 vulnerability candidates in open-source software, with only <a href=\"https:\/\/red.anthropic.com\/2026\/cvd\/\" target=\"_blank\">421 of those<\/a> getting patched upstream.<\/p>\n<p>That small exploited subset is a very important point. It tells defenders that <strong>treating every vulnerability with a High or Critical CVSS rating as an emergency is not only impossible, it\u2019s actually the wrong model<\/strong>. The critical task security teams face is <strong>deciding which exposures, on which assets, require immediate action<\/strong>, especially as both the number of findings grows and the gap between disclosure and exploitation narrows.<\/p>\n<h2><strong>The CVSS Alone Can\u2019t Tell You What Matters in Your Environment<\/strong><\/h2>\n<p>The same CVE can affect hundreds of assets, but the <strong>impact is rarely the same across them<\/strong>. Some instances are unreachable. Some sit behind controls that interrupt the techniques required for exploitation. Others are exposed on business-critical systems where prevention fails, and detection never fires.<\/p>\n<p><strong>The CVSS gives you a common severity baseline. It can\u2019t give you the context that determines impact to your organization.<\/strong><\/p>\n<p>This is why defenders need evidence from their own environment to find out whether the exposure is actually exploitable, which assets it affects, and whether those assets are reachable and important to the business. As vulnerability volume grows, this distinction becomes more and more important.<\/p>\n<h2><strong>Automated Pentesting Alone Can\u2019t Validate Every Exposure<\/strong><\/h2>\n<p>Once you move beyond severity scores, automated pentesting gives you some of the strongest evidence you can gather. It can run real exploits, prove that an exposure is exploitable in your environment, chain vulnerabilities, credentials, and misconfigurations into attack paths, and show how far an attacker could actually progress across your network.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>Yet coverage remains limited in practice. <strong><a href=\"https:\/\/go.synack.com\/ai-pentesting-report-omdia\" target=\"_blank\">Omdia research<\/a><\/strong> <strong>found that while 95% of organizations rank pentesting as a top or high priority, only 32% of their average attack surface is tested each year.<\/strong> Agentic and automated approaches can expand that coverage, but they don\u2019t remove every <strong>constraint of live exploitation<\/strong>.<\/p>\n<p><strong>For CVE-based exploitation, a working exploit still has to exist, and the target has to be safe to test.<\/strong> Newly disclosed CVEs may have no working exploit yet, while it simply may not be possible to test a live exploit on business-critical, restricted, and air-gapped assets. Those exposures still need an exploitability verdict, even when there\u2019s nothing an automated pentest can safely run.<\/p>\n<p>This is the gap automated pentesting can\u2019t close on its own. It\u2019s <strong>a required part of validation<\/strong>, but <strong>it can\u2019t validate every exposure<\/strong>.<\/p>\n<h2><strong>All for One. One for All Exposures.<\/strong><\/h2>\n<p>This is where the pieces come together.<\/p>\n<ul>\n<li><strong><a href=\"https:\/\/www.picussecurity.com\/platform\/exposure-validation\" target=\"_blank\">Exploitability validation<\/a><\/strong> determines whether an exposure is, in fact, exploitable in your environment, including CVEs with no working exploit and assets that live exploitation can\u2019t safely reach. <\/li>\n<li><strong><a href=\"https:\/\/www.picussecurity.com\/platform\/breach-and-attack-simulation\" target=\"_blank\">Security control validation<\/a><\/strong> tests whether your prevention and detection controls actually block, detect, or miss the attack. <\/li>\n<li><strong><a href=\"https:\/\/www.picussecurity.com\/platform\/autonomous-penetration-testing\" target=\"_blank\">Agentic pentesting<\/a><\/strong> safely runs real exploits and chains exposures to show how far an attacker can progress through your specific environment.<\/li>\n<\/ul>\n<p>These methods answer different questions under different exposure conditions. <strong>Mythos readiness requires all three capabilities, brought together in one platform with the same goal: validating exposures across your unique environment.<\/strong> This doesn\u2019t mean you have to always use all three against every exposure. The goal is to <strong>apply each method where it fits best <\/strong>and let the <strong>evidence contribute to the same decision process<\/strong>.<\/p>\n<p>These three key pieces become even more powerful when they operate as one program. A <strong>finding can trigger the validation step it actually needs<\/strong>, <strong>new evidence can change remediation priority<\/strong>, and <strong>fixes can be re-validated<\/strong> instead of disappearing into a closed ticket. That keeps exploitability, control effectiveness, and attack-path evidence connected instead of leaving them to wallow in separate workflows.<\/p>\n<p>This is also where <a href=\"https:\/\/www.gartner.com\/en\/documents\/7851581\" target=\"_blank\">Gartner\u00ae\u2019s May research<\/a> note points: toward validated attack paths, decision-driven response, and exposure reduction all integrated into operational workflows.<\/p>\n<p>This also happens to be the working model behind our<strong><a href=\"https:\/\/hubs.li\/Q04x66s80\" target=\"_blank\"> Validation Summit \u201926<\/a><\/strong>.<\/p>\n<h2><strong>What Security Experts See and How Leading Enterprises Put Validation Into Practice<\/strong><\/h2>\n<p>On October 14 and 15, Picus Security will host The Validation Summit \u201926 to bring together an independent view of what&#8217;s changed, our approach to validation, and lessons from security leaders who\u2019ve already put it into practice.<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/hubs.li\/Q04x66s80\" style=\"clear: left; display: block; float: left;  text-align: center;cursor:pointer\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjFe8q0GPCViyrKxRdTylzDehtChrMSgg73BQE40qiNffZYNkUpmNA2bd0jFnmCEgjUzG_LgqlqJyOm2K6VTI3LwuDc2gwBibPucEmG7iiUns-oHrNtv1VCuvOYfATbx8H1sPKc5ncPzX925VOhP3Ygu3d37HCT1lKuxyDWJUTm46j9W9x6lxPAceXnWgs\/s1700-nu-rw-lo-l85-e365\/HTN.png\" alt=\"\" border=\"0\" data-original-height=\"380\" data-original-width=\"728\"\/><\/a><\/div>\n<p><strong>Mikko Hypp\u00f6nen<\/strong> will open with why this shift is different from past ones. <strong>Picus CTO Volkan Ert\u00fcrk<\/strong> will then lay out what security validation needs to look like when attackers are powering their attacks with AI, and why exploitability validation, security control validation, and agentic pentesting work better together than on their own. The Picus team will then show the validation workflow<strong> live with a newly disclosed vulnerability.<\/strong> It starts with no patch and no working exploit, moves through validation before a PoC exists, tests the exploit against live controls once it appears, and then re-validates after the fix.<\/p>\n<p>Then security leaders from <strong>Chanel, Atlassian, and the NFL<\/strong> will discuss what this looks like inside real enterprise environments: how mature security teams are adapting their validation programs, what they\u2019ve changed, and the successes and failures they\u2019ve experienced along the way.<\/p>\n<p><strong>Two hours. One validation blueprint.<\/strong> <a href=\"https:\/\/hubs.li\/Q04x66s80\" target=\"_blank\">Join us for the Picus Validation Summit \u201926.<\/a><\/p>\n<p>Note: <em>This article was written by <a href=\"https:\/\/www.linkedin.com\/in\/silaozeren\/\" target=\"_blank\">Sila Ozeren Hacioglu<\/a>, Security Research Engineer at Picus Security.<\/em><\/p>\n<div class=\"cf note-b\">Found this article interesting? <span class=\"\">This article is a contributed piece from one of our valued partners.<\/span> Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqLQgKIidDQklTRndnTWFoTUtFWFJvWldoaFkydGxjbTVsZDNNdVkyOXRLQUFQAQ\" rel=\"noopener\" target=\"_blank\">Google News<\/a>, <a href=\"https:\/\/twitter.com\/thehackersnews\" rel=\"noopener\" target=\"_blank\">Twitter<\/a> and <a href=\"https:\/\/www.linkedin.com\/company\/thehackernews\/\" rel=\"noopener\" target=\"_blank\">LinkedIn<\/a> to read more exclusive content we post.<\/div>\n<\/div>\n<p><script async src=\"\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"<p>There&#8217;s a lot of noise around AI and cybersecurity right now. What\u2019s actually important is far simpler, if often lost in the hubbub. Vulnerability discovery is getting faster and happening&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2825,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[3398,1417,603,89,692],"class_list":["post-2824","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-change","tag-changed","tag-exposure","tag-problem","tag-validation"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2824","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2824"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2824\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2825"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2824"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2824"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2824"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}