ENISA Warns AI Could Weaponize New Vulnerabilities in Just 15 Minutes
The European Union Agency for Cybersecurity (ENISA) warns that frontier AI could shrink the time needed to weaponize newly discovered vulnerabilities to just 15 minutes, as Security Affairs writes.
The warning comes from ENISA’s July 2026 report, Cybersecurity in the Frontier AI Era, which argues that AI is accelerating nearly every stage of a cyberattack, from reconnaissance and exploitation to data theft.
AI is dramatically speeding up cyberattacks
ENISA says the median time between an initial compromise and data theft can now fall to around 72 minutes.
More concerningly, attackers could potentially weaponize a newly discovered vulnerability within 15 minutes.
AI-powered systems can automate work that previously required substantial manual investigation and technical expertise, allowing attackers to move much faster than traditional security teams.
AI tools are finding far more vulnerabilities
ENISA also highlighted an organization that previously identified around 80 CVEs per quarter.
After introducing AI tools, that figure reportedly jumped to roughly 500 vulnerabilities per day.
The increase shows how AI can dramatically scale vulnerability discovery and analysis, creating a growing challenge for organizations that still rely on slower manual processes.
ENISA warns of an “Authority Gap”
ENISA describes another emerging problem as the “Authority Gap.”
The term refers to situations where internal approval and decision-making processes take longer than an automated attack needs to establish persistence inside a network.
Security teams may identify a serious issue quickly, but manual review, authorization, and remediation procedures can prevent them from responding at the same speed as AI-powered attackers.
That could make traditional vulnerability management workflows increasingly ineffective.
ENISA wants organizations to automate remediation
ENISA recommends shifting resources away from simply finding more vulnerabilities and toward faster prioritization and remediation.
Organizations can use automated triage systems such as the Exploit Prediction Scoring System (EPSS) and Vulnerability Exploitability Exchange (VEX) to identify which flaws require the fastest response.
ENISA also recommends maintaining accurate asset inventories so security teams can immediately prioritize critical systems.
The agency says organizations should aim for detection and response times measured in single-digit minutes as attack automation continues to improve.
AI can also help defenders address vulnerabilities at scale. Microsoft’s September 2026 Patch Tuesday updates, for example, fixed 966 vulnerabilities.
However, some flaws can still bypass those security improvements. The recently disclosed ShieldCrash vulnerability showed that even fully updated Windows systems can remain exposed.
ENISA’s warning suggests organizations may need to rethink vulnerability management entirely as AI continues to compress attack timelines from days or hours to minutes.
Read our disclosure page to find out how can you help Windows Report sustain the editorial team. Read more
User forum
0 messages