AI is making software flaws easier to find. Deciding which ones to fix—and fixing them quickly—is becoming the harder problem.
On September 16, the Cybersecurity and Infrastructure Security Agency (CISA) announced that it will retire its weekly vulnerability bulletin on September 28, emphasizing actual exposure and evidence of exploitation over severity scores alone when prioritizing vulnerabilities.
That same challenge animated TPI’s Aspen panel, What Are Cybersecurity’s Hardest Problems? How should companies and policymakers respond when vulnerability discovery outpaces the capacity to act?
Much of the discussion centered on Anthropic’s Mythos model and Project Glasswing, which gives participating organizations access to advanced AI for defensive cybersecurity work. Panelists described dramatic increases in vulnerability discovery, alongside the potential for AI to shorten the path from finding a flaw to developing an exploit. For organizations accustomed to response times measured in weeks, validating findings, setting priorities, and deploying fixes are becoming increasingly urgent challenges.
Four takeaways
- Severity scores tell only part of the story. Ari Schwartz reported that Glasswing participants saw vulnerability counts rise roughly 150 to 500 times over prior tooling. He also described models chaining low- and medium-severity flaws into critical attack paths, making it harder to prioritize fixes by assessing each vulnerability in isolation.
- Validation is becoming the bottleneck. Elizabeth Chernow said Comcast blocks roughly 11 billion threats a year and described the discovery problem as catching fish faster than they can be cleaned. She said about 90 percent of Comcast’s vulnerabilities come from third-party code and warned that competing reporting clearinghouses could fragment information unless they can work together.
- Security guidance needs to match faster response times. Katerina Megas argued that the core cybersecurity frameworks still hold, but the detailed guidance underneath them needs updating as response times compress from weeks to hours. She described NIST’s work on AI-assisted detection for legacy operational technology, beginning with human oversight.
- Disclosure and accountability remain difficult. Alan Raul argued that existing laws already reach aspects of AI security incidents, while questions remain about which standards apply to AI applications and who must report what. He also warned that public vulnerability disclosure can leave smaller organizations exposed when they lack the resources to patch quickly.
Speakers: Elizabeth Chernow, Comcast; Katerina Megas, NIST Cybersecurity for IoT Program; Alan Raul, Harvard Law School and Future of Privacy Forum; and Ari Schwartz, Venable.
Moderator: Shane Tews, Logan Circle Strategies.