The Cyber Risk Eruption you missed.

Introduction

There is a major shift in attackers' capabilities, and you need to know about it. An underestimated threat puts your company or your customers at risk. There are currently three major changes that will make it important to fundamentally adjust your risk assessment.

The Eruption

If an attacker has a zero-day (0-day) exploit for a previously unknown remote code execution (RCE) vulnerability, then many security measures are useless. A 0-day is the laser sword when it comes to cutting butter.

In the pre-2000s, writing 0-day exploits was reserved for only a few exceptional talents in the world. Often, these talents were found in countries that offered the necessary level of education and access to computers and network technologies.

In the years that followed, the knowledge spread more and more; zero-days could be bought on gray markets by criminals, government agencies, or companies (also see This Is How They Tell Me the World Ends). Around the same time, companies were founded that acted as exploit brokers; well-known examples include iDefense, ZDI (Zero Day Initiative), and Vupen.

Commercialization and technical improvements in this area have advanced, but little has changed the situation in recent decades. Specialists develop exploits, which are then purchased and used (or taken off the market) by powerful buyers for large sums of money.

For the CISO community, this meant that an attacker with a zero-day exploit would have substantial resources (money and technical expertise) and would use them only to a limited extent for valuable targets. This is because a zero-day exploit is often “burned” after a few uses, as security analysts will reconstruct the attack.

What was correct under the old assumption is no longer correct. The situation has changed fundamentally. Zero-day exploits will become cheap off-the-shelf products. And here is why:

  1. The time-to-exploit has decreased
  2. AI-based software vulnerability search is real
  3. AI-orchestrated hacking platforms allow large-scale hacking for inexperienced threat actors

As a result, we have generally underestimated the threat posed by attacks using zero-day exploits.

Time-to-Exploit, only 1.1 days in 2026

On the Zero Day Clock website, you can see how long it takes to exploit a commonly known vulnerability and develop an exploit (Time-to-Exploit, TTE). In 2020, it took more than a year to develop the exploit; today (2026), it is only 1 day.

This fact alone is alarming because, for CISOs and CIOs, it means that all exposed systems should typically receive security updates within a day.

For manufacturers, it means that the updates — sufficiently tested — must be available to all customers upon publication of the CVE ID.

Zero Day Clock Data Diagram
Source: https://zerodayclock.com/Zero Day Clock, 2026–03–30

However, this does not yet describe the situation for zero-day exploits, because by definition, these exploits are available before they become public knowledge, for example, by publishing a new CVE ID.

According to Zero Day Clock, there has been an increase in attacks using zero-day exploits.

Zero Day Exploit Attack Trends
Source: https://zerodayclock.com/Zero Day Clock, 2026–03–30

For CISOs and CIOs, this development means that the probability of being hit by a zero-day exploit has theoretically increased by about 30% in the last two years. And this makes it clear that patching critical security vulnerabilities quickly alone is not enough. To minimize the risk here, it is necessary to reduce the attack surface, raise user awareness, and practice and optimize rapid incident response and recovery.

Manufacturers must significantly improve the quality and maintenance of their products; this works only in tandem with the legislator (Cyber Resilience Act | Shaping Europe’s digital future) to create a fair market of secure products and services.

(For fun: I Hacked This Temu Router. What I found should be illegal.)

More, faster, cheaper: AI-based vulnerability search

A few weeks ago, Anthropic published an article (Partnering with Mozilla to improve Firefox‘s security \ Anthropic) describing how Claude Opus found 22 previously unknown vulnerabilities in Firefox, 14 of which were classified as “high-severity”.

Anthropic Mozilla Firefox Security Findings
Source: https://www.anthropic.com/news/mozilla-firefox-security, 2026–03–30

Greg Kroah-Hartman, Linux kernel developer and former colleague, sums up the situation in an interview as follows: “Something happened a month ago, and the world switched. […]” (Linux kernel czar says AI bug reports aren’t slop anymore • The Register)

For security and IT managers in industry, government agencies, and NGOs, the situation will worsen because we only see one side of the coin. The good side, which searches for vulnerabilities and publishes them. But the other side, the underside, which lies in the shadow and eludes our view, will also already use this technique.

We first saw that exploits are being developed faster and faster, that zero-day exploits are being used more and more often, and that we have only recently seen AI models find critical security vulnerabilities.

Manufacturers should use the AI models to systematically increase the quality of their products and digital services.

Developer platforms, such as github.com, could scan the software repos for vulnerabilities and give the Git projects a “security score.”

Sophistication, large-scale: AI-orchestrated hacking platforms

However, this does not fully describe the eruption of cyber risks that I perceive. Because the hurdle for attackers drops even further, as we saw at the beginning of the year. At the beginning of 2026, around 600 Fortinet systems across 55 countries were compromised by a threat actor. (AI-augmented threat actor accesses FortiGate devices at scale | AWS Security Blog). This is a large-scale attack by a threat actor, increasing their power by using AI.

CyberStrikeAI (Cyberstrike — AI-Powered Penetration Testing Agent) and PentAGI (PentAGI — Advanced AI-Powered Penetration Testing) are already well known and are actively used to make it easier for inexperienced attackers to get started and to drive up the number of attacks.

Conclusion

In my opinion, AI has become a real security problem. In recent years, the CISO community has viewed AI as a threat due to its potential to improve phishing and fraud. But the world is a different place today!

Summary:

  • Publicly known vulnerabilities are exploited on average within 1 day.
  • The number of zero-day exploits has increased by ~30% over the past two years.
  • AI models can identify software vulnerabilities that were previously reserved for human experts.
  • Zero-day exploits will thus become cheaper and more readily available.
  • The number of zero-day exploits used in attacks will continue to rise, as criminals and state actors can leverage them more frequently.
  • This means a fundamental change in the threat landscape and thus an urgent adaptation of cybersecurity strategies to the new reality.
  • Manufacturers and independent developers must significantly increase speed and quality.

Zero-day exploits are becoming commonplace. For small and medium-sized companies, for which an attacker did not want to “burn” his valuable zero-day in the past, it could be done today, putting these SMEs at risk. This increases the frequency and probability of many “will never happen anyway” or “does not affect us” cyber risks.

This gives weight to old security wisdom again:

  1. Reduce Attack Surface
  2. Defense in Depth
  3. Short patch cycles
  4. Regular emergency drills
  5. Regular recovery tests

Dear CISO community, check your assumptions and risk assessments. Does your security strategy still fit the current threat landscape?

Popular posts from this blog

This is how every organization works. - The ‘Business Problem Handling Life-Cycle’ Model