Patching Faster Has Never Been the Answer
Patching is a necessary evil and doing it manually in any decent sized organization was essentially impossible in the pre-AI times and is now pure folly.

Patching is a necessary evil and doing it manually in any decent sized organization was essentially impossible in the pre-AI times and is now pure folly.
October 7, 2026 | 3 min read

RESTON, VA--The hoary Silicon Valley imperative to move fast and break things never really stood up to any serious scrutiny. And in the age of AI and all the absurdity that’s come with it, that phrase has now become some sort of post-irony slogan for people who missed the boat the first time around and are hoping there are still posh seats available on the next one.
Unfortunately, the latest area where that silly idea is being applied at the moment is in the realm of patch management, a component of security programs that is unsexy even in comparison to things like regulatory compliance. Long before AI was (allegedly) compressing time-to-exploit windows and taking years off the lives of security team members, patch management was a painful process that many organizations opted to automate, and for good reason. Patching is a necessary evil and doing it manually in any decent sized organization was essentially impossible in the pre-AI times and is now pure folly.
Enter the Vulnpocalypse.
A thing that may or may not be happening. (it’s probably not happening in the way that most people think it is.) But what is happening is a serious uptick in the number of vulnerabilities that vendors are disclosing (see Microsoft’s recent 1,000-bug Patch Tuesday), which of course means that enterprise security teams are expected to just handle this deluge without any extra resources, time, or money. Not only that, they’re meant to do it more quickly, because the bugs are coming more quickly, so they have to patch more quickly.
And that, friends, is not a tenable situation. It’s the kind of thing that makes people contemplate their life choices and daydream about buying a small farm upstate to raise chickens. (A word of advice: Don’t raise chickens.)
Moving faster is not the solution to this problem. It never has been and it never will be, regardless of how much automation and magic AI tripe we throw at it. The sage hacker Katie Moussouris often says you can’t bug bounty your way to being secure. You also can’t patch your way out of the Vulnpocalypse or whatever we want to call the current situation.
“Patching has never been harder. It's always been hard regardless. But attackers have always beaten patching. This isn’t new,” said Ben Harris, CEO and founder of watchTowr, during a talk at VulnCheck’s THREATCON1 here.
“It’s never been enough. As security professionals, we’ve tried so hard, we didn’t have breakfast, we didn’t sleep, and it got worse.”
How much worse? It’s impossible to quantify, but the constantly compounding volume of stories about the piles of bugs that AI models are finding sure isn’t helping. Nevermind that a substantial portion of those bugs may be unexploitable, low value, or duplicates. That only matters if you’re one of the unfortunate people who actually has to look at the bug pile and decide what’s valid or what’s worth patching at some point. Patching faster isn't just unrealistic; it's also impractical in a lot of environments where taking critical systems offline for updates requires long-term planning, not panicked button-pushing.
For outside observers (read: management) the AI-produced bug pile is a tangible, living thing that represents work not yet done by their security teams. It’s evidence that those teams need to move faster and up their games or else.
Or else what? Attackers will begin mass exploitation of those thousands of bugs in your backlog? No. Only a tiny fraction of CVEs disclosed in any given year are ever exploited, and an even smaller fraction of those are used in attacks that result in any kind of financial loss. Most vulnerabilities will never matter and will sit unused on a shelf like that bread maker you bought in 2020.
But that doesn’t mean researchers and their shiny LLMs are going to stop finding and disclosing them. That is only going to continue to accelerate, in fact, until the token-based economy eventually collapses into a radioactive pile of GPUs in Sunnyvale. Until then, security teams are left to play patch as patch can, fighting an uphill battle against an untiring foe.
October 7, 2026 | 3 min read
Dennis Fisher is an award-winning journalist and author. He is one of the co-founders of Decipher and Threatpost and has been writing about cybersecurity since 2000. Dennis enjoys finding the stories behind the headlines and digging into the motivations and thinking of both defenders and attackers. He is the author of 2.5 novels and once met Shaq. Contact: dennis at decipher.sc.