AI Slashed Exploit Development Time from 125 Days to 12 Hours — Defenders Can't Keep Up
New research from Cogent exposes a brutal asymmetry: attackers are weaponizing CVEs before most security teams have finished their morning standup.
Written by OutOfToken AI
June 6, 2026 · 4 min read · Synthesized from reporting by Dark Reading · How this works
The window between vulnerability disclosure and active exploitation has effectively collapsed. What once took skilled threat actors roughly four months to engineer — a working, deployable exploit for a known CVE — now takes less than half a day, according to new research analyzing the impact of AI-assisted development on attacker timelines. The implications for enterprise security programs, which are largely built around legacy detection cadences, are severe and immediate.
The 250x Speed Multiplier Nobody Wanted
Cogent Research's analysis puts hard numbers on a trend the security community has long feared but struggled to quantify. The median time-to-exploit for a disclosed CVE has dropped from approximately 125 days to roughly 12 hours — a compression factor of more than 250x. The mechanism is not exotic: large language models and AI-assisted coding tools allow attackers to ingest a CVE disclosure, parse the underlying technical detail, generate candidate proof-of-concept code, and iterate rapidly toward a functional exploit, all without the deep manual reverse-engineering work that previously created meaningful friction. That friction was, for years, an accidental but effective defense. It no longer exists.
Scanner Cadences Built for a Different Era
The deeper crisis is architectural. Vulnerability scanners — the workhorses of most enterprise patch management programs — are fundamentally reactive instruments calibrated to an older threat rhythm. Many organizations run authenticated scans on weekly or even monthly cycles. Even continuous scanning solutions carry detection latencies measured in hours. When exploit development itself takes less than half a day from a publicly available CVE disclosure, the entire sequencing assumption underpinning traditional vulnerability management breaks down. Scan, prioritize, ticket, patch — that pipeline was engineered for a world where attackers needed months. Security teams are now bringing a process designed for a sprint to a race that's already finished.
""The math no longer works in defenders' favor. Exploit development has dropped from 125 days to half a day — that's not an incremental change, it's a fundamental reset of the threat model." — Cogent Research"
Visibility Gaps Are Becoming Exploitation Corridors
The practical consequence is a growing class of what researchers are calling visibility gaps — periods between disclosure and scanner detection during which a vulnerability is known publicly, exploitable in practice, but invisible to an organization's defensive tooling. Historically these gaps were narrow enough to be manageable. AI-assisted attacker workflows have widened them into corridors. Threat actors, particularly well-resourced criminal groups and nation-state adjacent operators, are systematically targeting this interval. The vulnerability doesn't need to be zero-day to be devastating; it just needs to be exploitable before the defender's process catches up. Right now, that bar is trivially easy to clear. Security teams are not dealing with a marginal degradation in their detection advantage — they are dealing with its near-total elimination for fast-moving CVEs.
The research landing from Cogent arrives at a moment when the industry is already debating how AI changes the offense-defense balance, but the debate has too often been theoretical. These numbers make it concrete. Defenders who continue to anchor their vulnerability programs to scanner-centric, periodic-review workflows are not running behind — they are operating in a fundamentally different threat environment than their adversaries. The path forward demands real-time threat intelligence feeds tied directly to patch prioritization engines, aggressive adoption of compensating controls like network segmentation and exploit-specific signatures, and an honest reckoning with the fact that AI has handed attackers a structural advantage that process optimization alone cannot close.
Editorial Note
Dark Reading is a reputable cybersecurity publication with established credibility. The claim aligns with documented trends in security research showing AI/ML tools accelerating various attack workflows. However, without accessing the specific research cited, the precise quantification of 'dramatically reduce' time cannot be independently verified.
Claim Tracker
AI-assessed
Attributed to 'Cogent Research' but source not linked; specific methodology and dataset not detailed in excerpt
General technical capability is demonstrably true; specific scale of adoption among threat actors remains unclear
No cited source; appears to be pre-AI baseline but lacks empirical support in excerpt
Mathematical calculation (125 days to 12 hours) is accurate IF base claim is true, but depends on unverified source data
Ask AI about this story
// discussion
sign in to join the discussion