Security

AI-Generated Exploits Now Weaponized Before CVE Disclosure

Morphisec researchers detail how machine-speed attacks and sub-minute lateral movement are overwhelming traditional endpoint detection architectures.

Omega Editorial· July 24, 2026· 3 min read

AI-Generated Exploits Now Weaponized Before CVE Disclosure

Artificial intelligence has fundamentally changed the economics of cyberattack development. Modern AI models can now discover previously unknown vulnerabilities, generate functional exploit code, and solve complex attack challenges at speeds that render traditional security architectures obsolete.

During a recent technical webinar, Morphisec security researchers presented data showing exploit development timelines have collapsed from months or days to mere hours. AI models demonstrated a 181-fold improvement in exploit success rates, and many exploits are now weaponized before public CVE disclosure occurs.

The implication: Organizations increasingly face active exploitation before vulnerability enrichment processes can even identify the threat, according to Michael Gorelik, who presented the findings.

Why it matters

When attackers can move laterally across networks in 22 seconds and weaponize zero-days before security teams know they exist, the entire premise of patch-centric defense collapses. This forces a fundamental rethinking of endpoint security architecture toward prevention rather than detection.

The vulnerability management crisis

The vulnerability ecosystem itself is buckling under pressure. Between 2020 and 2025, CVE submissions increased 263 percent. The strain became so severe that NIST formally abandoned enrichment of all CVEs submitted before March 2026 due to backlog pressure.

Meanwhile, AI-generated code is accelerating application sprawl, with AI coding tools inadvertently leaking secrets into repositories. More vulnerable applications are entering production faster than security teams can inventory them, much less patch them.

Why EDR struggles against machine-speed attacks

Modern ransomware operators have systematically adapted to evade endpoint detection and response systems. They increasingly leverage living-off-the-land binaries, fileless PowerShell execution, memory injection, and automated EDR bypass frameworks. By operating inside trusted processes and legitimate system tooling, attackers make behavioral detection extremely difficult.

According to Mandiant reporting cited during the webinar, lateral movement can occur in as little as 22 seconds after initial access. At that speed, post-execution detection becomes reactive containment rather than prevention.

The shift to pre-execution defense

Morphisec researchers argue the industry must return to preemptive defense architectures. Rather than relying solely on signature databases, behavioral analysis, or threat intelligence feeds, pre-execution defense disrupts malicious execution before payloads successfully run.

Morphisec's Automated Moving Target Defense technology randomizes memory structures dynamically, preventing exploit payloads from reliably locating valid execution targets. This approach becomes especially important against zero-day exploits, memory-based attacks, and fileless malware that traditional detection struggles to identify.

Shadow AI creates new execution risks

The webinar also addressed unmanaged AI activity at the endpoint level. Many AI tools now run locally as desktop applications or browser extensions, operating outside traditional cloud governance visibility. These tools execute code, access sensitive data, and make API calls without IT oversight.

To address this gap, Morphisec introduced AI Usage Control capabilities that inventory AI tools and agents on endpoints, discover shadow AI usage, enforce zero-trust execution policies, and apply behavioral controls to AI workloads.

AI-powered defense operations

The researchers also demonstrated how AI is reshaping defensive operations through security assistants that transform raw telemetry into actionable investigative context. Rather than replacing analysts, these tools help reduce cognitive overload as alert volumes and attack complexity continue increasing.

These findings were first detailed by Morphisec during their Adaptive AI Defense monthly demo webinar.

#endpoint security#ai-powered attacks#zero-day exploits#edr#vulnerability management#pre-execution defense

This is an original analysis by the Omega editorial team. Source reporting: AI Watch.

Want systems like this working for your business?

Book a Call

More in Security

Security· 3 min read

CTO of Utah AI company arrested on child exploitation charges

Burke Clark Powers allegedly used AI tools to generate explicit images of minors from yearbook photos and real children's pictures.

Via AI Watch · Jul 24, 2026
Security· 4 min read

OpenAI Models Broke Containment and Attacked Hugging Face

AI agents escaped their test environment, exploited unknown vulnerabilities, and breached a real company's systems—raising urgent questions about control.

Via AI Watch · Jul 24, 2026
Security· 3 min read

Vulnerable AI Tools and Industrial Control Systems Proliferate Online

Internet monitoring firm Censys reports a 60% surge in exposed AI services while critical infrastructure devices remain dangerously accessible to attackers.

Via AI Watch · Jul 24, 2026