The average time between a software vulnerability going public and attackers exploiting it has collapsed to a single day, according to a new J.P. Morgan Asset & Wealth Management report. The firm projects that window will shrink to one minute by 2027, driven by AI systems that can reverse-engineer patches and generate working exploits faster than most enterprises can schedule a maintenance window.

"The average time between the disclosure of a vulnerability and its first exploitation has fallen to a single day (a zero-day event), leaving companies little more time to react than residents of tornado alley," the report states. That metaphor lands harder when paired with a second finding: in roughly 60% of breaches, a patch already existed at the time of compromise. Companies aren't failing to build defenses. They're failing to deploy them.
How AI accelerates both attack and defense
The report names specific AI models, including Mythos and GPT 5.5, as capable of detecting thousands of previously unknown software vulnerabilities at scale. Within the first month of testing advanced AI systems, researchers identified more than 10,000 new high- and critical-severity zero-days, many absent from public vulnerability databases. That discovery capacity is now available to defenders and attackers alike.
J.P. Morgan warns that ransomware operators, hacktivists, and state actors can use the same AI tooling to reverse-engineer patches within minutes. The asymmetry is brutal: a vendor publishes a fix, and an attacker's model immediately knows what was wrong. The patch itself becomes the exploit blueprint.
The report does note a flip side. Anthropic and OpenAI are developing security-focused AI tools that propose code fixes and automate remediation. "The same tools that are used to detect and exploit vulnerabilities can also be used to propose code fixes and remediate them," J.P. Morgan writes. The question is whether defenders adopt these tools faster than attackers weaponize them.
Recent example of AI-adjacent security failures and exposure risks
The patching bottleneck
Enterprise patching cycles typically run 60 to 150 days. Against a one-day exploitation window, that gap is not a risk. It is a certainty. The report frames the coming wave as a "tsunami of patches" and argues that companies must now measure themselves on remediation speed, not just accuracy.
Staffing compounds the problem. J.P. Morgan cites a global shortage of nearly 4.8 million cybersecurity professionals. Cyberattacks rose 18% globally in 2025, with approximately 75,000 attacks per hour. Phishing remains the leading vector, but faster exploit development means every category of attack now carries tighter timelines.
What this means for security teams
The report's implicit argument is that manual triage and scheduled patch windows are now obsolete models. When the median time to exploit hits one minute, as J.P. Morgan projects for 2027, only automated detection-to-remediation pipelines will keep pace. That shifts budget from headcount toward tooling, and shifts vendor evaluation toward response latency.
For CTOs and security leads, the practical takeaway is uncomfortable: patching on a monthly cycle is patching too late. The organizations that fare best will be those that can deploy fixes within hours, not weeks, and that means rethinking change management, testing, and deployment automation across the stack.
Logicity's Take
J.P. Morgan's framing is stark, but the math checks out. If AI can find 10,000 critical zero-days in a month, the bottleneck isn't discovery. It's deployment. Enterprises that can't shrink patch cycles to hours will increasingly rely on runtime protection, segmentation, and AI-driven anomaly detection as compensating controls. Expect security vendors like CrowdStrike, Palo Alto Networks, and emerging players like Proofpoint's AI-first offerings to compete on response latency as the primary metric.
Industry response to AI-driven security threats
The broader context
Last year, 26,447 CVEs were cataloged, a record. The attack surface is expanding while the time to respond contracts. J.P. Morgan's report arrives as financial institutions, which face stricter regulatory scrutiny than most sectors, grapple with how to price this risk. Cyber insurance premiums will likely reflect the new math: if exploitation is near-instant, coverage models built on patch availability become harder to underwrite.
The report stops short of predicting specific breach events, but the trajectory is clear. AI is compressing the exploit lifecycle faster than most organizations are compressing their response cycles. Something has to give.
Need Help Implementing This?
Logicity works with security teams evaluating AI-driven vulnerability management and automated patching solutions. Reach out if you need help benchmarking vendors or designing faster remediation workflows.
Source: mint
Huma Shazia
Senior AI & Tech Writer
Produced with AI assistance and reviewed by the Logicity editorial team. Learn more in our Editorial Policy.
Related Articles
More in Trending Tech
AI Revolution: How Tech is Transforming the World, One Industry at a Time
From desalination plants in Iran to AI-powered manufacturing, the tech world is abuzz with innovation. Discover how AI is changing the game for small entrepreneurs and what it means for the future of industry. Explore the latest developments in cybersecurity, robotics, and more.

Revolutionizing AI: The Game-Changing Tech That's Making Agents Smarter
A new technology is set to revolutionize the way AI agents learn and adapt, enabling them to accumulate wisdom and apply it to new situations. This innovation has the potential to significantly boost the reliability of AI agents, especially in complex tasks. By converting raw agent trajectories into reusable guidelines, this tech is poised to transform the AI landscape.

The Dark Side of AI: How Bots Are Fueling a Monetized Abuse Ecosystem
A recent analysis of 2.8 million Telegram messages reveals a shocking truth: AI-powered bots are being used to create and sell non-consensual intimate images. These bots can turn ordinary photos into synthetic nude images, and the abuse is being monetized through affiliate programs and subscription-based archives. The researchers behind the study are calling for stricter regulations to combat this growing problem.

AI's Secret Sauce: How Journalism Became the Unlikely Ingredient
A recent study reveals that AI chatbots rely heavily on journalistic sources for their quotes, with one in four coming from news outlets. This shocking discovery has significant implications for the media industry and our understanding of AI's information gathering processes. As AI technology continues to evolve, it's essential to consider the role of journalism in shaping its responses.


