AI Tools Accelerated Software Vulnerability Exploits
The mean time-to-exploit for software vulnerabilities dropped to minus seven days by 2025 as AI-driven attacks rose.
Updated on Sept. 23, 2026 in Cybersecurity

Live Poll
Do you trust that the software you use daily is secure against AI-driven cyberattacks?
Artificial intelligence tools significantly increased the speed of vulnerability discovery and exploitation within software supply chains, resulting in an estimated mean time-to-exploit of minus seven days in 2025. This shift occurred as attackers began using frontier models to identify and exploit vulnerabilities before patches were available.
Why it matters
AI agents are now making autonomous decisions regarding software dependencies, allowing attackers to chain low-severity findings into viable attack paths. To combat this, the Athena coalition was launched to automate the generation and distribution of engineering fixes for vulnerabilities.
As of July 2026, the Athena coalition has processed 40,000 vulnerabilities, with 86% marked as network reachable and 42% classified as critical or high severity.
The players
Athena coalition
This collaborative initiative automates the generation and distribution of security fixes to combat rising software vulnerabilities.
GitHub
This platform serves as a critical hub for global software development, processing over one billion commits annually.
OpenAI
This research organization develops large-scale artificial intelligence models that are increasingly integrated into security and development workflows.
The details
Frontier models now chain together multiple low- and medium-severity findings to create sophisticated attack paths that target software dependencies. This automated approach allows malicious actors to strike faster than traditional security patches can be developed and deployed.
Timeline
The mean time-to-exploit was 63 days between 2018 and 2019.
GitHub processed one billion commits in 2025.
Weekly GitHub commits reached 275 million in April 2026.
The Athena coalition processed 40,000 vulnerabilities by July 2026.
OpenAI released GPT-5.6-Cyber in August 2026.
The Tech Race
This vulnerability crisis represents a paradigm shift where AI-augmented exploitation cycles now outpace traditional defensive patching timelines. The competitive arms race between AI-driven attack vectors and automated remediation coalitions like Athena is replacing slower, manual security audit processes.
Developers and organizations must now adopt automated fix distribution workflows to keep pace with the faster exploitation cycles. Users may see more frequent software updates and stricter security requirements as organizations work to defend against AI-chained attack paths.
The takeaway
Security professionals must shift toward autonomous, AI-driven defense mechanisms to neutralize threats before they become viable exploits. Automation is no longer a luxury but a fundamental necessity for protecting software supply chains against modern, high-speed attack vectors.
Further reading
Explore more developments in Cybersecurity to understand how industry experts are responding to the rise of AI-powered exploits.
Live Poll
Do you trust that the software you use daily is secure against AI-driven cyberattacks?







