Exploits Now Beat Disclosure: the AI Cybersecurity Investment Case

Mandiant's M-Trends 2026 reveals the mean time to exploit a vulnerability has fallen to roughly negative seven days, meaning AI cybersecurity vendors that can detect flaws before CVE disclosure now hold the only defensible position in a patching race that legacy tooling has already lost.
By John Zadeh -
Industrial alarm panel flashing "-7 DAYS" in crimson — AI cybersecurity exploit window inversion visualised
  • Mandiant's M-Trends 2026 puts the mean time to exploit at approximately negative seven days, meaning the CVE disclosure system now functions as a post-incident record rather than a forward warning for enterprise defenders.
  • VulnCheck found 28.96% of CISA's Known Exploited Vulnerabilities were attacked on or before CVE publication in 2025, up from 23.6% the year before, confirming the pre-disclosure attack window is widening, not narrowing.
  • Anthropic's Project Glasswing, backed by up to $100M in commitments and anchored by partners including AWS, Google, Microsoft, CrowdStrike, and JPMorgan Chase, identified more than 10,000 high- or critical-severity vulnerabilities before public disclosure, proving AI pre-disclosure detection is operational at scale.
  • Prompt injection success rates of 25-50% across tested AI models, per Meta's CYBERSECEVAL 2, mean that AI cybersecurity tools carry their own exploitable attack surface, making a vendor's investment in securing its own AI layer a material differentiator.
  • Gartner projects the AI cybersecurity market growing at a 73.9% CAGR from $26 billion toward $172 billion, but the exploit-window inversion acts as a filter: vendors combining deterministic scanning with frontier AI reasoning are structurally better positioned than those applying AI branding to legacy tooling.
Summarise with AI:

Consider the ordinary logic of a security warning. A smoke alarm sounds so you can act before the fire spreads. The Common Vulnerabilities and Exposures (CVE) system, the public catalogue that tells the world a software flaw exists, is supposed to work the same way. According to Mandiant’s M-Trends 2026, the mean time to exploit a vulnerability has fallen to roughly negative seven days.

Read that again. The attack is now landing, on average, a week before the warning arrives. That is not a slow smoke alarm; it is an alarm that goes off after the building has already burned. Enterprise security budgets, cyber insurance models, and compliance frameworks were all built around a patch-on-disclosure timeline that, statistically, no longer exists.

This piece lays out what that timing inversion means for how you read cybersecurity vendor claims, weigh the risk hidden in enterprise software, and evaluate the investment thesis now forming around AI-native security tooling.

The exploit window is now measured in negative days

Start with the trend line. VulnCheck’s State of Exploitation 2026 report found that 28.96% of the vulnerabilities in CISA’s Known Exploited Vulnerabilities (KEV) catalogue, the US government’s authoritative list of flaws confirmed to be under active attack, were exploited on or before the day their CVE was published in 2025. That is up from 23.6% the year before. The first half of 2026 sits at 23.43%, and the median time from CVE publication to KEV listing has fallen to 80 days.

One report is a data point. Several independent reports pointing the same direction is a pattern.

CrowdStrike observed that 42% of exploited vulnerabilities were attacked before public disclosure. Mandiant put a single number on the whole phenomenon.

Mandiant’s M-Trends 2026 reports the mean time to exploit has dropped to approximately negative seven days: exploitation now precedes disclosure by roughly a week on average.

Then there is the network telemetry, which removes any doubt that this is measurement noise. GreyNoise, which watches real-world attack traffic, documented a median 11-day gap between exploitation surges and the disclosure that was supposed to precede them. For specific vendors the lead was far longer: 39 days of pre-disclosure attack activity against Cisco, 36 days against VMware, and 24 days against MikroTik.

The Pre-Disclosure Attack Window

Source Key Metric Time Period Trend
VulnCheck 28.96% of KEVs exploited on or before CVE publication 2025 Rising from 23.6% in 2024
Mandiant M-Trends Mean time to exploit approximately -7 days 2026 Exploitation now precedes disclosure
CrowdStrike 42% of exploited flaws attacked before disclosure Recent Pre-disclosure attack the norm
GreyNoise Median 11-day exploitation-to-disclosure gap Recent Cisco 39 days, VMware 36 days pre-disclosure

Verizon’s 2026 Data Breach Investigations Report ties it back to outcomes: vulnerability exploitation is now the top initial access vector, present in 31% of studied breaches.

Put the four intelligence sources together and the conclusion is not that patching is slow. It is that the CVE disclosure system is no longer a warning at all. It is a post-incident record. Any security posture built on patch-on-disclosure is, by construction, a posture built around being late. For anyone assessing enterprise software risk or a compliance-driven security vendor, that reframes the entire incumbent tooling category as defending a timeline that has already moved.

CISA’s BOD 26-04 implementation guidance formalises the KEV catalogue’s role as a risk-based prioritisation tool, requiring federal agencies to complete forensic triage steps within defined windows whenever a vulnerability is added to the list, a mandate that implicitly acknowledges how little time defenders have once exploitation begins.

Case studies that put a face on the timeline failure

Statistics establish the shape of the problem. Named incidents show what it costs when a real organisation is on the receiving end.

Consider three cases in sequence:

  1. Ivanti Connect Secure (CVE-2023-46805 and CVE-2024-21887). Mandiant and Google Threat Intelligence documented zero-day exploitation by suspected China-nexus actor UNC5221 beginning 3 December 2023. Public disclosure did not arrive until 10 January 2024. Mass exploitation followed the very next day, on 11 January 2024. The disclosure did not warn defenders ahead of the attackers; it fired a starting gun for the wider criminal field.

Timeline Failure: Ivanti Connect Secure

  1. Ivanti Connect Secure again (CVE-2025-0282). Exploitation of Connect Secure, Policy Secure, and Neurons for ZTA gateways began in mid-December 2024, weeks before Ivanti released patches and disclosed the flaw in January 2025. Same vendor, same sequence. That tells you the first case was not a one-off but a repeating institutional failure.
  2. Fortinet FortiClient VPN. In late 2024, Volexity disclosed that Chinese state-sponsored actor BrazenBamboo was exploiting a credential disclosure zero-day. It had been reported to Fortinet in July 2024. As of November 2024, it remained unpatched, with no CVE assigned at all.

The China-nexus attribution running through all three cases is worth pausing on. This is not opportunistic crime exploiting a gap by luck; it is well-resourced state actors systematically operating inside a window the disclosure system leaves open. That elevates the issue from vendor risk to geopolitical and systemic infrastructure risk.

When disclosure never comes

The Fortinet case is the most instructive, because it breaks a hidden assumption. The CVE system is voluntary at the vendor level. No law compels a software maker to assign an identifier or publish a patch on any timeline.

So the Fortinet scenario, a live zero-day exploited by a state actor for months with no CVE and no fix, is not an anomaly. It is a structural possibility for any piece of proprietary software you rely on.

That matters for how you read a vendor’s security posture. Some fraction of the flaws in any enterprise software stack have no assigned CVE and no vendor patch timeline whatsoever. Against that fraction, patching is not merely late; it is impossible. The only available defence is finding the vulnerability yourself, before anyone assigns it a number. That is precisely where the next part of the story begins.

How frontier AI is being redirected toward pre-disclosure defence

If the problem is that vulnerabilities are exploited before humans catalogue them, the response has to operate before the catalogue too. That is the explicit design goal of the industry’s most notable recent move.

Anthropic launched Project Glasswing on 7 April 2026, describing it as a collaborative effort to secure the world’s most critical software for the AI era. Powered by its frontier model Claude Mythos Preview, the programme redirects large language model capability toward defensive discovery, finding and fixing flaws before disclosure rather than exploiting them.

The commitment behind it signals institutional seriousness rather than a marketing gesture. Anthropic pledged up to $100M in usage credits and $4M in direct donations to open-source security organisations. The founding cohort of twelve partners spanned the core of the modern technology stack:

  • Cloud infrastructure: Amazon Web Services, Google, Microsoft
  • Security vendors: Broadcom, Cisco, CrowdStrike, Palo Alto Networks
  • Hardware and platform: Apple, NVIDIA
  • Institutional anchors: Anthropic, JPMorgan Chase, Linux Foundation

By 2 June 2026, the programme had expanded from roughly 50 initial partners to about 200. The output justified the scale.

Anthropic’s institutional positioning in security carries a complication that the Project Glasswing announcement does not address: the company was removed from the US defence AI market in January 2026 after refusing to allow its models to support autonomous weapons or mass surveillance, a policy choice that shapes which enterprise and government buyers can access its frontier capability.

Project Glasswing partners used the model to identify more than 10,000 high- or critical-severity vulnerabilities across systemically important software.

That figure settles the earlier question. Frontier AI is already functioning as a pre-disclosure detection layer at scale. The open question for you as an investor is no longer whether AI can do this. It is which vendors are integrating it deeply enough to matter.

Checkmarx, an application security firm with roughly two decades of enterprise AppSec experience, joined the programme on 3-4 September 2026 and secured early access to Claude Mythos 5. It represents the practitioner layer, the people who actually run scans against enterprise code.

What hybrid scanning architecture actually means

Traditional static application security testing (SAST), which analyses source code for flaws before it runs, works by matching against known patterns and signatures. It is deterministic and auditable, but it can only catch what it already has a rule for. A vulnerability with no known signature is invisible to it.

Frontier AI reasoning works differently. It can read code logic and surface a novel flaw that no rule anticipated, with no CVE or signature attached. Checkmarx integrates both into a hybrid architecture called Checkmarx Fusion, built on a Multi-Model AI Engine, and reports an overall F1 score of 0.74.

That number is a precision-recall balance metric: it measures whether a tool catches real flaws without drowning users in false alarms. A scanner that flags everything is operationally useless at enterprise scale, because analysts cannot triage the noise. The durable competitive advantage, then, is forming in systems that fuse deterministic scanning with AI reasoning, not in either approach alone.

Where dual-use risk and governance gaps threaten the thesis

The optimism has a mirror image. The same frontier capability that finds vulnerabilities before disclosure also lowers the cost of attacking them, and the tools themselves carry fresh weaknesses. Three unresolved tensions complicate the thesis without cancelling it:

  • Offensive cost reduction (economic): An IEEE/Computer Society analysis concludes that instruction-following LLMs can produce targeted malicious content far more cheaply than human effort, sharpening the economic incentive for attackers.
  • Prompt injection vulnerability (technical): Meta’s CYBERSECEVAL 2 benchmarking found prompt injection success rates of 25-50% across tested models, and Checkmarx practitioners warn that AI code reviewers can themselves be tricked into executing unsafe code.
  • Governance framework lag (structural): The NIST AI Risk Management Framework (NIST AI 600-1) warns that generative AI expands the attack surface via prompt injection and data poisoning, while analyses from MITRE, Censinet, and Truefoundry find existing frameworks lack technical controls for securing training pipelines or agent architectures.

Governance framework lag is not unique to the enterprise software stack: APRA’s April 2026 letter to Australian regulated entities identified the same pattern at the institutional level, flagging that board-level AI literacy and vendor exit planning have not kept pace with the AI-assisted threat environment that security teams are actually operating inside.

The prompt injection figure is the one to sit with. Prompt injection means feeding an AI system crafted input that overrides its instructions. A 25-50% success rate tells you that the AI being deployed as defensive infrastructure carries its own exploitable attack surface. So the investor question is not only whether a vendor uses AI, but whether it has secured the AI layer itself.

That points to a spending imbalance worth watching, though the specific figures below are unverified directional estimates rather than precise citations.

Category Estimated 2025 Spend Status
AI-amplified security tooling ~$49 billion Unverified estimate
Securing AI systems themselves ~$2.8 billion Unverified estimate

Even as an illustration, the gap is the point. Money is pouring into AI-powered security tools far faster than into hardening those tools against attack. The vendors that have invested in securing their own AI infrastructure are structurally better placed than those that have wrapped legacy tooling in AI branding.

What the exploit-window inversion means for your investment framework

The category is large and growing fast. Gartner projects worldwide end-user information security spending of $213 billion in 2025, with the application security testing market alone at $5.1 billion. The broader AI cybersecurity market is growing at a 73.9% CAGR, from $26 billion toward $172 billion, and Gartner expects over 75% of enterprises to use AI-amplified cybersecurity products for most use cases by 2028.

Cybersecurity sector spending forecasts from Gartner, IDC, and Forrester collectively project the market reaching US$377 billion by 2028, with software accounting for roughly 69% of that figure by 2029, a composition that favours platform consolidators over point-solution vendors whose relevance depends on a single detection category staying dominant.

Here is the trap in those numbers. A 73.9% growth rate is not a reason to buy the category broadly. Growth lifts the sector’s revenue, but it does not distribute evenly, and it is precisely when a category is expanding this fast that AI branding gets bolted onto tooling that cannot deliver on it.

The exploit-window inversion hands you a sharper filter. The vendors best positioned combine deterministic scanning with frontier AI reasoning rather than one alone, can demonstrate genuine pre-disclosure detection, and have secured their own AI layer instead of treating it as a bolt-on feature.

Compliance-driven vendor signals such as ISM certification, renewal patterns, and sovereign client rosters carry a different type of information than AI feature announcements: they represent ongoing performance verification under active institutional scrutiny rather than claimed capability, which is precisely the distinction the exploit-window inversion makes consequential.

J.P. Morgan gave the underlying condition a name.

J.P. Morgan’s Eye on the Market report of 22 July 2026, titled “Patchmageddon,” frames the environment as a “patching emergency” driven by AI-accelerated vulnerability discovery, under-resourced open-source maintainers, and long-lived operational technology.

Three structural signals are worth watching as you position:

  • Compression of exploit windows: the faster the gap between exploitation and disclosure widens into negative territory, the more it accelerates demand for pre-disclosure tooling.
  • Regulatory response: any move to compel faster disclosure or mandate pre-disclosure detection becomes a compliance driver for enterprise adoption.
  • AI platform security spending: the gap between money spent on AI-amplified security and money spent securing AI platforms is the emerging competitive differentiator.

The right question is no longer “does this vendor use AI?” It is “can this vendor find flaws before the CVE exists, and has it secured its own AI infrastructure?”

The patching window is already gone. The question is what replaces it.

The evidence from VulnCheck, Mandiant, and CrowdStrike converges on one uncomfortable finding: the CVE-patch cycle no longer works as a primary defence. When the mean time to exploit sits at roughly negative seven days, the industry has already shifted from a patching race to a pre-disclosure detection race, and AI is the only tooling that runs at that speed. Project Glasswing’s more than 10,000 critical vulnerabilities found before disclosure show that layer is real and operating now.

The tensions are real too. The same capability that enables pre-disclosure defence lowers the cost of attack, and governance frameworks have not caught up to how frontier models actually behave inside security workflows. Several figures in the wider debate, including J.P. Morgan’s 80% pre-disclosure estimate and various CSA projections, remain contested. The investor case rests on the verified direction of travel, not any single precise number.

Treat the exploit-window inversion as a filter, not a buy signal. It is a structural market condition, and the vendors closing that gap with genuine hybrid capability, rather than AI branding, are the ones worth watching as CVE volume climbs.

This article is for informational purposes only and should not be considered financial advice. Investors should conduct their own research and consult with financial professionals before making investment decisions. Past performance does not guarantee future results. Financial projections are subject to market conditions and various risk factors, and forward-looking statements are speculative and subject to change based on market developments.

Frequently Asked Questions

What is the CVE system and why is it no longer enough to protect enterprise software?

The Common Vulnerabilities and Exposures (CVE) system is a public catalogue of known software flaws intended to prompt patching. It is no longer sufficient because, according to Mandiant's M-Trends 2026, the mean time to exploit has fallen to approximately negative seven days, meaning attackers are breaching systems before the CVE warning is even published.

What is Project Glasswing and how does it address pre-disclosure vulnerability detection?

Project Glasswing is Anthropic's AI-powered security initiative, launched in April 2026, that redirects frontier model capability toward finding and fixing software flaws before they are publicly disclosed. By June 2026, its roughly 200 partners had used the programme to identify more than 10,000 high- or critical-severity vulnerabilities before any CVE was assigned.

What percentage of exploited vulnerabilities are attacked before public disclosure?

Multiple independent sources converge on a majority finding: VulnCheck found 28.96% of CISA's Known Exploited Vulnerabilities were exploited on or before CVE publication in 2025, while CrowdStrike reported 42% of exploited flaws were attacked before disclosure, and GreyNoise documented a median 11-day exploitation-to-disclosure gap in real-world attack traffic.

What is prompt injection and why does it matter for AI cybersecurity tools?

Prompt injection is an attack technique where crafted input overrides an AI system's instructions, effectively hijacking its behaviour. Meta's CYBERSECEVAL 2 benchmarking found prompt injection success rates of 25-50% across tested models, which means AI tools deployed as defensive security infrastructure carry their own exploitable attack surface that vendors must address separately.

How should investors evaluate AI cybersecurity vendors given the exploit-window inversion?

The exploit-window inversion means the right filter is not whether a vendor uses AI, but whether it can demonstrate genuine pre-disclosure detection, fuses deterministic scanning with frontier AI reasoning, and has secured its own AI layer against attacks like prompt injection rather than simply bolting AI branding onto legacy tooling.

John Zadeh
By John Zadeh
Founder & CEO
John Zadeh is an investor and media entrepreneur with over a decade in financial markets. As Founder and CEO of StockWire X and Discovery Alert, Australia's largest mining news site, he's built an independent financial publishing group serving investors across the globe.
Learn More

Breaking ASX Alerts Direct to Your Inbox

Join +20,000 subscribers receiving alerts.

Join thousands of investors who rely on StockWire X for timely, accurate market intelligence.

About the Publisher

Sponsored