AI
Sécurité

AI changed how attackers operate

Has your patch strategy kept up?

TL;DR: AI has collapsed the time between vulnerability disclosure and active exploitation from weeks to hours1. Third-party applications remain the most exploited and most under-managed attack surface2. N-central and N-sight answer both with a single, AI-accelerated workflow that scans, prioritizes, remediates, and verifies vulnerabilities across 900+ applications on Windows, macOS, and Linux, without tool switching.

A record 48,185 CVEs were published in 2025, roughly 131 every day3, and forecasts point to between 70,000 and 100,000 in 20264. Vulnerability exploitation now sits behind 20% of all breaches, up 34% year over year5.

That is not a patching backlog. It is a structural mismatch between how fast threats move and how fast most IT teams can respond. The teams that close the gap do more than patch faster. They consolidate workflows, cut manual triage, and use AI to operate at a speed that matches the threat.

How the threat landscape shifted

Attackers are not waiting for your next patch window. Work that used to require a skilled human researcher, from vulnerability discovery to exploit weaponization to attack chaining, is now automated in hours with AI-assisted tools and open-source offensive frameworks6. The disclosure-to-exploitation window has collapsed: nearly 29% of vulnerabilities added to CISA’s Known Exploited Vulnerabilities catalog in 2025 were exploited on or before the day their CVE was published1.

The math is unforgiving. The average team takes 30.6 days to deploy a patch. Attackers weaponize the same vulnerability in 19.5 days1. That is an 11-day exposure window, and attackers only need one of those days.

AI has also lowered the skill barrier. LLM-powered phishing, automated reconnaissance, and AI-assisted exploit generation let less-experienced adversaries operate with the capability of senior researchers. The pool of capable attackers is widening, not just quickening.

Third-party applications are the hardest part

Operating system patching gets the attention. Third-party applications get the exploits. Browsers, PDF readers, communication tools, developer utilities, and runtime libraries are the largest, fastest-changing, and most-exploited surface in any environment, yet most patch tools are built OS-first and treat third-party support as an afterthought7. Seventy percent of accumulated security debt traces back to third-party library flaws5.

Fragmentation compounds the problem. One tool for Windows, another for Mac, a third for Linux, a fourth for third-party apps, each with its own catalog, cadence, and blind spots. The apps a tool skips are the apps that get exploited. Manual tracking gives out at this volume, and lean teams default to patching what is loudest while the rest of the surface stays exposed.

What closing the gap takes

Three things have to work together, and most teams have none of them fully in place:

  • A single, continuous workflow. Scan, prioritize, remediate, and verify as one motion, not four handoffs that add days of exposure.
  • First-class third-party coverage. Any strategy that treats third-party apps as secondary is solving last decade’s problem. They are the primary attack surface.
  • AI-assisted prioritization. A CVSS score alone cannot tell you what to fix first. Real prioritization layers CVSS, CISA KEV exploitation status, EPSS probability, and live device data, the kind of judgment most lean teams cannot staff every patch cycle.

How N-central and N-sight close the gap

N-central™ and N-sight™ deliver AI-accelerated vulnerability and patch management as one continuous workflow, built into the unified endpoint management platform IT teams already run.

  • Continuous scanning, on-demand verification. Built-in scanning covers 900+ applications on Windows, macOS, and Linux, with on-demand scans to verify a fix or assess a fresh CVE the moment it breaks.
  • One workflow, full coverage. From the vulnerability view, technicians remediate 340+ third-party applications plus Mac and Linux operating systems without switching consoles. Patch policies standardize scheduling, approvals, retries, offline handling, and reboot control across sites and device types.
  • Guided intelligence from N-zo™. Two AI experts take the guesswork out of patch decisions. The Vulnerability Expert combines CVSS, CISA KEV, EPSS, and live device context to answer “what should I fix first?” in plain language, and counts how many devices a given CVE touches in seconds. The Patch Expert gives conversational, time-aware answers on what shipped, why a patch failed, and whether it is safe to redeploy. One prompt, full risk context, clear next step.

This is an early expression of ResilienceAI, the embedded intelligence layer woven across the N-able platform to help IT teams shrink the attack surface before a threat lands.

The outcomes that matter

The value is not the AI. It is what the AI lets teams accomplish.

  • Exposure windows compress from days to minutes. Detection, prioritization, remediation, and verification connect in one workflow, closing the exact gap attackers depend on.
  • The most exploited surface becomes the most defended. Third-party coverage moves from a fragmented afterthought to a first-class, continuously managed part of the environment, alongside Windows, macOS, and Linux, from a single console.
  • Every technician operates like a senior analyst. Independent research on N-zo has already validated dramatic time savings on related tasks: resource utilization analysis dropping from 240 minutes to about 1 minute, documentation lookups from 30 minutes to roughly 30 seconds, and overall technician task performance improving by up to 70%.

AI industrialized the attack. N-central and N-sight industrialize the response, giving IT teams and the service providers who support them a way to move at the speed the threat now demands, without adding headcount to do it.

Sources

  1. VulnCheck, 2026 (https://www.vulncheck.com/)
  2. FIRST, 2026 (https://www.first.org/)
  3. NVD, 2025 (https://nvd.nist.gov/)
  4. FIRST, 2026 (https://www.first.org/)
  5. Verizon DBIR, 2025 (https://www.verizon.com/business/resources/reports/dbir/)
  6. SentinelOne, 2026 (https://www.sentinelone.com/)
  7. Veracode, 2025 (https://www.veracode.com/)

© N‑able Solutions ULC and N‑able Technologies Ltd. All rights reserved.

This document is provided for informational purposes only and should not be relied upon as legal advice. N‑able makes no warranty, express or implied, or assumes any legal liability or responsibility for the accuracy, completeness, or usefulness of any information contained herein.

The N-ABLE, N-CENTRAL, and other N‑able trademarks and logos are the exclusive property of N‑able Solutions ULC and N‑able Technologies Ltd. and may be common law marks, are registered, or are pending registration with the U.S. Patent and Trademark Office and with other countries. All other trademarks mentioned herein are used for identification purposes only and are trademarks (and may be registered trademarks) of their respective companies.