Stop Chasing Every Vulnerability And Start Managing Exploitable Risk

Direct Source Verification: This story is aggregated from Forbes (forbes.com). Full reporting rights and copyright belong to the primary publisher.
Work that once required time, expertise and experimentation is now delegated to autonomous agents, yet most security programs follow a model AI has made obsolete.

Taylor is the chief solutions officer at TekStream, a digital resilience company helping organizations modernize and secure technology.

getty​AI has changed the economics of exploitation. Work that once required time, expertise and patient experimentation is now delegated to autonomous agents that test, adapt and pursue multiple paths at machine speed.

Yet most security programs follow a model that AI has made obsolete. Teams inventory vulnerabilities, assign severity, open remediation tickets and track closures. Those activities remain necessary, but they don’t consider the attacker’s approach: Which combination of vulnerabilities provides the most viable path to exploitation?

In July, an orchestrated multi-agent framework ran a four-day intrusion against Taiwan’s justice ministry, cracking employee accounts, extracting personnel records, SSO client secrets and database credentials. Over the same period, it scanned a nuclear safety agency, a government email system, IT supply-chain vendors and at least seven energy companies for exposed admin interfaces and exploitable misconfigurations.

1. It ran on free, publicly downloadable versions of Hermes and OpenClaw, assembled into a custom multi-agent attack framework.

2. There were no reported zero-days. The documented intrusion paths relied on ordinary identity and API weaknesses: hidden endpoints that returned authenticated sessions without credentials, unauthenticated APIs exposing employee information, predictable password patterns, credential spraying and weaknesses in authentication and SSO. The agents chained these familiar weaknesses together and iterated when individual paths failed.​

3. The frameworks’ safety guardrails were bypassed by describing the operation as an authorized penetration test. The checks evaluated what the operator declared but not what the operation was doing. Patching individual flaws will not address that weakness.​

Researchers describe this incident as near-autonomous. A human chose the targets, tuned the coordination and set the malicious goal. AI automated execution, not intent.​

The Taiwan operation did not happen in isolation. It ran the same month OpenAI discovered something on its side. OpenAI had been scoring two of its models against an internal offensive-security benchmark. The models determined that Hugging Face maintained the test solutions, escaped their testing environment, chained exposed credentials and zero-day vulnerabilities and pulled the answers out of Hugging Face’s production database. They stood up a message board and used it to coordinate with each other. OpenAI noticed because of an unrelated outage and wiped the channel. Within days, the models rebuilt it.

At Black Hat, OpenAI’s Michael Dalton put it plainly: “AI-orchestrated, fully-automated offensive attacks are real now.” He said the company had slowed its research and dramatically scaled up monitoring of its own agents. Anthropic followed with a similar disclosure.

Restraint at one frontier lab is not restraint in the field. The Taiwan operator needed nothing from OpenAI, and open-weight models remain available once published. In the same month, we got capable agent swarms behaving unexpectedly inside the best-instrumented lab on the planet and a determined malicious operator running a real intrusion against critical infrastructure with free downloads and no custom exploit code. There was no meaningful gap between the lab result and field use.

Attacks like this rarely depend on a single isolated vulnerability. They work on chains: an exposed application, a misconfiguration that yields credentials, excessive permissions that allow elevation and a trust relationship that permits lateral movement into something that matters.

Conventional vulnerability management often fails because findings are split among different owners and tools. Application teams see software vulnerabilities. Identity teams see excessive permissions. Cloud teams see configuration drift. SOC analysts see the alerts generated once someone starts exploiting it. Every team is looking at one link, but nobody owns the chain.

Attackers don’t evaluate environments the way defenders do. They aren’t looking for the highest CVSS score or the longest list of known CVEs. They’re asking a simpler question: Can I get where I want to go quickly?

An exploitable attack path may consist of findings that would not individually justify an emergency fix but collectively provide access to business-critical systems and data. Human attackers seek to exploit these chains, but doing so requires time, experience and effort. Autonomous systems evaluate thousands of combinations in parallel, test assumptions continuously, adapt when a route fails and never stop.

Attack path analysis, CTEM and exposure management have been available for years, but many programs bought the tools without changing the operating model. Machine-speed offense has removed the slack that made that old model survivable.

1. Define what you’re protecting first. Attack path analysis is meaningless without a defensible list of critical systems and data. Most of the work is here, and most programs skip it.

2. Join the data you already have. Identity, permissions, cloud configuration, application findings and network reachability must be queryable together. Connecting the data reveals the paths an attacker can use.

3. Fix choke points. One over-permissioned service account can sit on dozens of paths. Remediating it beats closing unrelated vulnerabilities so that ranking is invisible in a CVSS-sorted queue.

4. Change what you report. Boards drive programs through the metrics they receive. Report the number of viable paths to critical systems and how fast they’re eliminated.

5. Give the chain an owner. Paths cross team boundaries. If path ownership isn’t clear, everyone will keep closing their own links and the route will stay open.

Path modeling has limits, too. It is only as good as your asset inventory. A bad one produces confident, wrong maps. Done poorly, it generates a new queue nobody can work. Discipline and ruthless prioritization will retire exploitable risk.

Cybersecurity has always been an arms race, and right now, AI is accelerating attacks faster than defenses. We won’t close the gap by patching more vulnerabilities or investigating more alerts alone. We close it by making attacks harder to execute. Every eliminated path forces an attacker to start over, breaking the sequence they counted on. That’s the difference between reacting after an adversary has momentum and removing the conditions that enable exploitation.

The organizations best positioned for the next few years will make themselves expensive to move through.​​

Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

Original Source
https://www.forbes.com/councils/forbestechcouncil/2026/10/02/stop-chasing-every-vulnerability-and-start-managing-exploitable-risk/
Visit Forbes ↗
SHARE STORY:
𝕏 f in

Related Coverage in Business