The Expanding Threat Landscape and AI’s Dual Role
The cybersecurity landscape is currently grappling with an unprecedented volume of threats and vulnerabilities, exceeding organizations’ capacity for timely response. This surge is significantly influenced by the rapid advancement and deployment of artificial intelligence (AI) models, which serve as both an accelerator for threat detection and a powerful tool for adversaries. According to itnews.com.au, Dan Elliott, Field CISO for APJ at Recorded Future, highlights a “five-fold increase in CVE [Common Vulnerabilities and Exposures] volume” with the advent of new frontier AI models, citing events like the Mythos release and Glasswing test cases that prompted mass patching efforts by organizations like Mozilla and a corresponding 5x jump in discovered vulnerabilities reported by Palo Alto.
This explosion in potential threats arrives at a time when cybersecurity budgets are constrained, and a global shortage of cybersecurity experts persists. Compounding the issue, motivated threat actors now have access to AI models that can run on lower-cost hardware, enabling them to launch attacks at a scale and speed previously unimaginable. For security leaders, the imperative is clear: cut through the noise to strategically deploy resources for proactive detection rather than reactive measures post-breach.
Prioritizing Vulnerabilities Exploited in the Wild
The sheer volume of vulnerabilities makes traditional triage methods unsustainable. For example, the National Vulnerability Database (NVD) is projected to disclose approximately 50,000 CVEs in 2025. However, Recorded Future Intelligence observes that fewer than 1% of these are typically exploited in the wild. This disparity underscores a critical challenge: budget pressures and staffing realities force cyber teams to make difficult prioritization decisions. Elliott emphasizes that success now depends on using tools and data that can keep pace with new disclosures and enable teams to focus solely on prioritizing vulnerabilities exploited in the wild rather than relying solely on abstract CVE scores.
Beyond just identifying potential weaknesses, the focus must shift to acting on the most relevant threats before adversaries can exploit them. The exponential growth in threat volume, coupled with increasing complexity, has created a perfect storm that human teams alone cannot weather. The five-fold rise in vulnerabilities means manual triage is no longer feasible.
From Tactical Threat Intel to Strategic Business Risk Understanding
While AI contributes to the detection of more vulnerabilities, it also offers solutions for autonomous threat hunting, which is increasingly vital amid the cybersecurity talent shortage. Threat intelligence, often seen as tactical for detection, hunting, and vulnerability triage, possesses significant strategic potential once the signal-to-noise ratio is managed. Elliott advocates for leveraging threat intelligence for executive reporting, investment justification, and risk-based decision-making. Currently, many threat intelligence feeds operate in silos, disconnected from enterprise risk registers, procurement, or operational planning.
To achieve a more strategic operating model, organizations must integrate threat intelligence into existing security workflows, including detection, response, exposure management, and executive risk reporting. This involves moving beyond collecting data to prioritizing what truly matters for the business, using tools like generative AI and natural language processing while preserving human judgment. AI doesn’t replace people; it enhances their capacity to filter data, focus on critical threats, and provide actionable insights to C-suite executives and boards.
Enhancing Vulnerability Management with AI-Driven Workflows
Moving to this model requires an understanding of available tools and techniques. A large enterprise in the financial services sector demonstrated the benefits of an AI-enhanced vulnerability management workflow by partnering with Recorded Future. After a major patching effort, the organization automated processes between its vulnerability scanning and IT service management tools, extending visibility across its entire attack surface. This resulted in a streamlined, repeatable process and an estimated weekly time savings of over 20 hours for the team.
As threats are now detected and created at machine speed, and threat actors leverage AI to move faster than ever, the emphasis must be on prioritization. Organizations need reliable partners and tools that can pinpoint exactly what steps to take next to protect business assets.
Related: Ransomware as a Defensive Metric: Leveraging AI for Attack Path Remediation, Chinese LLMs Reshape Cyber Defense: Attacker Advantage