AI cybersecurity and the new reality of software risk: Beyond the patch

Advertisement

The cybersecurity landscape is undergoing one of the most significant transformations since the advent of the internet. For decades, organizations have operated under a relatively stable assumption: software vulnerabilities would be discovered, disclosed, patched, and eventually remediated over a period measured in weeks or months.

For most of my career, patch management was a predictable operational discipline. My teams would accumulate patches throughout the month, test them carefully, and deploy them during scheduled maintenance windows, often on the last weekend of the month. The process balanced security, stability, and operational risk. Today, that model is rapidly becoming obsolete.

Advancements in artificial intelligence are fundamentally changing the balance between cyber defenders and cyber attackers. New AI systems are capable of identifying software vulnerabilities at a speed and scale never before possible. While this breakthrough presents tremendous opportunities to strengthen security, it also introduces a new and unsettling question: what happens to the organizations that are not using these capabilities?

Understanding Mythos and Project Glasswing

A major catalyst for this discussion has been Anthropic’s Project Glasswing, an initiative designed to help secure critical software infrastructure using advanced AI models. According to Anthropic, Project Glasswing provides a select group of technology, security, and infrastructure organizations with access to Claude Mythos, an advanced AI system specifically focused on identifying software vulnerabilities before they can be exploited.

The reported capabilities of Mythos are extraordinary. Internal and industry assessments describe a system capable of discovering previously unknown vulnerabilities, reverse engineering software, identifying weaknesses across major operating systems and platforms, and accelerating defensive security efforts dramatically. Organizations participating in Glasswing have reportedly identified thousands of significant vulnerabilities in software systems that had been considered secure for years.

For healthcare leaders, the implications are profound. As noted in a recent board briefing that I presented, security leaders have described this not as hype or fearmongering, but as a fundamental shift in cybersecurity operations. The traditional time between a vendor releasing a patch and attackers developing an exploit may be collapsing from weeks to mere days, or even hours.

The Flood of Security Patches

Many technology teams are already experiencing the visible effects of this transition.

Across healthcare, financial services, government, and major industries, organizations are receiving an increasing volume of security alerts, vulnerability notifications, and urgent patch recommendations from their vendors. Software manufacturers, cloud providers, and infrastructure suppliers are identifying weaknesses and aggressively distributing fixes.

At first glance, this appears to be a positive development.

The vendors sending notifications are actively searching for vulnerabilities. They are investing in advanced security programs. They are leveraging AI-assisted code reviews and automated scanning technologies. Most importantly, they are communicating openly with us about potential risks and remediation steps.

These organizations understand that in the age of AI-driven vulnerability discovery, speed matters. Every day a vulnerability remains unpatched creates an opportunity for exploitation.

The increased volume of patches does not necessarily indicate that software is becoming less secure. In many cases, it reflects greater visibility into risks that have existed for years. What has changed is our ability to find them before attackers do.

The Real Concern: Silence

Ironically, the greatest concern may not be the vendors issuing frequent security alerts.

The greater concern may be those who are not.

When a software supplier has not announced new vulnerabilities, several possibilities exist. The most optimistic interpretation is that their software is exceptionally secure and free of meaningful weaknesses.

Realistically, that is unlikely.

Every meaningful software platform contains vulnerabilities. The history of cybersecurity has repeatedly demonstrated that no operating system, application, database, middleware platform, or device ecosystem is immune to defects.

A more probable explanation is that some providers have not yet adopted the next generation of security scanning technologies. Their source code may not have been thoroughly examined by modern AI security systems. Their products may simply not have received the same level of scrutiny that larger technology organizations are now applying.

This creates a dangerous asymmetry.

What may emerge is a new cybersecurity divide. Organizations with access to advanced AI-assisted vulnerability discovery will continuously identify and remediate weaknesses before they are exploited. Organizations without those capabilities may unknowingly fall further behind. The gap is not merely technological. It is operational. Security leaders are increasingly making decisions based on vulnerabilities discovered yesterday, while others may still be working from risk assessments performed months ago. The result could be an uneven security landscape where the strongest organizations become more secure while less mature organizations become increasingly attractive targets.

Attackers Do Not Need Permission

The cybersecurity industry has traditionally focused on responsible disclosure. Researchers discover vulnerabilities, vendors are notified, patches are developed, and customers implement fixes.

Artificial intelligence may compress this entire cycle.

As AI capabilities become more widespread, cybercriminal organizations will gain access to increasingly sophisticated vulnerability discovery tools. Even if the most advanced systems remain controlled, history suggests that comparable capabilities eventually proliferate across the market.

The critical question becomes whether defensive organizations can find vulnerabilities before adversaries do.

There is little reason to believe that smaller vendors, niche software companies, and under-resourced third parties are escaping attention from threat actors. On the contrary, they may represent attractive targets precisely because they lack the security maturity of larger technology providers.

For healthcare organizations, this creates a supply-chain challenge. A hospital may invest heavily in its own defenses, maintain strong security operations, implement multifactor authentication, monitor networks continuously, and conduct regular assessments. Yet a compromise at a trusted third-party vendor can still create operational, financial, and reputational harm.

The Third-Party Risk Reality

This concern is not theoretical.

Many organizations have observed that a significant percentage of cybersecurity incidents originate with third-party providers rather than internal systems. Some incidents are relatively minor, involving insignificant exposures with little operational impact. Others, however, have the potential to disrupt critical business functions.

The interconnected nature of modern healthcare amplifies this challenge.

Health systems depend on hundreds, and sometimes thousands, of vendors. Electronic health records, medical devices, cloud platforms, billing systems, patient engagement tools, analytics services, and integration partners all form part of a complex digital ecosystem.

Every connection represents both business value and potential risk.
The fact is that traditional third-party risk programs have not always delivered the protection organizations expected. Instead of simply evaluating compliance questionnaires and audit reports, organizations increasingly need to understand how vendors are actually connected, what systems they can access, and how rapidly they can respond when vulnerabilities emerge.

The question is no longer whether a vendor has vulnerabilities.

The question is whether they can find and remediate them before attackers do.

Resiliency Is the Strategic Imperative

While cybersecurity leaders continue strengthening defensive capabilities, an equally important shift is occurring.

The focus is moving from prevention alone to resiliency.

No security program can guarantee that every attack will be stopped. The complexity of modern technology ecosystems makes such a promise unrealistic. AI-driven attack capabilities only reinforce this reality.

Resilient organizations assume that some defenses will eventually fail.

They prepare for rapid detection, containment, recovery, and business continuity. They design systems that can continue operating even when certain components become unavailable. They test recovery processes, practice incident response, and ensure critical functions can be restored quickly.

In healthcare, resiliency means more than restoring servers and applications. It means preserving patient care during disruption. It means ensuring clinicians can continue caring for patients even when technology systems are degraded. It means maintaining communications, supply chains, scheduling systems, and revenue-cycle operations while recovery efforts are underway. The most important question is no longer whether an organization will experience a cyber event. The question is whether the organization can continue to fulfill its mission while responding to one.

The organizations that thrive in this new era will be those that combine modern defensive capabilities with mature resiliency programs. They will aggressively patch vulnerabilities, continuously assess third-party risks, strengthen operational readiness, and build architectures capable of withstanding inevitable disruptions.

Conclusion
Artificial intelligence is transforming cybersecurity faster than many anticipated. Initiatives such as Project Glasswing and technologies like Mythos have demonstrated that AI can uncover weaknesses at a scale impossible through traditional methods alone.

The growing flood of security patches from major vendors should be viewed as evidence of progress, not failure. These organizations are finding problems and addressing them.

The more difficult question concerns the vendors who remain silent. In an environment where AI can expose vulnerabilities faster than ever before, the absence of alerts may represent a lack of visibility rather than a lack of risk.
As healthcare and other critical industries become increasingly interconnected, third-party risk will remain one of the most significant cybersecurity challenges facing leadership teams.

The greatest cyber risk may no longer be the vulnerabilities we know about. Those vulnerabilities are being identified, disclosed, and patched at unprecedented speed. The greater risk may be the vulnerabilities that remain undiscovered inside the software and third-party services upon which we depend every day. As AI accelerates vulnerability discovery, organizations that fail to embrace these capabilities may unknowingly become the weakest links in an increasingly interconnected ecosystem. In this new era, cybersecurity is no longer simply about defense. It is about visibility, speed, and, above all, resiliency.

Success will not be measured solely by preventing attacks. It will be measured by how quickly organizations can adapt, recover, and continue delivering their mission when attacks inevitably occur.

At the Becker's 11th Annual IT + Revenue Cycle Conference: The Future of AI & Digital Health, taking place September 14–17 in Chicago, healthcare executives and digital leaders from across the country will come together to explore how AI, interoperability, cybersecurity, and revenue cycle innovation are transforming care delivery, strengthening financial performance, and driving the next era of digital health. Apply for complimentary registration now.

Advertisement

Next Up in Cybersecurity

Advertisement