Two AI systems arrived five weeks apart this year. One finds vulnerabilities and exploits them. The other finds vulnerabilities and fixes them. Attackers are now weaponizing a new CVE in under five days. Most enterprises still take more than 60 days to patch a critical one.
In this episode of EM360’s The Security Strategist podcast, host Richard Stiennon talks with Brinqa CSO & COO Brad Hibbert on what changes when offensive AI tools like Mythos start chaining medium and low-severity findings into full system compromises, the kind of findings that traditionally sit at the bottom of a remediation queue. Hibbert's answer: the volume of findings was never the real problem. Knowing which ones matter, and acting on that faster than your own change-management process, is.
Hibbert walks through why a low-severity firmware flaw on something as unremarkable as a fish-tank sensor became the opening move in a real breach, and what that means for how security teams should be scoring risk. He also gets into where defensive AI is headed next: agents that review code the moment it's checked in, flag weaknesses before release, and eventually propose their own fixes before a developer sees the pull request.
What you'll learn:
- Why attackers chaining low-severity findings together is a bigger shift than faster exploitation
- What separates a vulnerability count from an actual attack path
- Why patch counts are the wrong scoreboard for CISOs, and what to track instead
- Where agentic AI is headed inside the software development lifecycle
- The one question Hibbert says every CISO should ask their team on Monday morning
Watch the full conversation above, then see how Brinqa's CyberRisk Graph turns attack-path context into a prioritization program your team can actually defend.