
AI is speeding up exploits and vulnerability spreadsheets can't keep up
In a RapidFort-sponsored column for The New Stack, COO and co-founder Russ Andersson argues that AI is accelerating both vulnerability discovery and exploit development, while severity-based spreadsheets no longer capture real risk.
In a sponsored column published by The New Stack on October 3, Russ Andersson, COO and co-founder of supply chain security vendor RapidFort, argues that AI is widening the gap between the vulnerabilities security teams find and the ones they can fix. More software is being written, flaw discovery is accelerating and the time needed to build exploits keeps shrinking.
Severity is not the same as risk
The classic model has barely changed for years: scan software, identify CVEs, assign severity scores, prioritize findings, hand them to developers. Andersson says it never reflected risk faithfully, and AI is exposing its limits. AI-enabled attacks can also chain individual flaws into attack paths that are hard to anticipate by hand.
The core of the argument: a CVE, or its CVSS score, says nothing about whether an exploit exists, whether the flaw is exploited in the wild, whether the vulnerable component is exposed, or whether the vulnerable code path actually executes. The same CVE can mean very different risk in another organization. “The CVE is identical. The risk is not,” Andersson writes. Severity-driven programs, he adds, risk “CVE theater”: measuring activity instead of meaningful risk reduction.
Scan what is actually running
His prescription starts before deployment: hardened base images and curated libraries shrink the vulnerability footprint, SAST and AI-assisted code scanning cover first-party code, and configuration frameworks such as STIGs catch weaknesses outside the CVE list. A system can carry few CVEs and still be dangerously configured, he notes.
From there, production is the source of truth: scanning registries before release reflects perceived risk, not what is deployed, and images and configurations keep changing. That calls for continuous production scanning and reachability analysis: is the system externally accessible, and does the vulnerable code path actually run?
Prioritizing by real-world exposure
Remediation should then be ordered by context rather than score: threat intelligence from CISA's Known Exploited Vulnerabilities (KEV) catalog and the Exploit Prediction Scoring System (EPSS), combined with production exposure, reachability and business impact. In place of a spreadsheet of thousands of CVEs comes a sharper question: which flaw should we fix first, in this environment, and why?
The goal, he writes, is not an empty dashboard but continuous, layered risk management, with different remediation windows for different classes of vulnerability. His closing metaphor: knowing how many doors exist in the software is not enough. You need to know which are open, which an attacker can reach and which pose the greatest risk now.
RapidFort, which sponsored the column, sells a supply chain security platform that profiles container workloads and removes unused software components.
SiTech — AI-powered web development
We build fast, modern websites and bring AI into real business workflows. Have a project or a question? We'd love to help.