• 3 min read
AI shrinks the cyberattack timeline to hours
AI is shrinking the time from vulnerability discovery to exploitation from months to hours, forcing organizations to adopt faster defenses.

Image: TechXplore
Artificial intelligence is accelerating cyberattacks, helping criminals find vulnerabilities, develop exploits and launch campaigns faster and more cheaply. Researchers at the School of Cybersecurity and Privacy (SCP) say the main danger is not entirely new attack methods, but the speed and scale AI brings to familiar ones.
“AI is dramatically speeding up cyberattacks. AI can identify vulnerabilities far faster than humans and often in places humans wouldn’t think to look.”
AI compresses the attack timeline
Most cyberattacks involve finding vulnerabilities, developing an exploit, gaining access and pursuing a goal such as stealing information or disrupting operations. Frank Li, an associate professor in the SCP and ECE, says AI is having its greatest effect in the early stages.
“AI can help attackers explore potential decisions and implement attacks faster than in the past, whether it’s identifying software bugs or constructing social engineering hooks.”
Peter Swire, J.Z. Liang Chair in the SCP and professor of law and ethics in the Scheller College of Business, said the time between discovering a vulnerability and exploiting it has fallen sharply.
“The average time until an exploit was detected, even a couple of years ago, was measured in months. Now it is measured in hours.”
Health care systems, critical infrastructure providers, government agencies and small businesses remain attractive targets because they handle sensitive information or essential services, often on legacy systems. But the researchers stress that every organization is exposed, particularly those with outdated technology or limited cybersecurity resources.

Recommended reading
Glow reaches $1.2B valuation with AI endpoint security
“Unfortunately, everyone is at risk. AI is not creating new victims; AI is making attackers faster and more effective at targeting the same organizations they have always pursued.”
AI-powered defenses and faster patching
The same technology can help defenders identify and patch vulnerabilities, detect subtle intrusion patterns across networks, investigate compromises and deploy targeted protection. Saltaformaggio said AI can support defenders at every stage of responding to an attack.
Georgia Tech’s defensive work includes its recent success in the Defense Advanced Research Projects Agency’s (DARPA) Artificial Intelligence Cyber Challenge, which demonstrated how AI systems can autonomously discover and reason about software vulnerabilities at scale. Swire also noted that a Georgia Tech team led by Professor Taesoo Kim won a $4 million DARPA prize for advanced AI-based cybersecurity defenses.
Trust remains a major requirement. Security tools need to explain their conclusions and provide evidence analysts can verify, while attackers may try to manipulate AI systems themselves.
“AI’s primary impact on cyberattacks is enhancing speed and scale. Organizations need to adapt to more agile defenses and processes that account for this, in many cases relying on AI as well to help speed up defensive actions.”
Swire said traditional patch management cannot keep pace with exploits emerging within hours.
“The entire process for patching systems will have to be re-engineered.”
Swati Mestri holds a bachelor’s degree in Electronics Engineering and has worked as a content editor since 2019.
Andrew Zinin has a master’s degree in physics and research experience, and is a long-time science news enthusiast.
The research was reported by TechXplore on July 22, 2026.
Security Editor
Sophia unpacks the invisible wars happening on our networks. Covering cybersecurity, privacy legislation, and cryptography, she exposes how our data is weaponized and defended. Before joining for(geeks), she spent years as a penetration tester. She's the reason the rest of the team uses physical security keys.
via TechXplore


