Advances in artificial intelligence are dramatically accelerating cyber threats by enabling faster discovery and exploitation of software flaws, according to a recent report by J.P Morgan Asset and Wealth Management. The average window between vulnerability disclosure and its first exploitation has plummeted to just a single day, effectively turning standard security gaps into zero-day events. Researchers warn that as advanced AI systems like Mythos and GPT 5.5 evolve, this exploitation window could collapse further to a single minute by 2027.
Threat actors—including ransomware operators, terrorists, and hacktivists—are leveraging AI to reverse-engineer software patches within minutes to deploy functional exploits. Initial testing of frontier AI models uncovered over 10,000 high-severity zero-day vulnerabilities in a single month. This surge contributed to an 18% rise in global cyberattacks in 2025, reaching roughly 75,000 attacks every hour, with phishing remaining the primary vector.
Despite these risks, AI also offers critical defensive capabilities. Tools from developers like OpenAI and Anthropic can automatically detect flaws, propose code fixes, and accelerate remediation. To survive an impending "tsunami of patches," J.P. Morgan advises businesses to prioritize the speed of patch deployment and remediation over absolute accuracy alone.