AI Attacks Now Exploit Vulnerabilities in HOURS | Sergej Epp | Security Monday S1 E4

AI Attacks Now Exploit Vulnerabilities in HOURS | Sergej Epp | Security Monday S1 E4

🎙 EVA BENN | CYBERSECURITY | AI 👥 101K 📅 May 11, 2026 ⏱ 35 min 👁 18K 📄 expert opinion 🧭 2026-08-16
Available in: English (current) Français

Keywords

Zero Day Clockexploitation windowAI attackspatchingruntime security

Summary

In this episode of Security Monday, host Eva Benn interviews Sergej Epp, CISO at Sysdig and creator of the Zero Day Clock dashboard. The conversation centers on the alarming acceleration of vulnerability exploitation: from over a year in 2020 to less than a day in 2026, with projections of hours and minutes. Epp explains that Zero Day Clock aggregates data from trusted sources like CISA and VulnCheck to track the time from vulnerability disclosure to active exploitation. He argues that traditional patching is no longer sufficient, advocating for a shift to runtime security, zero trust, and assume-breach strategies. The discussion covers practical steps for CISOs, including five key questions to ask their teams and how to present this data to boards. Epp also shares his personal AI experiment that demonstrated how easily AI can find zero-day vulnerabilities, highlighting the need for defensive innovation. The episode emphasizes the urgency for organizations to adopt autonomous security measures and rethink their defense architectures.

160 words

Critical Evaluation

Value of the Information & Strength of the Argument

The video provides valuable insights into the current state of vulnerability exploitation, supported by concrete data from the Zero Day Clock dashboard and references to authoritative sources like CISA and VulnCheck. The argumentation is coherent and persuasive, emphasizing the collapse of the patching window and the need for proactive, runtime-focused security. Epp’s experience as a CISO lends credibility, and his practical recommendations (e.g., assume breach, zero trust, least privilege) are actionable. However, some claims are forward-looking and lack empirical evidence, such as the projection of one-minute exploitation by 2028, which is presented as a trend without rigorous statistical backing.

Scientific Rigor, Source Quality, Title Accuracy

The video demonstrates a strong commitment to using reliable data sources: Zero Day Clock relies on CISA’s Known Exploited Vulnerabilities catalog and VulnCheck, both reputable in the cybersecurity community. The presenter also references Sysdig’s 2025 Cloud-Native Security Report and Falco, an open-source runtime security tool. The title accurately reflects the content, focusing on the acceleration of AI-driven exploitation. The discussion is well-structured, with clear explanations of technical concepts, and the guest’s credentials are highlighted. However, the video is primarily an expert opinion piece rather than a peer-reviewed study, and some claims, such as the ‘patching is dead’ narrative, are provocative but not universally accepted.

218 words

Title / Content Match

The title accurately reflects the core topic: the accelerating exploitation of vulnerabilities by AI-driven attacks, as discussed with Sergej Epp.

Quality & Reliability

8/10

The video features a recognized CISO with extensive industry experience, and the claims are supported by references to specific data sources (CISA, VulnCheck) and a live dashboard (Zero Day Clock). However, the discussion is largely anecdotal and forward-looking, with limited peer-reviewed evidence, and the presenter's own AI experiment is not detailed.

Chapters

Cited Sources

  • Zero Day Clock live dashboard — The main subject of the video; a live dashboard tracking vulnerability exploitation timelines.
  • Sysdig 2025 Cloud-Native Security Report — Referenced as a source of data on cloud-native security trends.
  • Falco open source runtime threat detection — Mentioned as a tool for runtime security, created by Sergej Epp.
  • Sysdig Sage AI cloud security analyst — Mentioned as an example of AI-driven security analysis.
  • CISA Known Exploited Vulnerabilities — One of the primary data sources for Zero Day Clock.
  • VulnCheck exploit intelligence — Another primary data source for Zero Day Clock.
  • Sergej Epp LinkedIn — Guest's professional profile.
  • Sysdig — Guest's employer and a cloud security company.
  • Eva Benn LinkedIn — Host's professional profile.
  • Eva Benn Website — Host's personal website.

Concurring Sources

  • Sysdig 2025 Cloud-Native Security Report — Provides data on cloud-native security trends that align with the video's claims about increasing attack speed.
  • CISA Known Exploited Vulnerabilities — The catalog confirms the existence of actively exploited vulnerabilities, supporting the video's premise.

Dissenting Sources

  • No direct discordant sources found — The video does not present conflicting sources, but some claims about AI-driven exploitation speed may be debated in the industry.

Contribution & Novelties

The video introduces the Zero Day Clock, a novel dashboard that visualizes the shrinking time between vulnerability disclosure and exploitation, providing a tangible metric for security leaders. It also highlights the impact of AI on offensive security, with Epp’s personal experiment demonstrating how AI can accelerate vulnerability discovery. The discussion offers practical guidance for CISOs, including specific questions to ask their teams and how to communicate urgency to boards.

Pour aller plus loin :

  • CISA Known Exploited Vulnerabilities Catalog — Official catalog of actively exploited vulnerabilities, a key data source for Zero Day Clock.
  • Falco — Open-source runtime security tool for containers and Kubernetes, relevant to the runtime security discussion.
  • Zero Trust Architecture — A security model referenced in the video as a key defensive strategy.
  • NVD (National Vulnerability Database) — The NVD is mentioned as struggling to keep up with vulnerability disclosures, relevant to the data reliability discussion.

149 words

Radar Profile

The radar profile shows high scores in information quantity, quality, and reliability, with a slightly lower technical depth. This indicates a well-informed discussion with practical insights, suitable for cybersecurity professionals seeking actionable advice.

Reliability 8/10