The traditional vulnerability management playbook, built on the assumption that defenders have time between disclosure and exploitation, is failing. Three stories logged on this beat in recent weeks - a zero-day in Meta's Muse AI assistant, a report on attacks against enterprise infrastructure management systems, and a new tool for writing remediation scripts where no vendor patch exists - all point to the same conclusion. Attackers are now operating inside the window that used to belong to defenders, and the tools and systems that enterprises depend on are themselves becoming the attack surface.
Exploitation Now Outpaces Disclosure
The most striking data point comes from the InfraTrust report covered by BleepingComputer, which found that attackers are increasingly targeting the management systems used to control enterprise infrastructure, with several critical vulnerabilities actively exploited before or shortly after vendors disclosed them. This is not a marginal shift. Management systems are the control plane for enterprise networks. Historically, they were considered lower-priority targets because they were less exposed and because defenders assumed they had time to patch after a vendor advisory. Both assumptions are now wrong.
SiliconANGLE, in its coverage of Vicarius's ScriptAI launch, cited the Zero Day Clock showing mean time to exploit stood at negative eight hours as of July. That means the average exploit arrives eight hours before the vendor discloses the flaw. The disclosure that used to start the defensive clock now arrives after the attack has already begun. For US technology companies operating large enterprise estates, this inverts the entire remediation workflow. Patch prioritization based on CVSS scores and vendor timelines assumes the attacker is waiting for the starting gun. The data suggests they are not.
When the AI Helper Becomes the Backdoor
The Meta Muse incident, reported by Wired, illustrates how quickly the attack surface expands when AI assistants are embedded in endpoint systems. Meta says it issued a fix for a Muse zero-day vulnerability that would have let attackers do "whatever" they wanted on a victim's Mac. The phrasing matters. This was not a nuisance vulnerability or a data exposure limited to the assistant's own sandbox. It was a path to full control of the user's machine.
AI assistants are uniquely dangerous in this context because they are granted broad permissions by design. They need to read files, interact with applications, and execute tasks on the user's behalf. That is what makes them useful. It is also what makes a vulnerability in them catastrophic rather than contained. When a conventional application is compromised, the blast radius is often limited to that application's data and permissions. When an AI assistant is compromised, the blast radius is the user's entire session, and potentially every system that session can reach.
For US enterprises that have rushed AI assistants into production over the past two years, the Muse vulnerability is a warning about architecture, not just patching. The permissions that make these tools effective are the same permissions that make them high-value targets. Meta's fix addresses this specific flaw, but the pattern is structural. As AI assistants become more capable and more deeply integrated into endpoint workflows, the severity of vulnerabilities in them will rise proportionally. The security model for these tools has not caught up with their deployment.
The Control Plane Is the New Front Line
The InfraTrust findings and the Meta disclosure are often treated as separate categories of risk, but they share a common characteristic. Both involve systems that hold privileged access by design. Management systems control infrastructure. AI assistants control user sessions. In both cases, the attacker does not need to compromise the underlying asset directly. They compromise the tool that manages it.
This is an efficient attack strategy. Management systems and AI assistants are typically not subject to the same rigorous security review as public-facing applications, because they were not historically internet-exposed. They are often deployed with broad credentials and minimal segmentation. Once an attacker has a foothold in the management layer, they can move laterally with the privileges of the system itself, which are often extensive.



