Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.
On September 9, 2026, data from the Picus Blue Report 2026 confirms an operational gap CISOs can no longer delegate: the median time from CVE disclosure to weaponized exploit has crashed to roughly 10 hours, down from 56 days in 2024 and 23 days in 2025. At the same time, 338 million BAS simulations in production environments during H1 2026 show that 58% of offensive actions are logged, but only 14% generate an actionable alert. The defense doesn't lack tools; it lacks validation speed.
- The window from disclosure to weaponized exploit has shrunk from 56 days (2024) to roughly 10 hours (2026), with approximately 135 new CVEs daily in 2026.
- The Blue Report 2026 finds that 49% of detection failures stem from performance issues (doubled from 24% in 2025) and 41% from log collection gaps.
- Anthropic Mythos 5 scored a Cyber Weapon Index of 80 from Booz Allen and produced 181 working Firefox exploits in 14 days of sandbox preview.
- The proposed shift is from today's "schedule-driven" BAS to an agentic "signal-driven" model, with a closed loop of trigger, diagnosis, automated fix, and re-verification.
The Timeline Collapse: From 56 Days to 10 Hours
The figure is central and reported consistently across independent sources: HelpNetSecurity cites "roughly ten hours" as the 2026 median, BleepingComputer specifies the same value from analysis of CISA KEV, VulnCheck KEV, and ExploitDB, and SC World confirms the collapse across 3,532 analyzed CVE-exploit pairs. The contraction isn't incremental; it's a three-order-of-magnitude drop in two years.
Anthropic Mythos 5 accelerated the curve. According to Booz Allen, it reached a Cyber Weapon Index of 80, versus 49 for Grok-4.5. In 14 days of limited sandbox preview with 12 partners, it generated 181 working Firefox exploits, compared to 2 from the prior model. The UK AI Security Institute verified that Mythos completes end-to-end attack chains in capture-the-flag contexts.
Nico Waisman, CISO of XBOW, pinpoints the democratization vector: "You no longer need frontier access to do this." Open-weight models, not frontier models, are shifting the ROI calculus for autonomous attacks. Recorded Future concurs: "The danger for defenders isn't the headline-grabbing frontier models; it's the ease with which adversaries can deploy effective local models on modest hardware."
"Strong performance is rented, not owned." — Volkan Erturk, CTO Picus
The Detection Black Hole: 58% Logged, 14% Alerted
The 338 million BAS tests in H1 2026 reveal a structural pattern. Average prevention effectiveness of controls sits at 69%: one in three attacks bypasses controls. Telemetry has improved — 58% of offensive actions are captured in the SIEM, a four-year high — but the handoff from log to alert is stuck at 14%.
Volkan Erturk, CTO of Picus, cuts to the mechanism: "An AI SOC's unit of work is the alert. Point it at a pipeline where only one attack in seven produces an alert and it will handle that seventh at any speed you like, while the other six stay invisible." Automated triage speed is irrelevant when 86% of attacks trigger no signal at all.
The causes are diagnosed: 49% of detection rule failures stem from performance issues (doubled from 24% in 2024), 41% from log collection gaps. The problem isn't tool scarcity; it's detection engineering that isn't tested frequently enough to uncover silencing and gaps before the adversary does.
The 7-Point Lesson: Security Is Rented, Not Bought
A Blue Report 2026 data point debunks the idea of security as a static asset. Average prevention slipped 7 percentage points in one year, then recovered them the next. The only variable explaining the recovery was testing frequency: more simulations, same technologies, different results.
Erturk summarizes: "Strong performance is rented, not owned." Security is a service that expires if not renewed with continuous validation. The 10 least-prevented vulnerabilities in 2026 — in browsers, archive utilities, OpenSSL, core OS components — are blocked less than 25% of the time. They aren't exotic zero-days; they're everyday software organizations believe they've covered.
Agentic BAS: The Closed Loop Gen 1 Can't Do
Current Gen 1 BAS carries three structural limits documented by the source: the trigger is calendar-driven, it cannot test CVE day-one, and post-test requires manual handoffs across CTI, red team, blue team, vulnerability management, and IT. Erturk calls this pattern "spaghetti handoff": every transition between human teams injects latency the adversary doesn't have.
The agentic BAS proposed by Picus — and agreed by Recorded Future as the strategic direction for BAS and CTEM — is a four-stage loop. First, signal-driven: a CTI signal automatically triggers simulation. Second, diagnosis: determines whether failure lies in telemetry, rule logic, or performance. Third, auto-generates vendor-specific fixes, with human approval at decision gates. Fourth, re-runs the same attack to verify closure. All without real exploits, enabling immediate testability of new CVEs.
Recorded Future positions BAS and CTEM as two of three pillars for defensive AI agents. IBM Think validates the Gartner CTEM framework with the validation step as the key differentiator. Independent sources and vendors converge on direction, not maturity: it's unclear how many organizations have implemented this loop in production versus how much remains in pilot.
What to Do Now
For detection engineering teams, the priority is measuring your own alert coverage with BAS simulations against real attack protocols, not compliance tests. The 14% alert score is an internal benchmark: if your SIEM alerts on fewer than one in seven attacks, automated triage only accelerates failure.
For CISOs, governance must move BAS from calendar to trigger: test frequency must correlate with threat velocity, not the annual budget. The collapse to a 10-hour exploit timeline means a monthly test covers 1.4% of the average CVE lifecycle.
For boards, the gap between AI offensive speed and traditional defense is an existential risk that cannot be delegated to the operational level. The decision to invest in agentic BAS or stay schedule-driven is a corporate resilience choice with a 12-18 month horizon.
For the BAS sector, the category must evolve from "more tests" to "autonomous loop with integrated fix" or face structural obsolescence. A product that doesn't close the loop remains an instrumented consultancy, not a continuous security platform.
The most significant limitation remains the availability of independent data on the operational effectiveness of these agentic loops outside vendor claims. Booz Allen's CWI is a proprietary metric not externally validated. Mythos data comes from sandbox preview, not general release. The transition from product to security architecture is promising, but its real-world adoption is still undocumented.
Information has been verified against cited sources and is current as of publication.
Sources
- https://www.helpnetsecurity.com/2026/09/09/picus-security-autonomous-breach-attack-simulation/
- https://www.darkreading.com/cybersecurity-operations/companies-six-months-prepare-automated-attacks
- https://www.picussecurity.com/platform/breach-and-attack-simulation
- https://www.bleepingcomputer.com/news/security/73-seconds-to-breach-24-hours-to-patch-the-case-for-autonomous-validation/
- https://www.picussecurity.com/
- https://www.recordedfuture.com/blog/build-defensive-ai-agents
- https://www.ibm.com/topics/ctem
- https://www.scworld.com/native/how-to-defend-at-machine-speed-a-post-llm-era-playbook
- https://nvd.nist.gov/vuln-metrics/cvss
- https://discover.picussecurity.com/i%CC%87nteracti%CC%87ve-demos/scv/ai%CC%87-threat-bui%CC%87lder
Get DeafLetter
A weekly selection of signals, vulnerabilities and guides. Critical alerts remain optional.
You can unsubscribe at any time. Privacy policy.