AI-driven vulnerability discovery is outpacing the standards and frameworks defenders rely on. Rapid7's new policy paper, presented at a White House consultation, argues that CVE, CVSS, NVD, KEV, and EPSS were all built for human-speed discovery and are now under severe strain. CVE submissions grew 263% between 2020 and 2025, and NIST has acknowledged NVD can no longer keep pace. AI agents solving cybersecurity tasks jumped from 15% to 93% solve rates in a single year on the Cybench benchmark. The paper proposes reforms including recognizing AI-demonstrated exploitability, adding chaining-risk metadata to vulnerability records, updating the Vulnerabilities Equities Process, standardizing capability disclosure from AI labs, and establishing independent verification standards for AI security tools.

5m read timeFrom rapid7.com
Post cover image
Table of contents
AI vulnerability discovery is changing the rulesVulnerability management standards were built for human speedAI-era vulnerability prioritization needs reformAI vulnerability policy needs verification, access, and accountabilityThe next phase of cybersecurity resilience
136 Impressions