Attackers are moving faster than security experts can patch, Microsoft warns
Patch me if you can.

Image by Getty/Bloomberg
- Attackers can now exploit some vulnerabilities within hours of disclosure, leaving defenders less time to patch.
- Microsoft’s Igor Sakhnov says traditional vulnerability management no longer matches the speed of modern threats.
- AI helps organizations patch faster, but it also helps threat actors move faster.
- Network controls like access restrictions and segmentation can reduce exposure before software patches are ready.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
The window between disclosing and patching a vulnerability and attackers exploiting it is disappearing.
For decades, cybersecurity specialists relied on a model that gave them time to investigate a vulnerability, understand the issue, assess affected systems, test patches, coordinate change windows, and deploy fixes before widespread exploitation occurred.
According to Igor Sakhnov, corporate vice president and general manager for Azure Networking at Microsoft, that model no longer works.
“Traditional vulnerability management was built on the assumption that defenders could move faster than attackers. In many cases, they could,” he says in a lengthy blog about the patch window in today’s world.
Security research, public disclosures, proof-of-concept exploits, and threat intelligence: in the past, it took days or even weeks to circulate within the cybersecurity community. Nowadays, this is done within mere hours.
Meanwhile, the way security experts handle enterprise environments hasn’t changed. According to Sakhnov, that creates “one of the most dangerous periods in modern cybersecurity.”
Artificial intelligence (AI) is helping organizations immensely to accelerate the patching process. But at the same time, threat actors are moving faster than ever thanks to AI technology.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
“As the patch window continues to collapse, the industry will need new approaches that complement traditional remediation strategies, reduce exposure quickly, and help defenders regain the one resource that has become increasingly scarce in modern cybersecurity: time,” Sakhnov explains.
He argues that network measures are often faster and easier to implement than validating and deploying software patches.
Therefore, restricting access to vulnerable systems, countering opportunities for lateral movement, and applying network segmentation are emerging as the fastest control planes for businesses and organizations.