Otto  background

Reducing Endpoint Risk When There's No Patch Available

Frontier AI is finding vulnerabilities faster than teams can patch. Managing the risk when there’s no patch is the harder job.

Connect With Us

See for yourself how policy-driven IT Automation saves time and eliminates risk.

This week set another Patch Tuesday record: 973 vulnerabilities, up 70% from the previous high of 570 set in July. The number of patchable vulnerabilities keeps outpacing what IT and security teams can actually execute. Frontier AI models are why. They're finding vulns faster than we humans ever could.

It's great that major software vendors are providing patches in a relatively timely manner. But many others are not. The gap between discovery and root-cause remediation in a patchable vulnerability is often far too long for most organizations' risk tolerance. With a three-day federal directive to remediate high-risk exploitable vulns, we all need governance to drive execution at a whole new speed. But governance focused on patching misses most of the iceberg.

More unpatchables mean more mitigations and more difficulty

An even greater risk than reducing the exposure window for patchables is the growing number of unremediated vulnerabilities, which Verizon's 2026 DBIR cites as 74% of vulnerabilities in 2025. That includes patches still in development, vendors that can't or won't deliver a fix, and vulnerabilities that are inherently unpatchable. And the 26% of remediated vulnerabilities in 2025 is down from 38% in 2024, so we're going the wrong way even before frontier-model impact. That's a big deal, because many governance plans focus on time to patch, leaving the 74% to be mitigated in a higher-risk, ad hoc state.

Unpatchables are even more insidious over time because, unlike a patch that is applied and sticks, configuration changes can be reversed or compromised. So operationalizing unpatchable mitigations isn't a one-time task. Configuration drift is real and must be addressed as part of operational governance.

Prioritizing mitigation governance

Patch Tuesday gives us a clear view into the increased risk coming out of the frontier models. But if we see that volume as only the tip of the iceberg, we also need to rethink governance design and operational execution. Patching becomes the must-have checkbox. Unpatchables are the harder part, representing the biggest threat and largest opportunity for bad actors. Mitigation governance becomes a first-class citizen in enterprise security and risk management. Execution of that governance becomes a first-class priority for enterprise IT teams.

Automox works with tens of thousands of enterprise IT and security leaders. Since April, starting with Mythos and moving through model after model, we have focused on helping those leaders and practitioners navigate this unprecedented change. While frontier models continue to evolve faster and faster, the mission has remained remarkably consistent: ingest vulnerabilities, govern prioritized remediation and mitigation, and verify executional outcomes. All of it happens at AI speed (which continues to increase).

Operationalizing patch and mitigation risk reduction

Coming into this year, Automox was fortunate to be in the right place at the right time. And no, I don't mean Mythos was lucky. In February, months before frontier-model disruptions, we launched an application built on top of the Automox platform. That app was AI-trained on our history of billions of policy runs. We built it to prescribe the patching and mitigation policies needed to deliver a customer's personalized desired outcomes. We called the app and accompanying white-glove drift management Turnkey Results. Little did we know that, beginning in April, we would need to lean on that app to process many times the volume of work.

The frontier labs have increased the volume and velocity far beyond what humans can triage, prioritize, and execute. But the mission remains the same: patch and mitigate as fast as possible. There's just more to patch, and more to mitigate, and it's all moving faster and faster.

The moment to harden the system is now

Last month, I wrote an article outlining our approach to tackling the future of IT and security. Rather than coming from a crystal ball none of us has, it comes from anchoring to the fundamentals. It's about applying the power and capacity of automated remediation and mitigation to the rapidly increasing threat of AI-speed vulnerabilities and exploitation. None of us needs a crystal ball to know the exploitation phase of this disruption is coming soon and hard.

This week, Automox launched a new AI-speed mitigation capability first contemplated in May. While we've been mitigating at enterprise scale with Automox Worklet™ technology since 2019, Automox humans historically initiated and developed new mitigations in response to vulnerabilities. That speed is no longer fast enough. To bridge that gap without introducing AI-slop risk, we developed a proprietary high-velocity AI-driven pipeline. It runs over a dozen proof points and checks that ultimately culminate in expert human review. That process takes minutes to hours, rather than days to weeks. It scales. It runs fast. It's thorough. It chews on multiple vulnerability sources to programmatically determine what needs mitigating and the work that needs to be done. Can it mitigate everything? No, not yet. Is it a reliable, fast, AI-speed on-ramp for the unprecedented volume of AI-vulns that can't be patched? Absolutely.

We take the threat of frontier lab vulnerability exploitation seriously. We know the torrent is coming. It's why Automox shipped several innovations this summer to help customers accelerate against these new threats: best-of-breed MCP Server, Tenable integration, Canopy Jamf and Intune MDM orchestration. But none may be as meaningful over the next couple of years as this AI-speed mitigation pipeline. Unpatchables outnumber patchables. Mitigation volume, speed, and drift control are the operational governance bridges we all need to cross. Automox is committed to continuing to ship the capabilities our customers need to remediate and mitigate at AI speed.

Sources

Dive deeper into this topic