AI-powered vulnerability scanners are now surfacing security flaws that have existed undetected in production codebases for decades. The discovery rate is outpacing the patch deployment cycles most IT organizations are built for. Simultaneously, open-weight AI models are putting near-equivalent discovery capabilities into the hands of malicious actors, with an estimated lag of only 3 to 12 months behind frontier tools.
In this interview on TFiR, Simon Ritter, Deputy CTO at Azul, covers how AI is compressing the software security lifecycle, what a realistic patch management posture looks like under this pressure, and why the window between vulnerability discovery and exploitation is narrowing fast.
Guest: Simon Ritter, Deputy CTO at Azul
Show: TFiR
Here is what every security engineer and platform team needs to know.
Technical Deep Dive
Q: How is AI changing the rate at which security vulnerabilities are discovered in software?
Simon Ritter, Deputy CTO at Azul, explains that AI is creating a real acceleration in the speed at which vulnerabilities must be identified and patched. AI tools are not only finding new bugs but are surfacing flaws that have existed in codebases for decades without detection. Ritter cited a documented case where an AI system identified a vulnerability in OpenBSD that had been present in the source code for 27 years.
“AI is finding things that haven’t been found before and even things that have existed in software for a long time.”
Simon Ritter, Deputy CTO, Azul
Q: What does a “tsunami” of security vulnerabilities mean for IT patch management?
Ritter describes the incoming volume of AI-discovered vulnerabilities as a tsunami, a term used in the industry to signal a structural, not cyclical, increase in patch load. IT teams will face a prolonged period of heightened pressure to identify, prioritize, and deploy patches across their software stacks. The challenge is not a single event but an ongoing operational reality that requires new processes and tighter patch deployment timelines.
“IT teams are facing quite a prolonged period of time where we’re going to have to be much more on the ball and much more focused on figuring out how to roll out those patches so that we can keep our system secure.”
Simon Ritter, Deputy CTO, Azul
Q: Can open-weight AI models give malicious actors the same vulnerability discovery capabilities as frontier AI?
Ritter confirms that bad actors do not need access to proprietary frontier models to exploit AI-driven vulnerability discovery. Open-weight models such as Qwen are already capable enough to be useful to malicious actors, and the capability gap between open-weight and frontier models is estimated at only 3 to 12 months. As open-weight models continue to improve, that window closes further, making the threat timeline shorter than most organizations plan for.
“Those open weight models will develop and people who are malicious actors can then start using those.”
Simon Ritter, Deputy CTO, Azul
Q: What must organizations prioritize to stay ahead of AI-accelerated security threats?
Ritter is direct: organizations must focus on ensuring that patches are delivered and that customers are installing them in a timely manner. The symmetry of tools means that the speed advantage belongs to whoever deploys first. Security teams that maintain fast, consistent patch rollout cycles are better positioned to close vulnerabilities before they can be weaponized by actors using the same AI discovery tools.
“We really need to focus on making sure that we are delivering all of those updates and our customers are installing them in a timely manner.”
Simon Ritter, Deputy CTO, Azul
Resources & Documentation
- Azul JVM Security, Azul’s resources on JVM-level security capabilities and patch management for Java runtimes
***
👇 Click to Read Full Raw Transcript
Swapnil Bhartiya: If I ask you in general, how does the software lifecycle looks like after AI?
Simon Ritter: I think what we’re seeing there is just a real acceleration in terms of the way that we need to respond to changes that are required in terms of software, that’s both bug fixing and security patches. Security patches is obviously the big thing because as you say, I mean, it’s that approach where we have to adapt to the fact that there is going to be, and some people call it a tsunami of security vulnerabilities that are identified. AI is finding things that haven’t been found before and even things that have been existing or have existed in software for a long time. I think the example that I read about was that Mythos had found one vulnerability in the OpenBSD operating system that had been around for 27 years. So it hadn’t been the source code had been there for 27 years. The vulnerability hadn’t been identified. So it’s going to be finding things that have been there for a while, not new things, but been around for a while, and it’s just finding those and exposing them. Now, we certainly got the idea of being able to then use AI to figure out how to resolve those problems as well, but it means that IT teams are facing quite a prolonged period of time where we’re going to have to be much more on the ball and much more focused on figuring out how to roll out those patches so that we can keep our system secure. Because, as you say, bad actors as well will be using the same tools. Maybe not Myth, but you know, we’ve got the open weight models, things like Quin and so on that they can use, and even those open weight models, they’re not as good as Mythos at the moment, but again, the prediction I’ve seen is that they are only somewhere between 3 and 12 months behind. So those open weight models will develop and people who are malicious actors can then start using those. So we really need to focus on making sure that we are delivering all of those updates and our customers are installing them in a timely manner.





