It’s no surprise that AI has altered the technology landscape and added more complexity for IT teams. And when it comes to vulnerability management and patching, scheduled security is now outpaced by AI-detected vulnerabilities. This new complexity means our traditional, time-bound routines have become a liability—creating a lag time between threat discovery, containment, and remediation.

Anthropic’s recent Project Glasswing update proves what security teams have known for a while: The traditional patch cycle simply doesn't work when exposures are discovered at machine speed. Anthropic stated its Claude Mythos Preview model discovered over 10,000 high- or critical-severity vulnerabilities across major enterprise software in just weeks.

While AI has made identifying vulnerabilities near-instantaneous, finding them is only half the battle. The true challenge for IT leaders lies in the operational delay that follows—the critical gap between discovering a threat and enforcing the necessary containment or remediation before it can be exploited.

The real risk: Time between discovery and enforcement

Automating a deployment script misses the real operational bottleneck. In a hybrid environment, safely deploying a patch or rolling out a new build takes time, which requires testing, change approvals, and staged maintenance windows to protect and coordinate system uptime.

The delay between discovering vulnerabilities and addressing them becomes the risk. Relying on scheduled, periodic cycles creates three clear issues:

  • The exposure window: Even mature pipelines require hours or days to test and deploy a fix safely. Attackers exploit this exact window, moving minutes after a vulnerability goes public.
  • Predictable routines: Security postures that are only checked on a rigid schedule become highly predictable and create a false sense of security.  Malicious actors use automated bots and tooling to scan for vulnerabilities, they don't wait for schedules or routines.
  • Human-gated delays: While final deployments can be automated, the surrounding governance, such as architectural sign-offs and compliance reviews, remains human-bound, leaving exposures open at runtime.

Defending against automated threats means teams cannot leave systems exposed while waiting for a complete development cycle. 

Shrinking the containment window from days to minutes

To defend against machine-speed threats, organizations must shift away from waiting on the next scheduled maintenance window. Security enforcement needs to become an active, real-time response that contains threats the moment they are detected.

By automating these immediate containment steps, teams can shrink a typical multi-day or multi-week remediation cycle down to a near-instantaneous automated response. This doesn't replace the thorough testing required for a permanent software patch or an immutable build; rather, it safely buys the enterprise the time it needs to deploy those permanent fixes without leaving systems wide open to exploitation.

This is where Event-Driven Ansible, included in Red Hat Ansible Automation Platform, changes the operational dynamic. Instead of relying on a human engineer to manually triage a ticket and log into a console, Event-Driven Ansible acts as an automated circuit breaker. When a high-signal security tool identifies a critical exposure, Event-Driven Ansible can instantly trigger targeted, pre-approved playbooks to isolate the affected asset, tweak a security group, or temporarily revoke a compromised credential, supported with human-in-the-loop approval steps for higher risk actions.

Protecting uptime and restoring baselines

The next step in this evolution is combining event-driven execution with AI intelligence. Shifting to an orchestration model delivers operational benefits that go far beyond basic vulnerability patching:

  • Continuous compliance: Security baselines are enforced continuously at runtime. This turns compliance from a stressful, point-in-time audit into a natural byproduct of daily operations.
  • Uptime-aware remediation: The platform monitors system health during execution. If a containment action or configuration change disrupts production, the system can automatically rollback to protect uptime while instantly elevating the alert to SecOps. This human-in-the-loop guardrail allows engineers to step in and deploy alternative mitigations, such as tightening perimeter security or modifying firewall rules, rather than leaving an exposure unprotected.
  • Breaking the exploit chain: Automated orchestration can continuously correct things such as configuration errors and drift. But what about watching for things you don’t know about? Attackers will leverage lateral pathways they need to move through your network in unknown or new unpredictable ways. The recently announced automation orchestrator is designed to turn isolated automated responses into a continuous, guarded security loop that handles both software flaws and configuration issues. The resulting workflows combine contextual analysis and human-in-the-loop governance to execute and scale across fleets.

The bottom line

AI is making vulnerability management more complex. IT operations leaders must evolve from time-bound routines using automation to continuous and event-driven results minimizing lag time between threat discovery and containment allowing teams to reduce risks in minutes and restore systems to a secure baseline more efficiently.

Next steps

To close the velocity gap and move your enterprise from scheduled patching to continuous, event-driven enforcement, check out these resources:

리소스

비즈니스 자동화의 5단계

이 e-book에서는 Red Hat Services가 엔터프라이즈 수준의 자동화를 도입하여 팀을 통합하고 프로세스를 표준화하고 IT를 혁신하는 데 어떻게 도움이 되는지 살펴봅니다.

저자 소개

Richard is responsible for the Ansible Automation Platform strategy. With more than 16 years of experience in Financial Services IT across a range or operational, design and Architecture roles. As well as being an Ansible customer before joining the Red Hat team, he brings a customer focused viewpoint to compliment the strong engineering capabilities of one of the most popular open source projects.

UI_Icon-Red_Hat-Close-A-Black-RGB

자세히 알아보기

채널별 검색

automation icon

오토메이션

기술, 팀, 인프라를 위한 IT 자동화 최신 동향

AI icon

인공지능

고객이 어디서나 AI 워크로드를 실행할 수 있도록 지원하는 플랫폼 업데이트

open hybrid cloud icon

오픈 하이브리드 클라우드

하이브리드 클라우드로 더욱 유연한 미래를 구축하는 방법을 알아보세요

security icon

보안

환경과 기술 전반에 걸쳐 리스크를 감소하는 방법에 대한 최신 정보

edge icon

엣지 컴퓨팅

엣지에서의 운영을 단순화하는 플랫폼 업데이트

Infrastructure icon

인프라

세계적으로 인정받은 기업용 Linux 플랫폼에 대한 최신 정보

application development icon

애플리케이션

복잡한 애플리케이션에 대한 솔루션 더 보기

Virtualization icon

가상화

온프레미스와 클라우드 환경에서 워크로드를 유연하게 운영하기 위한 엔터프라이즈 가상화의 미래