ai-cybersecuritytrade-pressNewsThe Broadside1 min read

ISACs weigh risk triage as AI swells CVE backlog

The feed-everything model cannot survive a vulnerability market where discovery accelerates faster than patch capacity.


TL;DR

Inside Cybersecurity reports that IT-ISAC, Health-ISAC and Retail and Hospitality-ISAC leaders are exploring risk-based triage for vulnerability intelligence as AI-driven discovery increases volume. The CVE program logged 48,244 records in 2025 and 35,872 in the first half of 2026. For members, the operative question is no longer whether to patch everything; it is which exposed, exploitable systems move first.

The useful admission from the July 14 Cyber Threat Alliance webinar was not that artificial intelligence will produce more vulnerability noise. Everyone in the patch queue already knows that. The admission was that information-sharing groups now have to decide what not to push with equal force, because members cannot remediate every CVE at the speed frontier models may help find them.

IT-ISAC's Jonathan Braley pointed to the numbers: 48,244 CVE records in 2025, then 35,872 in the first half of 2026. He said only a small percentage are likely to be exploited by a threat actor. That is the practitioner problem hiding under the word intelligence. A larger feed is not more useful if it leaves the security team with the same backlog and less confidence about which asset is actually exposed.

Braley cited CISA's June 10 binding operational directive for federal civilian agencies as a model moving in the right direction. The directive uses criteria including asset exposure, exploit automation, technical impact and presence in CISA's Known Exploited Vulnerabilities catalog. That is not a universal scoring oracle, and Braley did not pretend it was. It does, however, put the argument where it belongs: exploitability, exposure and operational consequence, rather than CVE volume by itself.

For ISAC members, the change is likely to show up as more context and fewer undifferentiated alerts, if the groups execute well. Health-ISAC's Errol Weiss emphasized cross-sector sharing around identity attacks, deepfakes and phishing. Retail and Hospitality-ISAC's Pam Lindemoen put the sharper point on it: AI creates more information to sort through, but members need trusted context. That means the traditional feed model is insufficient on its own. The value moves to prioritization, sector relevance and the uncomfortable call that some vulnerabilities wait.


Published ·Deep Fathom