AI shrinks exploit window to zero days, ESET warns
Wed, 16th Sep 2026 (Today)
ESET has warned that software vulnerabilities are now being exploited as soon as they are publicly disclosed. Global data shows the median gap between disclosure and exploitation fell to zero days in 2026.
The finding marks a sharp shift from 2018, when the median period between disclosure and real-world exploitation was 771 days, according to analysis from the Zero Day Clock, a project that tracks vulnerabilities confirmed as exploited in attacks.
Scott Leman, Country Manager, ESET NZ, said the shift reflects how artificial intelligence is changing both the speed of technical attacks and the wider online threat landscape for businesses.
"We have reached a tipping point. AI isn't simply making phishing emails more convincing, it is also changing the speed at which attackers can identify and exploit vulnerabilities and the way people find and trust information online.
For years, businesses could reasonably assume that when a new security weakness was discovered, there would be time to understand it, fix it and protect themselves.
That breathing space is disappearing. AI can now analyse a newly released security patch, work backwards to identify the flaw it was designed to fix and help turn that information into a working attack extremely quickly.
In one recent test involving a browser security update, an advanced AI model was able to analyse the patch and produce a working exploit in less than an hour. Historically, that work required specialist expertise and considerably more time."
The warning adds to growing concern among security professionals that advances in generative AI are reducing the time companies have to patch newly discovered flaws. Where defenders once had days, weeks or months to assess a disclosed vulnerability, some attacks can now be prepared almost immediately after a patch reveals what the software maker has fixed.
That creates particular pressure for small and medium-sized businesses, which often lack dedicated security teams or round-the-clock monitoring. Faster exploitation means delays in applying updates carry greater risk, especially for widely used business software and internet-facing systems.
Leman said the window for installing a security update before attackers act on the underlying flaw is becoming extraordinarily short.
"For newly discovered vulnerabilities, automated patching is becoming increasingly important. The faster attackers can turn a vulnerability into an attack, the less time businesses have to close that gap.
For smaller businesses, continuous monitoring and rapid response are becoming increasingly important, particularly as the window to detect and contain an attack gets shorter.
As attacks accelerate, the ability to detect and respond is becoming just as important as trying to prevent them in the first place."
AI search risks
ESET also pointed to a second area of concern linked to AI tools used for search and recommendations. Its research found ChatGPT results directing users to websites already classified as unsafe, including fake online stores, cryptocurrency scams and imitation login pages.
Researchers tracking outputs over a 30-day period also found responses linking to malicious code that could steal information or compromise a device. ESET said this broadens the ways staff may be exposed to fraud, beyond traditional phishing emails or text messages.
AI tools are becoming mainstream in New Zealand. ESET said four out of five New Zealanders now use AI, while ChatGPT was the country's most downloaded free iPhone app last year.
That trend could change how cyber criminals reach victims. Instead of relying only on inboxes and messages, attackers may benefit when users follow AI-generated suggestions to visit websites, download software or sign into online services.
"Kiwis are increasingly using AI to tell them where to buy something, what software to download or which website to visit.
The risk is that we start placing blind faith in the answers these tools provide. Someone asks an AI tool for help, follows the link it provides and ends up on a fake login page, scam website or malicious download.
Because that recommendation has come from a tool they trust, they may be less likely to question whether the destination is genuine or safe.
What this data shows is that users cannot assume a link is safe simply because ChatGPT has provided it."
Phishing pressure
ESET's New Zealand threat telemetry showed phishing-related threats accounted for 34.9% of all threats detected across its local user base in July. Such attacks typically aim to persuade a target to click a link, open a document, scan a QR code or enter credentials and payment details into a fake website.
Leman said AI is making those attacks harder to spot because it can generate polished, context-specific messages without the spelling and grammar mistakes that once served as warning signs.
"For years, people were told to look for obvious warning signs such as spelling mistakes, poor grammar or an email that simply didn't sound right.
Those clues haven't disappeared, but they are becoming much less reliable. AI can create a polished email in seconds, write it in natural language and tailor it to a particular company, employee or situation.
That means someone can be presented with something that looks completely legitimate and still be handing an attacker the keys to their account or business."
He also said companies should not assume antivirus software alone will stop these threats, particularly where the attacker captures valid login details rather than installing malicious files.
Once an email account is compromised, a criminal may be able to observe conversations, access files, impersonate staff or alter payment instructions. That can turn a basic phishing incident into direct financial loss if customers or suppliers are tricked into sending money to a fraudulent account.
"An attacker could see that an invoice is about to be paid and then send another email from the genuine account saying the bank details have changed.
The customer has little reason to suspect anything is wrong because the message has come from the same email address and may even form part of an existing conversation. By the time either side realises what has happened, the money may already be gone."
The broader picture, Leman said, is that AI is speeding up both attack and defence, but businesses can no longer rely on time to absorb the shock of a new threat.
"Attackers are using it to move faster, identify vulnerabilities and develop convincing attacks, but defenders are also using AI to analyse activity, uncover threats and respond more quickly.
When attackers were moving at human speed, delays were already a problem. As AI increasingly allows attacks to operate at machine speed, businesses and consumers can no longer assume they will have time on their side."