Vulnerability Exploitation Window Plunges to Two Hours as Taiwan Unveils AI Risk Framework
The proliferation of generative artificial intelligence and automated attack tools is driving a structural shift in the global cybersecurity threat landscape. Attackers are using AI to identify vulnerabilities in code and generate malware, posing a major challenge to traditional cyber defenses. Governments and businesses therefore urgently need robust AI governance and security management frameworks to protect critical information infrastructure and digital assets in an increasingly speed-driven contest.
According to the latest Zero Day Clock data, the average time from a vulnerability's disclosure to its exploitation plunged from 21.5 days in 2025 to two hours in July 2026. To guard against AI threats, Taiwan's Ministry of Digital Affairs announced its Artificial Intelligence Risk Classification Framework on July 7, 2026. Effective immediately, the framework divides AI risks into three main categories—technical flaws, operational interactions and societal impacts—spanning 20 subcategories.
All Coverage
1 original reportsThe Backstory
The history behind this eventUS CISA Sets Three-Day Patch Deadline for Highest-Risk Flaws as AI Threats Mount
The US Cybersecurity and Infrastructure Security Agency, or CISA, uses binding operational directives to standardize vulnerability handling across federal civilian executive branch agencies. As AI helps attackers analyze vulnerabilities and develop attack tools more quickly, the interval between disclosure and exploitation continues to shrink, making patching speed critical to the security of government systems and critical infrastructure.
CISA's newly issued BOD 26-04 directs federal agencies to prioritize vulnerability remediation according to risk, requiring the highest-risk flaws to be patched within three days of confirmation. The new framework sharply compresses the response window to help government defenses keep pace with AI-accelerated attacks and reduce the risk of vulnerabilities being exploited before they are patched.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →