The race to patch software vulnerabilities before zero-day cyber-exploitations proliferate
Highly capable frontier AI models can now detect previously unknown vulnerabilities in software and operational hardware at massive scale. As a result, state-grade cyber capabilities will become increasingly accessible to actors with malicious intent such as ransomware operators motivated by profit, terrorists or hacktivists with no goal but destruction. Unfortunately, it’s taking longer to patch vulnerabilities just as attacker time to exploit is falling; the average time between disclosure of a vulnerability and its first exploitation has now fallen to zero days. In May 2026, Anthropic reported that of 530 high and critical vulnerabilities reported to maintainers, only 75 had been patched. Even when patches exist, companies often don’t respond in time: in ~60% of breaches, a patch was already available at the time of compromise.
I partnered with JP Morgan’s Cybersecurity Teams to get into the details on this critical national security issue. In “Patchmageddon” we review how cyber risks have changed, the underappreciated breadth and risks from open source code, the risks to physical infrastructure and some guidance what business owners, software developers and the Federal government should be doing to mitigate the potential consequences.
Watch the Podcast
Click here for important information.
About Eye on the Market
Since 2005, Michael has been the author of Eye On The Market, covering a wide range of topics across the Markets, investments, economics, politics, energy, municipal finance and more.