The Clock Is Ticking Faster Than Your Scanner: A First Look at Emerging Exposures

AI changed how fast vulnerabilities are found. Join JupiterOne and VulnCheck for a fireside chat on what that breaks and what it takes to keep up.

Chief Product Officer

Kevin Tonkin

Director of Product Management

Chad Richts

Cybersecurity and Vulnerability Researcher

Pat Garrity

Date

September 22, 2026

Time

12pm EST

Type

Virtual event

Vulnerability management has always been a volume problem. What's different now is the rate of change. Autonomous, AI-driven discovery tools can find and validate exploitable weaknesses at a pace no scanner-and-patch cycle was built to absorb and the gap between "a vulnerability exists" and "it's being weaponized" has compressed from weeks to hours for the ones that matter most.

This is a fireside chat, not a scripted demo. JupiterOne's Kevin Tonkin and Chad Richts sit down with Pat Garrity of VulnCheck — a threat intelligence firm tracking exploitation activity in the wild — to talk through that shift from two different vantage points: what the attack-surface side sees, and what the threat-intelligence side sees. The conversation is built around four questions, not a slide deck, and both companies' early work shows up as evidence for the conversation, not the point of it.

This session is for CISOs and security leaders who need to explain to their board why the old patch-and-pray model can't keep pace with AI-accelerated threats; security architects and engineers running Tenable, Qualys, Rapid7, or similar scanners who are tired of prioritizing by CVSS score alone; vulnerability management leads under increasingly aggressive remediation SLAs; and anyone evaluating risk-based vulnerability management or exposure management platforms as the category shifts.

What We'll Cover

In this fireside chat, we'll get into:

The Speed Shift

What vulnerability discovery looked like when it depended on human researchers and scanner fingerprinting, and what it looks like now that AI models can autonomously find, validate, and in some cases generate working exploits for previously unknown weaknesses — from both the threat-intelligence and attack-surface vantage points.

What this breaks in vulnerability management

Patch cycles measured in weeks, CVSS-first prioritization, and remediation workflows built for a trickle of findings all assumed a slower world. We get into exactly where that model fails once discovery outpaces remediation capacity.

A workable scenario

What it would actually take for a security team to reasonably absorb this volume — a continuously current view of your attack surface, threat signal matched to it instead of a generic feed, risk context that accounts for what's already mitigated, and workflows that act on high-confidence signal without a human triaging every finding.

Where the industry needs to go

An honest, two-company read on what the vulnerability management and exposure management market needs to build toward — and where the current generation of tools, JupiterOne and VulnCheck included, still falls short.

Who should attend

CISOs and security leaders. You're the one who has to explain to the board why a patch-and-pray cycle built for a slower era can't keep pace with AI-accelerated vulnerability discovery. This conversation gives you a grounded, vendor-neutral read on what's actually changed and what a credible response looks like.

Security architects and engineers. If you're running Tenable, Qualys, Rapid7, or a similar scanner and you're tired of prioritizing by CVSS score alone, this is the session that gets into what a smarter, context-aware alternative actually requires, and how close the tooling is to delivering it.

Vulnerability management leads. Remediation SLAs keep tightening while the volume of findings keeps climbing. We'll talk through what it takes to defend your prioritization calls once there's no realistic way to fix everything at once.

Platform evaluators. Whether you're comparing risk-based vulnerability management tools or rethinking your approach to exposure management altogether, this fireside chat lays out where the category is headed and what to actually look for.

Want a walkthrough scoped to your own environment?

A 30-minute demo with our team, mapped to your stack, no prep required