Skip to content

Security1 publisher2 min readPublished

Automox drafts endpoint mitigations with AI for the flaws that have no patch yet

The launch rests on a count of 973 CVEs in one Patch Tuesday, published with no vendor breakdown and no exploitation data, and on a pipeline that has AI write the configuration change a human then tests.

The Watch · Security desk

What happened

  • Automox announced an AI-speed Mitigation Worklet Pipeline aimed at vulnerabilities that cannot be patched immediately, with the Worklets available now to customers who have Worklet Catalog access.
  • The company says this week's Patch Tuesday release shipped 973 CVEs, which it calls the largest on record, and it uses that figure as the evidence that AI-assisted research is finding more flaws.
  • The pipeline evaluates each unpatchable vulnerability, drafts a Worklet with AI, and aims to have the mitigation in the catalog within hours of the disclosure.
  • Published Worklets are searchable by CVE or by Mitigations category, and customers decide which ones to run, which endpoints to target, and at what time.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • contradiction The announcement's headline treats these flaws as unpatchable while its body says they are not immediately patchable, so a buyer cannot tell whether a Worklet is a permanent control or a workaround that has to be reversed once the vendor patch lands.
  • exposure An AI-drafted configuration change can run across every endpoint in scope, which puts the vendor's own review and testing in the position of the only gate on the script's content; the customer controls targeting and timing.
  • constraint With no per-CVE coverage figure published, a prospective buyer has no way to check how much of any given Patch Tuesday the catalog actually reaches before committing.

The 973 count comes from Automox, and the announcement carries no vendor breakdown, no figure for how many of the flaws are remotely exploitable, and no figure for how many have public exploit code [16]. It also does not say how many of them have no patch, which is the subset a mitigation catalog exists to cover [16]. The wider proposition, that AI-assisted research now finds faster than vendors ship fixes, rests here on that one number and on the chief executive's assertion [2][11]. No independent count, CNA tally, or exploitation data appears in the release [20].

The announcement's headline says the Worklets cut endpoint exposure to unpatchable flaws [17]. Its body says most frontier-model vulnerabilities are not immediately patchable, which is why mitigation has become the lever [6]. Those are two different jobs. A permanent configuration change stays in place; a temporary workaround has to come back off when the vendor ships the fix. The release does not define what a frontier-model vulnerability is [21].

A Worklet is an automation that takes verifiable action on an endpoint, whether enforcing a configuration, installing software, or mitigating a vulnerability [4]. Automox says Worklets have run across billions of policy runs and millions of endpoints since 2019 [5].

"AI is increasing the speed of vulnerability discovery and exploitation, and Automox Mitigation Worklets are designed to close that gap," said Justin Talerico, CEO of Automox [11]. He put the sequence this way: "AI tooling analyzes the disclosure and generates a fix within minutes or hours. Automox then reviews and tests before release." [12] The quality and security checks, including human review and testing, come before anything reaches the catalog or a customer [8].

Automox puts the old disclosure-to-mitigation gap at days or weeks and the new one at minutes or hours [3]. Read weeks as two and hours as a full day: the old figure spans 24 to 336 hours, the new one tops out at 24, so the claimed saving runs from about fourteenfold at one end to nothing at the other [19].

For a responder the part that survives an audit is the evidence trail. Automox says the Activity Log and Policy Results show that a mitigation actually executed [10], and a feature called FixNow covers the urgent case with immediate evaluation and remediation [15]. Mitigation Worklets are available now to customers with Worklet Catalog access [14].

What to watch

  • An independent, vendor-by-vendor count of the same Patch Tuesday release, which would confirm or shrink the 973 figure.
  • Whether the catalog carries Worklets for the specific CVEs from that release that shipped without a fix, and how many hours behind disclosure they appeared.
  • The first AI-drafted Worklet that breaks a production configuration, and whether Automox's review or the customer's own change control caught it.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories