SPEAKER

Jean-Christophe Praud (Senior cybersecurity consultant - Synerio Consuting for OCSIN (IT Department of the State of Geneva))

Presentation in preparation...


Welcome to the ISC2 Suisse Romande Chapter!

09/30/2026 | 11h15 -> 12h30 | Room G

The ISC2 Suisse Romande Meetup is the premier networking and knowledge-sharing event for cybersecurity professionals across French-speaking Switzerland. It is a dynamic space where experts, engineers, and enthusiasts don't simply attend they actively shape the conversation.

Session : The Mythos Effect: impact of AIs on vulnerability management

Vunerabilities referenced by CVEs have existed since 1988, with numbers slowly rising until 2017, after which the pace accelerated due to increased attacker interest and vendor bug bounty programs. Since 2022, generative AI has significantly impacted IT security, both offensively and defensively. Notable models include Anthropic's limited-release Claude Mythos (deemed "too dangerous" for public use), closed models like Claude Fable 5 and GPT-5.6, and open-source models such as Qwen 3.8, GLM 5.3, Kimi K3, Gemma 4, Meta Muse Glimmer, and Nvidia Nemotron 3.5.

When combined with agent-based harnesses, these AI systems are highly effective at discovering and exploiting CVEs. Consequently, CVE growth has become exponential, and the Time To Exploit (TTE), the interval between vulnerability discovery and real-world attack, has plummeted from 756 days in 2018 to just 5 days in 2023, and is now negative, meaning exploits often occur before CVEs are published or patches are available.

Traditional patching cycles (e.g., monthly "Tuesday patches") are no longer sufficient. The IT industry must adopt new vulnerability management strategies, where generative AI and agents can also play a defensive role.

This session offers an insider's perspective on the ISC2 ecosystem and see how its global chapters drive local impact.

 

Register