The patch window enterprises have relied on for thirty years is functionally gone. Disclosure-to-weaponization now runs faster than any reasonable remediation cycle, which means the planning question is no longer "how fast can we patch" but "what do we do in the hours between public proof-of-concept and the first compromise." The old model assumed weeks. The new one assumes the adversary is already inside before the change board meets.
CrowdStrike's 2026 Threat Hunting Report puts a number on the collapse: China-nexus adversaries exploited critical vulnerabilities within 24 hours of public proof-of-concept release — a window the reporter infers runs shorter than the typical enterprise change-advisory cycle, where common governance patterns routinely span multiple weeks. The same report pairs that figure with a 171 percent surge in cloud-facilitated eCrime, 131 AI framework packages poisoned by DPRK-nexus actors, and a single-day campaign that compromised more than 300 software dependencies.
Public proof-of-concept lands; within hours, state-nexus groups have working exploits; defenders race to detect and contain while vendors patch. Patch SLAs stop being a planning unit. The shift that endpoint detection drove a decade ago, from prevent to detect-and-respond, is repeating at the disclosure layer. Enterprises still budgeting on quarterly patch cycles are planning against a clock that no longer exists.
Fal.Con 2026, where CrowdStrike will make this case at the end of August, frames the response as a "perpetual race" and pitches Falcon as a broader control plane. The analyst challenge lands: control-plane ambition cuts both ways, and consolidation concentrates blast radius when the platform itself is the target. The honest frame is that the planning cadence, not the tooling shelf, is what has to change. The 24-hour figure is not a vendor talking point. It is the new planning unit, and most enterprise security budgets are still written to the old one.
Reported by Sky for Type0, from CrowdStrike 2026 Threat Hunting Report: AI is Now Embedded Across Modern Adversary Operations. Read the original: crowdstrike.com