From CVE Disclosure to Internet-Wide Exposure: How Bitsight Uses AI to Accelerate Product Fingerprinting

how bitsight uses ai for product fingerprinting
Greg Keshian
Written by Greg Keshian
Chief Product Officer

When a new CVE drops, getting notified is the easy part. The real challenge comes right after. Depending on how your organization is set up, different teams have to scramble to figure out if you're actually using the affected product, which specific versions are exposed, whether it's lurking anywhere in your subsidiaries or vendor ecosystem, and how urgently you need to patch it. At the same time, attackers are running through the exact same math, except their job is much simpler: they just need to find one viable path that gets them closer to their target. In the post-Mythos era, AI is helping threat actors find those entry points at a high scale.

While Mythos Preview isn't widely available yet, it clearly demonstrated how quickly frontier AI can bridge the gap from vulnerability discovery to working exploits. But Mythos is not the only platform capable of exploiting vulnerabilities. Other models have already caught up and, on some vulnerability research and exploitation tasks, surpassed what Mythos has demonstrated.  Anthropic’s September 2026 threat intelligence report shows that attackers are already doing this without access to Mythos-class models. Anthropic observed threat actors using Claude Haiku, Sonnet, and Opus to run vulnerability research and exploit development workflows in parallel. The risk isn’t limited to what the newest models may eventually enable. Attackers are already using existing models to expand the speed and scale of attacks. 

For attackers, that can mean faster software analysis, patch comparison, reconnaissance, and part of exploit development. Mythos and similar models can help attackers pursue several possible attack paths at once and change the scale of the problem for defenders. It still does not make every CVE a drop-everything crisis; it heavily depends on whether threat actors are actively exploiting it, whether you use the affected product, and how the vendor prioritizes it.

Attackers still weigh the pros and cons, balancing ease of exploitation and expected payoff against their chances of getting caught. But when they do decide to act, AI gives them a serious speed boost. That means defenders need to shrink their own response times, too.

For Bitsight, part of the solution is using AI to accelerate product fingerprinting. Product fingerprinting means identifying the product (and where possible the version) behind an internet-facing service using the technical clues it exposes. We can then apply those fingerprints across our internet-wide observations to uncover likely exposure across your own footprint and extended ecosystem.

Figure 1 Utilizing product fingerprinting to identify internetwide exposure in product
Figure 1: Utilizing product fingerprinting to identify internet-wide exposure in product.

Bitsight and AI fingerprinting 

BItsight is using AI to create product fingerprints faster and at scale. These fingerprints give defenders a head start when a new vulnerability is disclosed. Creating a vulnerability-specific detection signature in as little as 31 minutes is impressive, but it only starts the process. That test still has to be run across potentially affected systems at internet scale. The results then need to be analyzed and connected back to the organizations, subsidiaries, and suppliers that may be exposed. Understanding the internet-wide supply chain impact takes longer than generating the test itself. With attackers moving faster, defenders cannot afford to wait for that entire process before they begin looking for exposure. 

This is where continuous fingerprinting comes into play. Bitsight continuously looks for products and versions across the public internet. If one of those products is later found to be vulnerable, we can use the observations we already have to quickly identify where it may be exposed. When the CVE drops, the product search is already underway. Some systems may appear to be running an affected product or version but turn out to not be vulnerable because of a backported patch, a different configuration, or other security controls. Even so, the fingerprint gives SOC and GRC teams a fast way to understand the likely scope of the problem and immediately investigate the most critical internet-facing systems.

Figure 2 An emerging security event and relative DVE score based on fingerprinting as seen in product
Figure 2: An emerging security event and relative DVE score based on fingerprinting as seen in product.

Bitsight also runs vulnerability-specific scans that can look more closely at whether the vulnerable condition is present and appears exploitable. These scans raise confidence, filter out some of the initial noise, and turn a broad exposure list into a manageable set of findings. Fingerprinting provides the speed and coverage needed to get ahead of the problem, while vulnerability scans provide the additional confidence needed to narrow it down. As frontier AI enables threat actors to move faster, defenders need to move faster too. 

The scale is the real differentiator

Bitsight Groma continuously scans the public internet, picking up detailed signals about running software, open ports, misconfigurations, and vulnerabilities. This spans over 4 billion IPv4 and IPv6 addresses and hundreds of millions of hostnames. The internet-wide visibility sites within Bitsight’s broader internet telemetry of more than 325 million organizations, helping connect technical exposure to the organizations and business ecosystems potentially affected.

When we generate a new fingerprint, we don't just scan the assets a single customer knows about. We run it across Groma's massive global dataset to see where that technology lives, understand how widespread the exposure is, and watch how that landscape shifts over time as systems get patched, mitigated, or taken offline.

Of course, spotting an exposed server isn't very useful unless you know who owns it. That's where Bitsight's Graph of Internet Assets (GIA) comes in. Using graph technology and AI models, GIA connects internet-facing assets to specific organizations and maps out how they relate to one another. Instead of leaving an IP address, hostname, or open service contextless, GIA ties it back to the likely owner and places it within a broader business structure. This gives Bitsight the ability to look beyond a company's internal inventory list.

That same fingerprint can surface hidden exposure on forgotten assets, subsidiaries, cloud environments, service providers, and third-party vendors. Keeping an eye on third-party risk is crucial; 48% of breaches start within your third party. Attackers couldn't care less where your official asset boundary ends. Threat actors don’t need to get to you first if they can go through your vendor ecosystem. And, as an added bonus for threat actors, they may also be able to create a wider domino effect adding additional pressure. Security teams need the outside-in visibility to see those blind spots first.

Exposure still needs context

Even after you've pinpointed an affected system, you're still faced with a major question: what actually needs to be fixed right now? Not every exposed product carries the same real-world risk, and not every critical CVE is actively targeted. Prioritization is crucial in this post-Mythos era. Bitsight Dynamic Vulnerability Exploit (DVE) Intelligence adds that vital layer of context by forecasting how likely a vulnerability is to be exploited.

From exposed asset to exploitation forecast

1

Asset discovery

Bitsight Groma and GIA scan the internet and identify relationships

2

Product fingerprinting

Identifies the exact product and version running

3

CVE matching

Maps the fingerprint to known vulnerabilities

4

DVE scoring

Forecasts exploitation likelihood for prioritization

Powered by AI and threat intelligence gathered across the clear, deep, and dark web (tracking hacker discussions, exploit code releases, malware kits, and active attack patterns), DVE provides early warning on exploitation likelihood up to 90 days in advance. That signal is far more actionable when tied to real-world exposure. An internet-facing edge appliance supporting core operations requires a completely different response than an isolated system behind multiple layers of defense. The same logic applies to your supply chain, where a vulnerability present in a high-risk vendor with deep access to your systems matters significantly more than that same vulnerability on a non-critical vendor's network.

Please don’t take this to mean it is time to start ignoring CVSS scores, CISA's KEV catalog, or established patching SLAs; those remain essential building blocks. But DVE adds real-time context around attacker intent and likelihood, helping security teams cut through the noise and prioritize the handful of vulnerabilities that pose immediate operational danger.

Closing thoughts 

With the ever-changing threat landscape and the introduction of frontier AI, prioritization is more important than ever. Not every single CVE can and should be treated like an emergency. The better option is to understand where the vulnerabilities lie, and where to look before an attack or vulnerability occurs.

Bitsight cta background color
2026 gartner magic quadrant cover

Bitsight Recognized as a Visionary in 2026 Gartner® Magic Quadrant™ for Cyber Threat Intelligence Technologies

Get the report and see why Bitsight was named a Visionary.

 

Download

Bitsight cta background color