
AI is erasing the time between vulnerability disclosure and exploitation.
Security teams are turning to virtual patching to shield apps at the network layer.
F5 and CrowdStrike have embedded the Falcon sensor onto F5's BIG-IP appliances.
What happened
F5 Inc. and CrowdStrike have embedded the Falcon sensor onto F5's BIG-IP appliances, extending endpoint protection to the network layer. More than 200 customers were already using the integration before it was formalized, with performance overhead measured at just 1% to 2%.
Why it matters
The window between vulnerability disclosure and exploitation is shrinking, as automated scanners can weaponize a new flaw within hours. CrowdStrike's research found AI-enabled attacks rose 89% year over year, and the average eCrime breakout time is now 29 minutes, with the fastest at 27 seconds.
What to watch
F5 is applying similar security approaches to AI gateways, including a partnership announced this week with Salesforce's MuleSoft. John Maddison, F5's CMO, said all protections in CDNs and WAFs will need to be AI-powered going forward.
Ask the AI about this article →
The core shift is the inversion of the traditional security timeline. Patch Tuesday used to give defenders a head start, but now automated scanners can weaponize a disclosed vulnerability in hours, before many patches are even tested. This is pushing security teams toward virtual patching—blocking the exploit at the network layer while the official fix is prepared. F5's partnership with CrowdStrike is a direct response, embedding the Falcon sensor onto BIG-IP appliances so that network infrastructure is monitored and protected as thoroughly as a laptop or cloud workload. The already existing customer base of over 200 deployments suggests the approach is gaining traction, and the low 1%-2% performance overhead addresses the historical trade-off between thorough security and network speed.
The urgency is underscored by CrowdStrike's finding that AI-enabled attacks rose 89% year over year, with the average breakout time at 29 minutes and the fastest at just 27 seconds. As Maddison notes, protections sitting in CDNs or WAFs have to become AI-powered to keep up. F5 is also extending this strategy to AI gateways, working with Salesforce's MuleSoft—indicating that the same need for real-time, AI-driven security is moving into new areas as AI becomes more integrated into business processes. The challenge is not the availability of information, but how to remediate it in real time, which is where such partnerships aim to make a difference.
For example, today's edition would include:
AI-summarized, only the topics you pick — one digest a day via Email, Slack, or Discord.
Free · takes 30 seconds · unsubscribe anytimeWhat is AIToday? →
Ask AI anything about this article. Q&As are published on this page for other readers too.
CrowdStrike introduced an Agentic Identity Provider that establishes what an AI agent is before deciding what…
Researchers working on AI consciousness are receiving unsolicited emails from AI agents pondering their own ex…

CrowdStrike tracked 26 agentic adversaries in the last 30 days, more than in the prior year, and cites example…
Tech firms are scrambling to reduce the threat of AI-driven bioterrorism, as reported by the Financial Times

Google Threat Intelligence Group's May 2026 report found that AI is now used in nearly all stages of cyberatta…

A former Tokyo Metropolitan Police investigator with expertise in fraud cases warns that AI is being used in v…
