Alon Noy, Co-Founder and CEO of Astelia
Opinion

I ran Israel's national red team. Now every attacker has one

AI makes cyberattacks faster and cheaper, leaving network reachability as the only thing between attackers and their targets. Most defenders still overlook it.

During the years I led Israel's National Red Team, we broke into some of the hardest targets in the world before a real adversary could. The exploits were the expensive part. Building one that worked against a specific target took a team of specialists months, and reaching anything that mattered often meant chaining several together.
AI models like Mythos ended that expense. The gap between a disclosure and a working exploit has fallen from 2.3 years to under 20 hours, and the capabilities my team spent years assembling are now something an attacker can rent.
That breaks the two filters most programs run on. Ranking by risk of exploitability worked while exploits were scarce; once a model can write one for almost any vulnerability on-demand, the answer converges on yes, and a filter that returns yes for everything ranks nothing. Patch cycles fail differently. A 30-day SLA was a bet that the attacker needed longer than that to build something usable, and at 20 hours the bet is lost before the ticket is assigned. Patching speed is governed by change control and maintenance windows, and those did not get faster when the exploit did.
Reachability is the filter that survives. The process still has to be running, the port still has to be open, and a route has to exist from wherever the attacker actually stands. No model generates that from the outside. It comes out of your own network topology, and every attack path my team ever used was based on it. In the field, that often meant building our own map of the environment from incomplete information and finding the paths that diagrams and documentation did not show.
Over the past decade, much of the security industry's attention shifted to cloud, identity and now AI. Network reachability was often overlooked, but it never ceased to be the most important factor in exposure management. Large organizations still run complex environments shaped by firewalls, routers, load balancers, segmentation rules, exceptions and years of accumulated decisions. Attackers still have to move through that reality, and many of the paths that matter are hidden there.
That distinction becomes more important as AI lowers the cost of offensive work. If exploit generation gets faster while defenders continue treating every finding as an independent ticket, automation can simply accelerate the wrong workflow. Security teams will process more alerts without necessarily reducing the paths an attacker can actually use.
The better shift is to change the unit of work from the vulnerability to the attack path. At Astelia, we saw this clearly in one enterprise environment with nearly 3,000,000 vulnerability alerts. Once the customer’s actual topology, segmentation and security controls were taken into account, roughly 30 were found reachable and demanded immediate action. Reachability is inherently environment-specific. That is precisely the point.
Once the path becomes the unit of work, remediation changes too. Patching remains essential, but it is not always the fastest or even an available option. A vendor may not have released a patch yet. A production system may be too sensitive to update immediately. Legacy and end-of-life systems may have no patch coming at all. If the objective is defined only as “patch the vulnerability,” the defender can be left waiting while the exposure remains open.
If the objective is “close the attack path,” there are more options. A segmentation change can remove reachability. An access-control change can break the chain. A configuration change or compensating control can prevent exploitation even when the vulnerable software remains in place.
On the Red Team, we never cared about the number or score of vulnerabilities. We looked for the reachable few that could get us to our target. AI has changed what attackers can build. It has not changed the paths they have to cross.

Alon Noy (Neuhaus) is Co-Founder and CEO of Astelia