Xage Expands Zero Trust Protection as AI Speeds Up Vulnerability Exploitation
- 59 minutes ago
- 2 min read
Artificial intelligence is shrinking the time security teams have to defend vulnerable systems, prompting Xage Security to expand its Critical Asset Protection technology beyond industrial environments and into cloud services, business applications, AI systems and other digital infrastructure.
The Palo Alto-based cybersecurity company said its platform will now protect both traditional critical assets and rapidly changing digital resources, including ephemeral cloud workloads, machine identities and autonomous AI agents.
The expansion reflects a widening gap between how quickly attackers can exploit software flaws and how quickly enterprises can safely test and deploy patches. Threat actors are increasingly using AI to automate vulnerability discovery, reconnaissance and exploit development, potentially allowing attacks to begin soon after a weakness becomes public.
At the same time, enterprise attack surfaces are becoming more complex. Organizations are deploying AI agents, interconnected applications and temporary cloud resources that may appear, scale or disappear faster than traditional network security policies can accommodate.
Xage’s approach combines identity-based microsegmentation with access controls that govern interactions between users, machines and protected assets. The platform can conceal resources from unauthorized scanning, broker connections and restrict communications to approved identities and actions.
Unlike conventional network segmentation, the system is designed to apply policies without requiring companies to rebuild their underlying architecture or create large numbers of firewall rules. Access can be granted just in time and adjusted as workloads, identities and operational requirements change.
“Organizations need to assume that any asset could contain an exploitable weakness and prevent attackers from reaching or interacting with it in unauthorized ways,” said Duncan Greatwood, CEO at Xage Security. “The security industry has spent decades trying to eliminate vulnerabilities faster than adversaries can exploit them. AI makes that race increasingly unwinnable. The next era of cybersecurity will be defined by controlling exposure. That means governing every interaction with and between assets, so that a vulnerability does not automatically become a path to compromise.”
The strategy is intended to reduce reliance on patching and threat detection as the first line of defense. Patching remains essential, but updates may require testing, downtime, vendor assistance or specialized expertise. Detection systems can also respond only after suspicious activity has begun.
Xage is instead positioning exposure control as a preemptive security layer. By blocking unauthorized discovery and limiting lateral movement, the company argues that organizations can reduce the likelihood that an unpatched vulnerability becomes a full-scale breach.
The expanded platform also addresses a newer concern: attackers using AI systems to target legitimate enterprise AI infrastructure. As AI agents gain access to sensitive data and operational tools, controlling machine-to-machine activity could become a central requirement for enterprise Zero Trust security.


