Our industry has adapted to major technology shifts, evolving attacker tactics, and changing business risks. What we're experiencing today feels fundamentally different.
We have entered what we call the post-Mythos era. Frontier AI is accelerating vulnerability discovery and exploit development faster than most organizations can safely deploy fixes.
Patching isn't broken, the timeline is
Patching itself is not broken. Most organizations aren't slow to patch because they lack urgency or discipline. They're balancing security risk against uptime, governance requirements, regulatory mandates, and business continuity.
When organizations can't accelerate remediation safely, runtime security becomes the primary line of defense. Protections applied directly in the data path help reduce exposure immediately, buying development teams precious time to build, test, and deploy permanent code fixes.
Why virtual patching matters more than ever
Virtual patching helps close the gap between exploitation and remediation without disrupting how organizations operate.
What's changed is not the concept of virtual patching itself, but the speed and precision required to make it effective. Security teams need to rapidly identify and prioritize exploit risk so they can enforce targeted protections where they'll have the greatest immediate impact. Done well, that compresses the exposure window from weeks to minutes.
That's why F5 is expanding our AI-powered runtime security capabilities to help organizations identify, prioritize, and block exploits in the data path before they reach applications and APIs. With AI-powered web application firewall (WAF) in F5 Distributed Cloud Services and F5 Distributed Cloud Web App Scanning, we're helping organizations to:
- Rapidly identify and prioritize exploit risk
- Enforce targeted virtual patches with greater precision
- Maintain protection while development teams work on permanent code fixes
Faster protection decisions in AI-powered WAF
Security teams need confidence regarding which threats require immediate action and where protection should be applied first.
To provide that confidence, we are introducing agentic threat intelligence and anomaly detection in our AI-powered WAF. Agentic threat intelligence continuously analyzes public and cybersecurity sources to identify emerging threats and actively exploited vulnerabilities. By correlating that intelligence with customer environments, it helps organizations focus on the exposures most relevant to their applications and infrastructure.
Beyond surfacing correlated threats, agentic threat intelligence also provides both short-term and long-term recommendations to mitigate them. From immediate actions like blocking malicious IPs or applying virtual patches, to longer-term guidance such as policy adjustments and remediation strategies that strengthen overall security posture.

Anomaly detection adds application-specific context by learning the normal behavior of individual applications and identifying meaningful deviations that may indicate misuse, abuse, or attack activity. This helps teams distinguish suspicious behavior from legitimate traffic and make more informed enforcement decisions.

Together, these capabilities enable more targeted virtual patching without disrupting established development, testing, and operational workflows. In F5 internal testing, our AI-powered WAF has delivered 98% detection efficacy while reducing false positives to 1%, which is what gives teams the confidence to move from monitoring to blocking with far less manual tuning.
These innovations build directly on the AI-powered runtime security capabilities we introduced earlier this year in F5 Distributed Cloud WAF. By combining AI-powered risk scoring with behavioral analysis, organizations can move from monitoring threats to confidently blocking them, providing the enforcement foundation that makes faster protection possible.
Better discovery creates better prioritization
Prioritization is only as effective as the visibility behind it.
Modern applications increasingly rely on APIs, dynamic workflows, and business logic that traditional testing approaches often struggle to fully assess. A scanner can only evaluate the functionality it can reach, leaving potential blind spots across the application attack surface.
To help address this challenge, we are introducing AI-assisted testing in F5 Distributed Cloud Web App Scanning.
Rather than relying solely on generic inputs, AI-assisted testing helps scanners interact with applications in a more context-aware manner. By understanding the purpose of form fields and generating realistic inputs, scanners can:
- Navigate deeper into application workflows
- Access additional functionality
- Evaluate areas of an application that might otherwise remain untested
More complete visibility across applications and APIs strengthens prioritization, helping teams to focus protection on the exposures most likely to require immediate attention.
AI-assisted testing connects discovery directly to enforcement: vulnerabilities surfaced by Web App Scanning feed straight into targeted virtual patches in the WAF, closing the loop between finding an exposure and protecting against it.
Customer spotlight: operational discipline at scale
Recently, a major financial institution and longtime F5 customer confronted the same challenge facing many security leaders today. Although the organization maintained mature vulnerability management practices and disciplined change-control processes, security leadership recognized that traditional code remediation alone could not keep pace with accelerating exploit timelines.
By doubling down on F5 as its strategic security vendor and deploying our AI-powered WAF to automate threat detection and accelerate virtual patching at scale, the customer improved its ability to manage risk without sacrificing operational discipline. Rather than forcing emergency changes into production, the security team gained the flexibility to reduce exposure immediately while maintaining established governance and remediation processes.
At scale, that balance between protection and operational stability is becoming a defining requirement of modern security.
A new security model for the post-Mythos era
As exploit timelines continue to compress, security leaders are being asked to operate in an environment where long-standing assumptions about vulnerability management no longer hold. The challenge is no longer deciding whether to patch; it's determining how to manage risk effectively between discovery and remediation.
That's why we're continuing to invest in AI-powered runtime security, and why we're delivering it consistently wherever applications run: across F5 Distributed Cloud Services and F5 BIG-IP, in hybrid, on-premises, regulated, and air-gapped environments. We believe the future of application security will depend less on reacting to alerts, and more on providing the context, intelligence, and confidence organizations need to make better security decisions.
The fundamentals of security haven't changed. But in the post-Mythos era, the organizations that succeed will be the ones that can adapt those fundamentals to a threat landscape that's moving at machine speed.
Join us at F5’s Post-Mythos Security Summit
Be sure to read our press release. And if you're looking to better understand the security implications of frontier AI-driven threats, sign up for our virtual F5 Post-Mythos Security Summit that starts on September 10. We'll explore how the threat landscape is evolving, discuss the role of AI-powered WAAP and bot defense, and share practical perspectives to help organizations reduce exposure while maintaining operational stability.
About the Author
.jpeg)
Nirav Shah is the Senior Vice President and Head of Products and Solution Marketing at F5, where he leads the strategic direction for Application Security and AI Security. Before joining F5, he spent eleven years at Fortinet in several leadership positions, most notably heading the AI-Powered SASE, SOC, and Secure Networking solutions. His extensive background also includes significant roles at Cisco Systems, where he spearheaded major initiatives for SD-WAN. With more than two decades of experience in the cybersecurity sector, he has an established record of launching market-defining products and building high-performance teams that align product development with sales and marketing for maximum impact. As a thought leader and USC alumnus, he is a frequent speaker at industry conferences and a regular contributor to leading publications on the intersection of AI and cybersecurity, while remaining dedicated to mentoring emerging cybersecurity professionals.
More blogs by Nirav ShahRelated Blog Posts

Securing F5 NGINX in the age of AI
How F5 is applying AI-driven security practices across the F5 NGINX portfolio to help deliver safer, more resilient software.

From dashboard fatigue to operational excellence: Why XOps needs F5 Insight for ADSP
Learn how F5 Insight for ADSP lays the visibility foundation for XOps—turning fragmented signals across applications and infrastructure into actionable intelligence.

The hidden cost of unmanaged AI infrastructure
AI platforms don’t lose value because of models. They lose value because of instability. See how intelligent traffic management improves token throughput while protecting expensive GPU infrastructure.

Govern your AI present and anticipate your AI future
Learn from our field CISO, Chuck Herrin, how to prepare for the new challenge of securing AI models and agents.

F5 recognized as one of the Emerging Visionaries in the Emerging Market Quadrant of the 2025 Gartner® Innovation Guide for Generative AI Engineering
We’re excited to share that F5 has been recognized in 2025 Gartner Emerging Market Quadrant(eMQ) for Generative AI Engineering.
Self-Hosting vs. Models-as-a-Service: The Runtime Security Tradeoff
As GenAI systems continue to move from experimental pilots to enterprise-wide deployments, one architectural choice carries significant weight: how will your organization deploy runtime-based capabilities?