1. Executive summary
Recorded Future has announced Automated Signature Creation, a new capability in its Attack Surface Intelligence (ASI) product that uses agentic AI processing to generate production-ready external-exposure detection signatures for newly surfaced vulnerabilities in as little as 31 minutes, replacing a previously manual Insikt Group signature-authoring workflow and increasing in-platform signature output tenfold. The announcement is framed against a compressed exploitation window: vendor-cited Gartner data showed discovery-to-exploitation dropping from 45 days to 15 days between 2010 and 2020, Recorded Future's own 2025 Malware and Vulnerability Trends report reported weaponization "within days of disclosure," and the vendor now assesses the window is measured in hours. The announcement references two concrete anchor events: the February 2025 Trimble Cityworks CVE-2025-0994 disclosure (CVSS 8.6 HIGH, CWE-502 deserialization of untrusted data, in CISA KEV since 2025-02-07, EPSS 31%), which was the last high-profile case handled by the manual signature process, and a reported incident in which OpenAI agents exploited a zero-day in Artifactory, tied to the Hugging Face incident. For EMEA financial services clients the bottom-line risk is procedural rather than a new vulnerability: manual vulnerability triage and exposure-validation cycles are now slower than adversary weaponization, and external attack surface validation cadence must be compressed accordingly. This is a vendor capability announcement and trend assessment, not a report of a new exploitable flaw or an in-the-wild campaign; no new IOCs, malware, or attributed actor are in scope.
2. Regulatory framing
No specific DORA/NIS2 article is directly engaged by this item. This is a vendor product announcement and threat-trend assessment; it discloses no incident at a client, no new vulnerability requiring patching, and no third-party failure. The general observation that vulnerability weaponization timelines are shortening would be true of virtually any security item and does not, on its own, trigger an incident-management, reporting, or testing obligation under the referenced articles. Clients already running external attack surface validation under DORA Art. 24 (digital operational resilience testing — general requirements) may treat the compressed weaponization window described here as an input to testing cadence, but that is a programme-design consideration, not an obligation triggered by a distinctive fact in this item.
3. Technical analysis & attack chain
This item is a vendor capability announcement and trend piece; there is no attack chain to reconstruct. The technical substance is as follows.
The capability. Automated Signature Creation is a function within Recorded Future's Attack Surface Intelligence (ASI). ASI continuously maps an organisation's external exposure, correlates newly surfaced vulnerabilities with real-world threat intelligence, and prioritises response. The new function automatically creates "signatures" — pieces of detection logic that let the Recorded Future Platform recognise a specific vulnerable or exposed condition across the organisation's assets in real time. Per the vendor, a signature is detection logic of the form "go ask this asset this exact question; if the answer looks like this, it's vulnerable" — the distinction between asset discovery ("we found your assets") and exploitability assessment ("we found the ones a threat actor can potentially break into"). Agentic processing turns a newly surfaced vulnerability into a deployable signature in as little as 31 minutes; the vendor describes the mechanism as a three-step early warning system (the source text provided is truncated at this point and does not enumerate the three steps — do not assume their content). In-platform signature volume has increased tenfold versus the prior expert-authored process.
The prior manual process, illustrated by CVE-2025-0994. The vendor's worked example is the February 2025 Trimble Cityworks vulnerability CVE-2025-0994 — CVSS 8.6 HIGH, CWE-502 (deserialization of untrusted data), added to CISA KEV on 2025-02-07, EPSS 31% at the time of the verified data. Under the manual workflow, the Insikt Group built a Nuclei template (distributed as a downloadable YAML file) specific to CVE-2025-0994, letting defenders test potentially vulnerable Trimble Cityworks instances running versions prior to the patched release, and used it alongside ASI's web-infrastructure scanning to identify internet-facing assets vulnerable to the CVE. This is the workflow the new automated capability replaces. Note the framing: the Nuclei template was a detection and prioritisation aid for patch targeting, not a patch or a workaround.
The trend claim. The vendor's supporting evidence for automation: (1) Gartner data cited in 2020 showing discovery-to-exploitation time dropping from 45 days to 15 days between 2010 and 2020; (2) Recorded Future's 2025 Malware and Vulnerability Trends report reporting weaponization "within days of disclosure"; (3) the vendor's current assessment that the window is measured in hours; (4) a new generation of AI models able to automatically find zero-day vulnerabilities in major operating systems and web browsers — a capability the vendor states was previously exclusive to advanced government cyber units and research labs; and (5) a recent report that OpenAI's own agents exploited a zero-day vulnerability in Artifactory, tied to the Hugging Face incident.
Confidence caveats. This entire item is single-sourced: it is a vendor blog post announcing the vendor's own product, so the capability claims (31-minute signature generation, tenfold volume increase, three-step process) are unverified marketing assertions from the vendor about its own platform — treat as single-sourced; verify before procurement or process decisions. The Artifactory/Hugging Face incident is referenced second-hand ("it was reported that") with no primary source, technical detail, CVE, or affected versions given in this material; the specific vulnerability, its exploitation mechanics, and the exact role of the OpenAI agents are unconfirmed here. The "window measured in hours" assessment is the vendor's own characterisation, not a corroborated metric. No threat actor is named or attributed anywhere in this material.
4. Mitigation & containment
There is no vulnerability to patch and no threat to contain from this item. The actionable output is process change, driven by the compressed weaponization window the vendor describes.
P1 — within 24h. Nothing to action within 24 hours. This is a trend/capability announcement, not an active threat. Do not treat it as an incident trigger.
P2 — within 72h.
- Review your current external attack surface validation cadence. If internet-facing assets are re-scanned on a weekly or longer cycle, that cadence is now slower than the weaponization window the vendor describes (hours). Identify the fastest feasible re-scan and exposure-validation interval for internet-facing estate, and confirm your process can ingest a new high-severity CVE and produce an "are we exposed, where" answer same-day.
- If you hold a Recorded Future/ASI licence, confirm with your account team whether Automated Signature Creation is enabled on your tenant and what the signature-to-alert path looks like in your existing integrations. The 31-minute figure and tenfold volume increase are vendor claims — validate actual turnaround on the next high-EPSS CVE in your environment.
- Confirm your vulnerability triage runbook has a defined path for KEV-listed CVEs (CISA KEV addition as a hard prioritisation trigger, as it was for CVE-2025-0994 on 2025-02-07) and for high-EPSS CVEs affecting internet-facing assets, independent of CVSS alone.
P3 — within 7 days.
- If you run Trimble Cityworks or did in early 2025, close out the CVE-2025-0994 action: confirm all instances are at or above the patched version and that no internet-facing instance remains. The verified data shows it in CISA KEV with EPSS 31% — if any unpatched instance exists, that is a live exposure regardless of this announcement.
- Assess whether your tooling can consume machine-generated detection logic (Nuclei templates or equivalent) at the pace the vendor describes, and whether your SOC has the capacity to act on a tenfold increase in exposure-signal volume. Signal volume without triage capacity is a risk in itself.
- For AI/ML supply-chain exposure: the referenced Artifactory/Hugging Face incident is a reminder that package/artifact registries in your build pipeline are attack surface. Verify artifact repository authentication and integrity controls (signed artifacts, allowed-lists) — but note the specifics of that incident are not in this source material; do not act on assumed details.
5. Indicators of compromise
No indicators of compromise available in the source material.
6. Detection
Insufficient indicators to author detection rules.
The source material contains no threat artefacts — no strings, command lines, file paths, registry keys, mutexes, or network indicators belonging to any malicious tool or activity. The only technical artefact mentioned is a defensive Nuclei YAML template authored by Insikt Group for CVE-2025-0994, which is a defender tool, not a threat artefact, and its content is not provided. Authoring a rule that greps for the CVE identifier, product names, or vendor phrases would detect reporting about the threat, not the threat.
CVE assessment
1 referenced CVE — 1 actively exploited (CISA KEV)
| CVE | CVSS | Exploited | EPSS | Summary |
|---|---|---|---|---|
| CVE-2025-0994 | 8.6 High | ⚠ KEV 2025-02-07 | 31% | Trimble Cityworks versions prior to 15.8.9 and Cityworks with office companion versions prior to 23.10 are vulnerable to a dese… |
7. Sources
- Recorded Future, "Recorded Future Announces Automated Signature Creation, Accelerating Vulnerability Prioritization," https://www.recordedfuture.com/blog/automated-signature-creation, 2026-09-04. (Primary and only direct source; single-sourced item.)
8. Adverse Trace position
This is a vendor capability announcement, not a vulnerability or campaign, and we assess it as low direct severity with genuine process relevance. The verified anchor fact — CVE-2025-0994, CVSS 8.6 HIGH, CWE-502, in CISA KEV since 2025-02-07, EPSS 31% — is a year-old, already-patchable Trimble Cityworks flaw; any client still running a pre-patch Cityworks instance has an exposure that predates and is independent of this announcement, and that should be closed out under P3 above. The substantive takeaway is the trend claim: weaponization windows compressed from days to hours, which argues for same-day exposure validation for KEV and high-EPSS CVEs against internet-facing estate. That claim, along with the 31-minute signature generation figure, the tenfold volume increase, and the Artifactory/Hugging Face incident reference, is single-sourced vendor material — the incident reference is second-hand with no primary source or technical detail provided — and should be verified before driving procurement or process change. No actor is named and no attribution is claimed anywhere in the material. We will monitor for independent corroboration of the Artifactory/Hugging Face incident, for the first independently observed turnaround times of automated signature generation on a live high-severity CVE, and for any client-side evidence that exposure-signal volume is outpacing SOC triage capacity.
Published via PulseTrace — Adverse Trace threat intelligence.