TAMPA — The lowly software patch has become a big headache and growing operational problem for Pentagon and defense industry networks due to the explosion of cyberattacks driven by artificial intelligence, a topic that dominated the Defense Intelligence Agency’s DODIIS show this week.

Multiple speakers here noted that vulnerabilities are being discovered and exploited faster, vendors are issuing fixes at an unprecedented rate and government networks cannot simply be taken offline every time software needs to be updated.

Roger Greenwell, CIO of the Defense Information Systems Agency, described a cycle that is putting a heavy burden on those responsible for patching.

“What keeps me up at night is recognizing that our adversaries are using these capabilities to look for inherent vulnerabilities within our software, within industry software, within common software,” he said. “The speed at which we need to be able to patch [is] working our people very hard these days.

“All of these vendors are out there looking in depth at their code, discovering vulnerabilities, coming out with patches at a rate that we’ve never seen before,” Greenwell said. “How do you make sure that you actually are getting those patches applied to everything? How are you taking care of your workforce who is working rapidly to do this trying to stay ahead of the game.”