"Airgaps include scanning removable media for viruses, and not allowing autorun facilities."

How does even an up to date and uncompromised virus scanner detect a previously unpublicised exploit method ?

How does trying to disable autorun prevent e.g. the kind of "specially crafted JPEG(or whatever) may cause unauthorised code execution" vuln which has been happening in commodity OSes for decades?

Suggestions welcome.

