< ciso
brief />
Tag Banner

All news with #vulnerability management tag

290 articles

Configuring an AI vulnerability harness steering file

🔒 This post explains how a steering file configures an AI model to perform structured, evidence-based vulnerability triage with the consistency of an experienced analyst. It outlines five configuration sections that enforce structural verification, evidence-based scoring, infrastructure-aware prioritization, and threat-intel boosts. The steering file encodes team methodology so the model applies it uniformly across analyses and reduces hallucinations and false positives.
read more →

Three-Layer AI Vulnerability Harness for Scanners

🔍 This post explains a three-layer pipeline that filters raw scanner findings into a prioritized, evidence-backed set of vulnerabilities for engineers to act on. It emphasizes a tool-agnostic architecture combining multi-scanner agreement, AST-based structural verification, and deployment-context checks (IaC) to reduce noise and increase confidence. The article describes context scoping for AI reasoning and notes a companion post that covers the steering file controlling model behavior.
read more →

Three Lessons from Frontier AI Vulnerability Research

🔍 Microsoft Security’s FORGE Lab advances AI-native vulnerability research across Windows and open-source projects, emphasizing autonomy, defense through offense, and ecosystem-focused outcomes. From May to September 2026, FORGE reported 140 Windows CVEs and 155 validated reports across 23 open-source projects, including the Linux kernel. The post argues that discovery scale shifts the bottleneck from model intelligence to reproducible validation, remediation, and integration with engineering and servicing workflows.
read more →

AI Forces Continuous Offensive Security Practices

🔐 As AI-enabled attacks scale and accelerate, CISOs face a surge in exploitable vulnerabilities and must rethink vulnerability management. Experts argue that annual compliance pen tests are no longer sufficient; organizations need continuous, automated offensive security—pen testing, red teaming, and attack path validation—to prove exploitability in production. Human expertise remains critical to guide AI tools and develop future offensive security talent.
read more →

Anthropic Expands Claude Access for Cyber Defenders

🔒 Anthropic is expanding a program that lets vetted cybersecurity professionals test advanced AI models with reduced safeguards, reporting Project Glasswing uncovered at least 129,000 verified vulnerabilities between April and July 2026 and another 5,500 through open-source scans through October. The new Cyber Verification Program (CVP) offers three tiers—Defense, Red Team, and Specialized Access—providing graduated model access including Claude Opus 5.5 and Claude Mythos 5.1. Anthropic says these capabilities will help defenders while acknowledging dual-use risks and uneven exploitability of discovered flaws.
read more →

CISO Views: Managing Vulnerability Risks in AI Age

🔐 This article outlines how frontier AI is changing vulnerability management by producing vastly greater volumes of findings and shifting the CISO challenge from speed to scale and accuracy. It describes Microsoft’s use of AI-powered scanning, harness layers like MDASH, and Red Teaming to find and mitigate flaws, while urging defense-in-depth and Secure by Default controls such as Microsoft Baseline Security Mode (BSM). The post emphasizes coordinated open-source scanning, risk-based decision making, and rolling out secure defaults to reduce exploitation risk.
read more →

Red Hat's Lightwell Remediates 400+ Java Vulnerabilities

🔒 Red Hat's open-source security initiative Lightwell has remediated over 400 novel vulnerabilities across core Java libraries since launching in June. The company announced the general availability of the Lightwell Clearinghouse after a pilot phase, aiming to validate AI-generated reports and reduce noise for maintainers. Backed by IBM and supported by major financial institutions, Lightwell offers continuous signed binaries, SBOMs and a premium clearinghouse for targeted backports to production systems.
read more →

Google pause spotlights AI-driven triage challenge

🔍 Google paused certain bug bounty submissions after a surge of largely automated, low-quality reports stretched its validation capacity. The company had already tightened rules and raised evidence requirements to reduce false positives, but high volumes of AI-generated findings continue to challenge triage workflows. Experts warn that unchecked report floods can waste engineering time and that organizations should treat triage as a security capability, requiring reproducible evidence and reachability checks. AI can discover real vulnerabilities but also produces plausible, costly false leads that must be filtered before remediation.
read more →

AI-driven surge in n-day exploits outpaces zero-day

🔍 Google’s Threat Intelligence Group reports attackers are increasingly weaponizing disclosed flaws, with AI accelerating exploit development. GTIG recorded 141 exploited CVEs between January and August 2026 versus 127 in all of 2025, while monthly disclosures doubled. High-risk exploits and time-to-exploit have risen, and perimeter appliances remain prime targets. Organizations must adopt threat-driven triage and automated remediation to manage the growing volume.
read more →

AWS Continuum Raises Bar for Autonomous Code Security

🔒 AWS reports that Continuum for code vulnerabilities achieved an 89.0% end-to-end pass rate on the CyberGym-E2E benchmark, passing 819 of 920 tasks within a 90-minute limit. The multi-agent system improved on prior public results across all measured stages (discovery, validation, remediation) and reached 93.7% when allowed to run longer. The evaluation was conducted under network-isolation and submission-review rules to ensure results came from analysis rather than retrieval.
read more →

EU Cyber Resilience Act reshapes vendor security baseline

🔒 The EU Cyber Resilience Act mandates 24-hour reporting for actively exploited vulnerabilities and severe incidents affecting products with digital elements, creating an EU-wide product-security law that applies even to non-EU companies. Experts warn the requirement effectively ends manual vulnerability triage, forcing vendors to automate linkage between SIEMs, SBOMs, KEV alerts, asset inventories, and other telemetry. The regulation is expected to elevate secure-by-design practices, test operational resilience, and reshape global technology markets much like GDPR did for data protection.
read more →

ThreatsDay: AI‑Fueled Zero‑Day Chains Rise

🛡️ This ThreatsDay bulletin surveys a week of practical attack paths where ordinary components—caches, model inspection, compilers, and public secrets—become exploitable. It highlights criminal campaigns from Tren de Aragua ATM jackpotting to blockchain dead drops, new EDR evasion and cache poisoning techniques, model inspection code execution, and AI‑enabled automation that accelerates vulnerability discovery. The report stresses that modest assumptions about what is "ordinary" are driving many compromises.
read more →

Why scanners alone can’t secure modern infrastructure

🔍 Kaspersky’s analysis shows a sharp rise in detected vulnerabilities and a shrinking window between disclosure and exploitation, fueled in part by AI. Relying solely on periodic scanners creates gaps: findings pile up, prioritization is often manual and inconsistent, patches are delayed or incompletely applied, and assets can remain untracked. The article advocates four core processes—asset inventory, contextualized vulnerability analysis, risk-based prioritization, configuration hygiene, and post-patch verification—and highlights the Kaspersky Vulnerability Management module as a solution to centralize and operationalize these steps.
read more →

AWS Security Hub adds remediation plans to prioritize fixes

🔒 AWS Security Hub now groups related exposure findings into remediation plans that target shared root causes. Each plan provides prioritization (Critical, High, Medium, Low), impact assessment, and step-by-step remediation instructions with examples for AWS CLI, Terraform, CloudFormation, Python, and CDK. Security Hub automatically ranks plans by potential risk reduction so teams can focus on the most impactful fixes, and AI agents can consume the plans via API to automate remediation. Remediation plans are available in all Regions where Security Hub is offered and included at no extra cost under the AWS Security Hub Essentials plan.
read more →

Vulnerability Discovery and Exploitation Trends in AI Era

🔍 Google Threat Intelligence Group analyzes CVE disclosure and exploitation data from January 2025 through August 2026 to assess AI's impact on vulnerability trends. The report finds that disclosures and in-the-wild exploitations roughly doubled in 2026, AI-facilitated discovery surfaces proportionally more Moderate- and High-Risk issues and RCEs, and exploitation growth is concentrated in perimeter appliances and high-impact n-day weaponization. GTIG recommends threat-intelligence-driven triage and targeted remediation.
read more →

AI-discovered Vulnerabilities More Likely to Enable RCE

🔍 Google Threat Intelligence Group (GTIG) reports that vulnerabilities identified as likely discovered by AI are disproportionately associated with remote code execution (RCE). Between January and August 2026, GTIG found 50% of likely AI-discovered flaws led to RCE versus 26% of other CVEs, while overall disclosures and exploit activity accelerated. The research highlights concentrations in agent orchestration frameworks and edge/security appliances, noting rapid weaponization of n-days and localized zero-day spikes.
read more →

AI-powered attack campaign compromises retailers cheaply

🔒 Research from Israeli security firm Gambit shows attackers used open-source AI tools to target 105 online retailers over five days, successfully compromising 27 of them. The campaign used tools named Strix, Cairn, and Hermes to find vulnerabilities, exploit them autonomously, and orchestrate operations. The attacker acquired AI model access via OpenRouter and spent roughly $7,005 over four weeks — about $25 per attack — while harvesting hundreds of thousands of credit card details and installing skimmer scripts.
read more →

CISA outlines a Quality Era for global CVE program

🔍 CISA has published a framework to improve CVE data quality as disclosure volumes and AI‑driven discovery accelerate. The paper, released on September 22, shifts the CVE Program from growth to a focus on reliability, responsiveness and record accuracy amid surging submissions. It defines quality across governance, ecosystem participation, data infrastructure and CVE record content and proposes potential measures without setting targets. CISA plans continued engagement with CNAs, researchers and vendors alongside technical modernization.
read more →

Guide to Major Hardware and Firmware Vulnerabilities

🔒 This article surveys high-impact hardware and firmware vulnerabilities discovered since Meltdown and Spectre, explaining how speculative execution and other low-level design features enable side-channel leaks. It summarizes notable CPU and DRAM exploits, outlines required mitigations such as microcode, BIOS/UEFI and OS updates, and highlights cases where only silicon revisions can fully resolve the risk. The piece emphasizes long-lived exposure and coordination challenges among vendors.
read more →

Unit 42 Launches Continuous Frontier AI Defense

🔒 Unit 42 introduces Continuous Frontier AI Defense, an always-on service that combines offensive security expertise with Anthropic Mythos and OpenAI GPT cyber models to discover, validate, and remediate vulnerabilities across applications, identities, cloud, and network assets. The service uses proprietary multi-model harnesses and Zero Data Retention architectures to protect customer data while accelerating remediation and reducing exposure. It builds on prior Frontier AI offerings and is available worldwide via annual subscription.
read more →