< ciso
brief />
Tag Banner

All news with #vulnerability management tag

256 articles

AI-Driven Development Raises App Vulnerability Risk

🔍 Sonatype finds enterprise applications now contain 4.31 times more critical and high-severity vulnerabilities since AI-driven software development accelerated. The firm analyzed four years of development data and reports application creation has increased nearly fivefold in the AI era. While the median age of unresolved vulnerabilities has fallen 59%, indicating faster fixes, the growth in risk outpaces traditional security processes.
read more →

Study: Mid‑Market Firms Drive Majority of Ransomware Hits

📊 A Black Kite study finds that 73% of ransomware victims since 2023 were mid‑market firms with $10m–$1bn in revenue. The report analyzed 13,336 disclosed incidents and scanned 120,128 mid‑market companies, revealing that lower mid‑market organizations bore the largest share of attacks. Manufacturing is the sector most targeted, and common security gaps include KEVs, patching failures, high‑severity CVEs and deficient DMARC. Black Kite warns AI will compound the triage burden for small security teams.
read more →

ETSI Proposes 17 Standards for EU Cyber Resilience Act

🛡️ The European Telecommunications Standards Institute (ETSI) has launched an approval process for 17 draft cybersecurity standards to align products with the EU Cyber Resilience Act (CRA). The drafts, published on 13 August, define minimum security features—such as modern cryptography, secure-by-default settings, SBOMs and update capabilities—across network, edge, IoT and security product categories. Submissions from 41 member bodies are under public enquiry, with stakeholder comments invited through mid-September to mid-November 2026 and final standards expected by December 2026 ahead of CRA enforcement in December 2027.
read more →

Oracle launches Database Security Central free trial

🔒 Oracle has introduced Database Security Central, a tool that provides a centralized view of security risk across database environments and will be free through February 2027. It arrives as attackers increasingly target Oracle database flaws and following Oracle’s move to monthly patch releases. The tool assesses posture, detects configuration drift, highlights privileged access risks, monitors sensitive data access, and centralizes policy management and audit evidence collection.
read more →

AI-driven vulnerability discovery and its implications

🔍 A Black Hat USA 2026 keynote highlighted rapid growth in AI-assisted vulnerability discovery and the strain it places on defenders. Research from Arizona State University found that advanced models and workflows dramatically increased the number of bugs found, creating reporting and patching backlogs. This surge raises concerns about responsible disclosure, patching practices, and the potential for AI to eventually reduce new vulnerabilities as models and development processes improve.
read more →

Rethinking cyber defense as AI accelerates exploits

🔒 Microsoft warns that AI-driven tools are accelerating vulnerability discovery and exploit generation, making traditional reactive patching and detection-centric defenses insufficient. David Weston of Microsoft highlighted MDASH findings showing rapid, low-cost exploit generation and urged industry shifts toward memory-safe languages like Rust, proactive secure-by-construction methods, and AI-assisted remediation. The talk, delivered at Black Hat USA, framed resilience and prevention as the new priorities.
read more →

Unit 42 expands Frontier AI exposure analysis

🔍 Unit 42 is deploying advanced frontier AI cyber models in customer environments to find, validate, and help remediate meaningful attack paths. Through a partnership with OpenAI, Palo Alto Networks is integrating models like GPT-5.6 Daybreak into its Frontier AI Exposure Analysis to test exploitability, chain weaknesses, and prioritize fixes. Unit 42 combines model output with its offensive expertise and telemetry to validate findings and guide defenders.
read more →

Black Hat USA 2026: AI and cybersecurity controls

🧭 The Black Hat USA 2026 conference centered on AI's influence across cybersecurity, featuring keynotes and panels with senior US officials who debated regulation, innovation, and national leadership. Speakers including the White House National Cyber Director and representatives from CISA and the FBI discussed rapid vulnerability discovery enabled by AI, industry collaboration, and the need for prioritization. Presentations highlighted incidents such as the OpenAI–Hugging Face case and emphasized that AI systems act through human-set tasks and controls, underscoring accountability and governance requirements.
read more →

NIST Seeks Input to Modernize NVD for AI Era

🛡️ NIST has issued a request for information to modernize the National Vulnerability Database (NVD) to better address AI-driven challenges and incorporate automation. The RFI, published on August 12, asks stakeholders for forward-looking perspectives and practical recommendations to improve the NVD’s scalability, interoperability, transparency and utility. NIST noted that traditional periodic scanning and manual remediation are becoming inadequate as AI-enabled tools and faster technology cycles increase vulnerability volumes. Responses are invited through October 13, with the aim of creating a more continuous, contextual and automated vulnerability management system.
read more →

Legacy software bugs that lingered for decades

📰 This article reviews a series of long-dormant vulnerabilities—some more than 30 years old—unearthed and finally patched in recent years. It highlights how AI-powered analysis and deep inspections have accelerated the discovery of latent flaws across widely used projects such as libpng, PostgreSQL, Nginx, and the Linux KVM module. The piece explains the origins, exploitation risk, and remediation status of each bug, emphasizing supply-chain and infrastructure impacts and urging administrators to apply available patches.
read more →

OpenAI launches GPT‑5.6‑Cyber for security teams

🔒 OpenAI introduced GPT‑5.6‑Cyber, a cybersecurity-focused variant of GPT‑5.6 Sol designed for vulnerability research, exploit development, and incident response. Offered through a Daybreak Red tier for authorized defenders, it completes far more high-risk cyber prompts than standard models and outperforms prior GPT‑5.5‑Cyber on several benchmarks. The model has already helped discover high-severity flaws, though it sometimes produces shorter vulnerability reports and performs less well on open-ended exploit development tasks.
read more →

OpenAI unveils GPT‑5.6 Cyber for vetted security partners

🔒 OpenAI has released GPT 5.6 Cyber, a specialized model for vulnerability research, penetration testing, and incident response, available only to approved companies and security vendors. The offering includes two access tiers—Daybreak Blue for defensive workloads and Daybreak Red for tightly governed tasks—and will be integrated into partner tools and services rather than exposed to regular users. OpenAI emphasizes safeguards such as identity verification, scoped testing, logging, and human oversight to mitigate abuse.
read more →

Rise of polyglot file attacks and defenses

🛡️ Files created with the polyglot technique are increasingly used in cyberattacks to evade filters and confuse investigators. Attackers craft files that can be interpreted as multiple formats (for example, PNG or ZIP) so different applications or scanners see different contents. Real-world campaigns have used EXE/ZIP, PDF/DOC, MSI/JAR, DLL/HTML and multi-archive polyglots to deploy malware like PhantomPyramid, StrRAT, Ratty and IcedID. Defenses rely on consistent security hygiene and targeted testing of detection tools.
read more →

Top Exposure Management Questions Security Leaders Ask

🔎 This article answers common questions security leaders ask when evaluating Check Point Exposure Management, covering asset discovery, cloud coverage, supplier monitoring, dark web intelligence, leaked credentials, IOC feeds, and integrations. It explains how EASM and CAASM discover external and internal assets, how findings are enriched with vulnerabilities and controls, and how unified visibility supports prioritization and remediation. The piece emphasizes integrations and operational workflows that accelerate response and reduce organizational risk.
read more →

Human oversight critical as AI patching tools miss risks

🔍 Researchers from 1Password evaluated AI-generated patches from ChatGPT-5.5 and Claude Opus 4.8 and found many fixes syntactically correct but operationally flawed. The study examined 6 recent CVEs and 6,080 generated patches, revealing only ~26% fully remediated issues without altering behavior. The team found numerous cases where patches left attack paths open, introduced new vulnerabilities, or merely blocked the proof-of-concept without fixing root causes.
read more →

Why exposure management is replacing vulnerability management

🔍 Traditional vulnerability management finds issues, but that doesn't equal reduced risk. Modern environments are interconnected, and attackers chain weaknesses, identities, and permissions to reach valuable targets. The Gartner CTEM framework shifts the focus from individual findings to the broader exposures attackers can exploit. Organizations must prioritize reducing exposure, not just counting or patching vulnerabilities.
read more →

BigQuery Autonomous Performance and Cost Optimizations

🧭 BigQuery introduces autonomous, history-based query optimizations and an upgraded advanced runtime to improve performance and reduce compute costs without user intervention. These capabilities include enhanced vectorization, short query optimizations, and support for open formats like Apache Iceberg, delivering up to 35% faster queries and 40% lower slot usage in 2025. The platform’s fluid scaling autoscaler enables per-second billing and average cost reductions up to 34%, with built-in safety guardrails to prevent regressions.
read more →

Verification Closes the Loop on Risk Reduction

🔍 Organizations often equate remediation with reduced risk, but scanning and closed tickets don’t prove attackers can no longer achieve their objectives. A survey of 750 security leaders found only 30% validate that patches actually eliminate risk, while many rely on rescans. Real verification requires testing attack paths and outcomes, as shown by a firm whose retest reduced impacts from 251 to zero. Continuous verification, not just remediation, is the emerging standard.
read more →

Frontier AI Drives a Surge in OSS Vulnerabilities

🛡️ Unit 42 reports that an autonomous agentic system called NOVA scanned 3,915 open-source projects and found 14,090 confirmed vulnerabilities in two months. The research shows 99.4% of findings were previously unreported and many were high or critical severity, demonstrating how frontier AI accelerates vulnerability discovery and compresses the time between disclosure and exploitation. The report highlights the need for rapid virtual patching, coordinated disclosure, and improved supply-chain and defensive practices.
read more →

AI Lowers the Bar for Offensive Cyber Capability

🔒 Generative AI is reshaping attacker profiles by enabling less experienced actors to perform tasks that once required deep technical expertise. Security teams should expect faster exploit development, higher attack volume, and more experimentation as AI accelerates reconnaissance, code generation, and payload adaptation. Continuous validation of controls through Continuous Threat Exposure Management and services like PTaaS becomes essential to keep defenders ahead.
read more →