< ciso
brief />
Tag Banner

All news with #vulnerability management tag

290 articles · page 3 of 15

Unit 42 expands Frontier AI exposure analysis

🔍 Unit 42 is deploying advanced frontier AI cyber models in customer environments to find, validate, and help remediate meaningful attack paths. Through a partnership with OpenAI, Palo Alto Networks is integrating models like GPT-5.6 Daybreak into its Frontier AI Exposure Analysis to test exploitability, chain weaknesses, and prioritize fixes. Unit 42 combines model output with its offensive expertise and telemetry to validate findings and guide defenders.
read more →

Black Hat USA 2026: AI and cybersecurity controls

🧭 The Black Hat USA 2026 conference centered on AI's influence across cybersecurity, featuring keynotes and panels with senior US officials who debated regulation, innovation, and national leadership. Speakers including the White House National Cyber Director and representatives from CISA and the FBI discussed rapid vulnerability discovery enabled by AI, industry collaboration, and the need for prioritization. Presentations highlighted incidents such as the OpenAI–Hugging Face case and emphasized that AI systems act through human-set tasks and controls, underscoring accountability and governance requirements.
read more →

NIST Seeks Input to Modernize NVD for AI Era

🛡️ NIST has issued a request for information to modernize the National Vulnerability Database (NVD) to better address AI-driven challenges and incorporate automation. The RFI, published on August 12, asks stakeholders for forward-looking perspectives and practical recommendations to improve the NVD’s scalability, interoperability, transparency and utility. NIST noted that traditional periodic scanning and manual remediation are becoming inadequate as AI-enabled tools and faster technology cycles increase vulnerability volumes. Responses are invited through October 13, with the aim of creating a more continuous, contextual and automated vulnerability management system.
read more →

Legacy software bugs that lingered for decades

📰 This article reviews a series of long-dormant vulnerabilities—some more than 30 years old—unearthed and finally patched in recent years. It highlights how AI-powered analysis and deep inspections have accelerated the discovery of latent flaws across widely used projects such as libpng, PostgreSQL, Nginx, and the Linux KVM module. The piece explains the origins, exploitation risk, and remediation status of each bug, emphasizing supply-chain and infrastructure impacts and urging administrators to apply available patches.
read more →

OpenAI launches GPT‑5.6‑Cyber for security teams

🔒 OpenAI introduced GPT‑5.6‑Cyber, a cybersecurity-focused variant of GPT‑5.6 Sol designed for vulnerability research, exploit development, and incident response. Offered through a Daybreak Red tier for authorized defenders, it completes far more high-risk cyber prompts than standard models and outperforms prior GPT‑5.5‑Cyber on several benchmarks. The model has already helped discover high-severity flaws, though it sometimes produces shorter vulnerability reports and performs less well on open-ended exploit development tasks.
read more →

OpenAI unveils GPT‑5.6 Cyber for vetted security partners

🔒 OpenAI has released GPT 5.6 Cyber, a specialized model for vulnerability research, penetration testing, and incident response, available only to approved companies and security vendors. The offering includes two access tiers—Daybreak Blue for defensive workloads and Daybreak Red for tightly governed tasks—and will be integrated into partner tools and services rather than exposed to regular users. OpenAI emphasizes safeguards such as identity verification, scoped testing, logging, and human oversight to mitigate abuse.
read more →

Rise of polyglot file attacks and defenses

🛡️ Files created with the polyglot technique are increasingly used in cyberattacks to evade filters and confuse investigators. Attackers craft files that can be interpreted as multiple formats (for example, PNG or ZIP) so different applications or scanners see different contents. Real-world campaigns have used EXE/ZIP, PDF/DOC, MSI/JAR, DLL/HTML and multi-archive polyglots to deploy malware like PhantomPyramid, StrRAT, Ratty and IcedID. Defenses rely on consistent security hygiene and targeted testing of detection tools.
read more →

Top Exposure Management Questions Security Leaders Ask

🔎 This article answers common questions security leaders ask when evaluating Check Point Exposure Management, covering asset discovery, cloud coverage, supplier monitoring, dark web intelligence, leaked credentials, IOC feeds, and integrations. It explains how EASM and CAASM discover external and internal assets, how findings are enriched with vulnerabilities and controls, and how unified visibility supports prioritization and remediation. The piece emphasizes integrations and operational workflows that accelerate response and reduce organizational risk.
read more →

Human oversight critical as AI patching tools miss risks

🔍 Researchers from 1Password evaluated AI-generated patches from ChatGPT-5.5 and Claude Opus 4.8 and found many fixes syntactically correct but operationally flawed. The study examined 6 recent CVEs and 6,080 generated patches, revealing only ~26% fully remediated issues without altering behavior. The team found numerous cases where patches left attack paths open, introduced new vulnerabilities, or merely blocked the proof-of-concept without fixing root causes.
read more →

Why exposure management is replacing vulnerability management

🔍 Traditional vulnerability management finds issues, but that doesn't equal reduced risk. Modern environments are interconnected, and attackers chain weaknesses, identities, and permissions to reach valuable targets. The Gartner CTEM framework shifts the focus from individual findings to the broader exposures attackers can exploit. Organizations must prioritize reducing exposure, not just counting or patching vulnerabilities.
read more →

BigQuery Autonomous Performance and Cost Optimizations

🧭 BigQuery introduces autonomous, history-based query optimizations and an upgraded advanced runtime to improve performance and reduce compute costs without user intervention. These capabilities include enhanced vectorization, short query optimizations, and support for open formats like Apache Iceberg, delivering up to 35% faster queries and 40% lower slot usage in 2025. The platform’s fluid scaling autoscaler enables per-second billing and average cost reductions up to 34%, with built-in safety guardrails to prevent regressions.
read more →

Verification Closes the Loop on Risk Reduction

🔍 Organizations often equate remediation with reduced risk, but scanning and closed tickets don’t prove attackers can no longer achieve their objectives. A survey of 750 security leaders found only 30% validate that patches actually eliminate risk, while many rely on rescans. Real verification requires testing attack paths and outcomes, as shown by a firm whose retest reduced impacts from 251 to zero. Continuous verification, not just remediation, is the emerging standard.
read more →

Frontier AI Drives a Surge in OSS Vulnerabilities

🛡️ Unit 42 reports that an autonomous agentic system called NOVA scanned 3,915 open-source projects and found 14,090 confirmed vulnerabilities in two months. The research shows 99.4% of findings were previously unreported and many were high or critical severity, demonstrating how frontier AI accelerates vulnerability discovery and compresses the time between disclosure and exploitation. The report highlights the need for rapid virtual patching, coordinated disclosure, and improved supply-chain and defensive practices.
read more →

AI Lowers the Bar for Offensive Cyber Capability

🔒 Generative AI is reshaping attacker profiles by enabling less experienced actors to perform tasks that once required deep technical expertise. Security teams should expect faster exploit development, higher attack volume, and more experimentation as AI accelerates reconnaissance, code generation, and payload adaptation. Continuous validation of controls through Continuous Threat Exposure Management and services like PTaaS becomes essential to keep defenders ahead.
read more →

Extend Amazon Inspector SBOM Generator with Plugins

🔍 Amazon Inspector’s SBOM Generator (inspector-sbomgen) now supports a plugin system that lets developers add custom package collectors without recompiling or waiting for official releases. The post explains how to scaffold plugins, the discovery-collection pipeline, testing with Lua fixtures, and IDE support for rapid iteration. It also details the sandboxed safety model, artifact tracing via source_path, and how plugin-generated components integrate with Amazon Inspector for vulnerability scanning.
read more →

Google credits AI for surge in Chrome vulnerability fixes

🔒 Google reports that AI has enabled Chrome to patch 1,072 security bugs across Chrome 149 and 150, exceeding the total fixed in the prior 23 milestones combined. The company uses large language models across the vulnerability lifecycle—from discovery and repro to patch generation and testing—and has developed multi-agent systems like Naptime and Big Sleep. Google is also accelerating updates with tighter release cycles and exploring dynamic patching to reduce the window between fix commit and user update.
read more →

Sysadmin AI Expectations Fall Short by 2026

🔍 Action1 surveyed over 1,000 sysadmins worldwide to compare 2024 expectations of AI and automation against the state of adoption in 2026. The report finds substantial shortfalls in areas such as patch management, monitoring, vulnerability prioritization and incident remediation, with predicted full automation far exceeding current implementation. Adoption is, however, growing selectively: many admins use AI for analysis and recommendations under supervised models while retaining authority over critical decisions. Concerns remain around privacy, accuracy, cost and job impact.
read more →

AI-Found Flaws Exploited at Similar Rates

🔍 VulnCheck's H1 2026 analysis finds that vulnerabilities discovered with AI tools are being exploited in the wild at roughly the same rate as those found without AI. Of 1,061 AI-attributed findings, 14 (1.3%) were confirmed exploited, closely matching the overall exploitation rate for the period. The report also notes that Anthropic's Project Glasswing produced over 23,000 findings but only 126 led to CVEs and one confirmed exploitation. The researcher concludes frontier AI currently appears to help defenders more than attackers.
read more →

Risk‑Based Patching: Rethinking Vulnerability Prioritization

🛡️ CISA’s Binding Operational Directive (BOD) 26-04 shifts federal vulnerability management from uniform deadlines to risk-based remediation, prioritizing exposures most likely to be exploited. The directive recognizes that CVSS scores alone don’t capture exploitability, reachability or operational context. With AI accelerating attack lifecycles and expanding the attack surface via copilots and integrations, defenders must adopt continuous exposure mapping and validation. The article argues defenders need adversary-aware testing, business-aligned prioritization and a move from patch counts to exposure-centric strategies.
read more →

Threat Source newsletter: Q2 2026 vulnerability trends

📈 This edition of the Threat Source newsletter reviews Q2 2026 vulnerability trends, noting a 49% YoY increase in tracked CVEs and roughly 200 CVEs per day by June. The author contrasts a shifting AI model landscape with slower real-world impact, highlights concerns about keyword-sensitive AI-CVE counts, and advocates prioritizing patches using EPSS rather than raw CVSS scores. Additional coverage includes Cisco Talos' discovery of the Rust-based msaRAT, new Antares SLMs for vulnerability localization, major incidents impacting land registries and WordPress sites, and tactical detection recommendations.
read more →