Tag
Trail of Bits critiques 1Password's AI patching benchmark as misleading due to flawed experimental design, and releases tools to assist in patch validation and review.
OpenAI introduces the Defense Factory, an automated system using AI agents to continuously discover and remediate cybersecurity vulnerabilities, and shares its architecture and operational insights.
OpenAI is expanding access to its frontier cyber models through the Daybreak Cyber Partner Program, enabling security partners like Accenture, CrowdStrike, and Cloudflare to integrate advanced AI into vulnerability discovery, validation, and remediation workflows.
Tenzai announces that its autonomous AI hacker can now automatically deploy WAF mitigations, including via AWS WAF, closing the loop from exploit discovery to deployed defense at machine speed.
Hacktron Automations is a tool designed to streamline the process of discovering and patching vulnerabilities in software systems.
Alex Gaynor argues that the AI-driven 'vulnpocalypse' makes traditional bug-by-bug fixing untenable and calls for systemic security fixes, such as rewriting components in memory-safe languages.
Microsoft is integrating AI into Windows vulnerability management to enhance discovery speed and reduce fix times. The MDASH scanning system and cloud infrastructure help streamline security updates while maintaining quality.
OpenAI launches Patch the Planet, a full-scale effort with Trail of Bits and HackerOne to help open-source projects patch vulnerabilities using AI tools, alongside other cybersecurity announcements including an improved GPT-5.5-Cyber model and expanded government access.
Wiz introduces a closed-loop automated defense system using AI (Gemini) for deep scanning and CodeMender for automated patching, integrated with its cloud security platform used by over 50% of Fortune 100 companies.
The article argues that the traditional 90-day responsible disclosure window is obsolete because LLMs enable rapid, simultaneous discovery of vulnerabilities, necessitating immediate patching of critical issues.
Google announces a $12.5 million pledge as a founding member of the Linux Foundation's Alpha-Omega Project to advance open source security in the AI era, alongside Amazon, Anthropic, Microsoft/GitHub, and OpenAI. The funding will help maintainers address AI-driven threats and deploy advanced security tools like Big Sleep and CodeMender.