‏إظهار الرسائل ذات التسميات AI Cybersecurity. إظهار كافة الرسائل
‏إظهار الرسائل ذات التسميات AI Cybersecurity. إظهار كافة الرسائل

Sophos Unveils Exploit Path Verification to Prioritize Real‑World Vulnerabilities with OpenAI Cyber Models

Sophos, a global cybersecurity leader, today announced Exploit Path Verification (EPV), a new capability that will be built into Sophos Managed Risk to help security teams better prioritize and manage exploitable vulnerabilities in their environment. The capability will be built with OpenAI's GPT cyber models through the Daybreak Defense Network, to return verified, evidence-backed verdicts that give defenders the clarity they need to fix the exposures that matter first. Availability will be announced at a later date.

Security teams face a widening gap between the vulnerabilities they can find and the ones they can fix. Scanners surface thousands of exposures and severity scores and rank them, but a severity score cannot tell whether a critical flaw sits behind a control that blocks it, or whether two low-severity findings chain into the path that leads to a breach. As a result, security teams often patch by generic score, rather than by whether an attacker could reach and use a flaw in their specific environment.

Sophos is designing EPV to close that gap. It is being built to reason over asset and patch state, endpoint protection policy, network reachability, identity and privilege facts, and known exploit availability, and returns a clear evidence-backed exploitability verdict:
  • Confirmed Exploitable
  • Blocked by a Control
  • Not Reachable
  • Insufficient Evidence
EPV will also be designed to identify chained paths where multiple lower-severity findings combine into one exploitable route, assess whether a control blocks a technique class or only a common public proof of concept, and draft remediation text ready for a ticket.

The capability will be advisory and additive by design. Every verdict is labeled as AI-generated with its evidence visible, and Sophos analysts review the results.

One of the most common challenges we hear from security teams today is the volume of findings they need to sift through, and the lack of clarity of which findings matter most, or in other words, put them at greatest risk,” said John Peterson, chief technology officer, Sophos. “Exploit Path Verification is being built to make it clear what in their environment is reachable by an attacker, with the evidence to prove it, so they fix what counts first.”

EPV extends Sophos' work with OpenAI. Through the OpenAI Daybreak Defense Network (formerly OpenAI Daybreak Cyber Partner Program), which Sophos joined in June 2026, the company brought frontier cyber models into MDR investigation, advisory assessments, and workflows that help customers discover, validate, and remediate exposure. EPV will build on that work inside a product customers already run. OpenAI's GPT cyber models provide frontier reasoning to help assess exploitability. Sophos supplies the environment-specific evidence and product controls, and its analysts review the results delivered to customers.

Our goal through the OpenAI Daybreak Defense Network is to give defenders the advantage of frontier AI, safely,” said McCall McIntyre, Head of Global Cyber Partnerships, OpenAI. Sophos has been a thoughtful partner since joining the program, and Exploit Path Verification is a clear example of frontier reasoning applied to a real defensive problem, with the guardrails that responsible deployment demands.”

Sophos defends more than 625,000 organizations worldwide, including 40,000 managed detection and response (MDR) customers across enterprise, mid-market, and commercial segments, delivered through one of the industry's largest partner ecosystems. That reach is central to EPV's purpose. Verified exploitability should not be a capability reserved for the largest security teams with the deepest budgets.

EPV is in development for enterprise and mid-market business customers of Sophos Managed Risk. Sophos will announce availability, including early access and general availability timing, at a later date.

For more on Sophos Managed Risk, please visit sophos.com/services/managed-risk.

Palo Alto Networks Launches Frontier AI Critical Defense Program to Shield Infrastructure at AI Speed

A collaboration of leading technology providers to protect critical infrastructure against the rapid rise of AI-discovered vulnerabilities

Palo Alto Networks (NASDAQ: PANW) today announced the Frontier AI Critical Defense Program, a first-of-its-kind initiative to protect critical infrastructure from AI-driven exploits. Through the program, leaders across operational technology (OT), healthcare, commercial software and open-source communities coordinate with Palo Alto Networks to deploy proactive "virtual patches,” neutralizing vulnerabilities at the network-level before attackers can exploit them.

Palo Alto Networks recently used Frontier AI models to uncover more than 14,000 previously unknown vulnerabilities in open source software, underscoring how AI could enable threat actors to automate cyberattacks and shrink attack timelines. Yet, critical infrastructure operators, constrained by strict uptime and safety testing, cannot patch at AI speed. This mismatch creates a significant exposure gap, leaving essential systems vulnerable long before software fixes can be safely deployed.

​​True defense at AI speed requires joint action. This program builds on our existing collaborations with IBM and Red Hat (as part of Lightwell), Microsoft (as part of MAPP) and OT leaders like Siemens and the Idaho National Laboratory (as part of the OT Threat Research Lab).

Today, the collaboration is expanding to include Anthropic, OpenAI, OT leaders like Mitsubishi and Axis Communications, industry consortiums for sharing risk information like Analysis and Resilience Center for Systemic Risk and Health-ISAC, OT research organizations like the independent, non-profit Energy R&D Institute (EPRI) and OSS initiatives like Akrites (an initiative from the Linux Foundation).

Palo Alto Networks Frontier Virtual Patching puts these insights into action to deliver proactive protection for joint customers. By combining Frontier AI threat discovery with trusted vulnerability intelligence, it delivers rapid network-level patches while safeguarding sensitive vulnerability details from attackers.

Lee Klarich, Chief Product Officer, Palo Alto Networks, In the age of Frontier AI, the traditional, reactive race to build and deploy software patches before adversaries exploit a flaw is a losing battle. Protecting critical infrastructure requires a structural shift from isolated patching to collective, proactive intelligence. Through initiatives like our Frontier AI Critical Defense Program, we can neutralize threats at the network layer before they are weaponized.”

Help safeguard critical infrastructure by joining the expanding Frontier AI Critical Defense Program, today. Visit the website to learn more on how to get involved, or explore Palo Alto Networks broader Frontier AI Defense Initiative.

Palo Alto Networks (NASDAQ: PANW), the global AI cybersecurity leader, protects our digital way of life with a comprehensive portfolio of cybersecurity solutions and platforms across Network, Cloud, Security Operations, AI and Identity. Trusted by 70,000+ customers and powered by Unit 42 threat intelligence, our AI-driven platforms eliminate complexity, empowering enterprises to modernize with confidence and securing the speed of innovation. Explore the future of security at www.paloaltonetworks.com.

Forward-Looking Statements

This release contains forward-looking statements with respect to Palo Alto Networks that involve risks, uncertainties and assumptions, including, without limitation, statements regarding the benefits, impact, or performance or potential benefits, impact or performance of Palo Alto Networks products, technologies, and integrations or future products, technologies, and integrations. These forward-looking statements are not guarantees of future performance, and there are a significant number of factors that could cause actual results to differ materially from statements made in this release. Palo Alto Networks identifies certain important risks and uncertainties that could affect its results and performance in its most recent Annual Report on Form 10-K, its most recent Quarterly Report on Form 10-Q, and its other filings with the Securities and Exchange Commission from time-to-time, each of which are available on Palo Alto Networks' website at investors.paloaltonetworks.com and on the SEC's website at www.sec.gov. All forward-looking statements in this release regarding Palo Alto Networks are based on information available to Palo Alto Networks as of the date hereof, and Palo Alto Networks does not assume any obligation to update the forward-looking statements provided to reflect events that occur or circumstances that exist after the date on which they were made.

IBM & Red Hat Invest $5B to Secure Open Source Software in AI Era

IBM & Red Hat Invest $5B to Secure Open Source Software in AI Era

IBM and Red Hat’s Project Lightwell is being positioned as a landmark effort to secure open-source software in the age of AI-driven cyber threats. Rather than treating vulnerabilities as isolated incidents, Lightwell embeds remediation directly into enterprise workflows, ensuring that fixes are not only discovered but also deployed seamlessly across production environments.

At its core, Lightwell operates as an enterprise clearinghouse. This means it coordinates vulnerability disclosures, validates patches, and manages lifecycle fixes across the open-source ecosystem. Enterprises can integrate Lightwell into their existing build tools—such as Maven, Nexus, or Artifactory—by redirecting them to Red Hat’s secure registry. With a single configuration change, organizations gain access to a catalog of more than 6,500 digitally signed, remediated dependencies. These are backported to the exact versions running in production, eliminating the need for disruptive upgrades that often stall patch adoption.

The initiative is powered by a combination of frontier AI models and 20,000 engineers. AI accelerates vulnerability discovery and triage, while human experts validate and remediate issues with enterprise-grade rigor. This dual approach is critical because AI alone can generate false positives or incomplete fixes, but when paired with human oversight, it becomes a force multiplier for security.

Lightwell is structured around two major offerings. The Lightwell Network, already live, provides enterprises with immediate access to remediated dependencies. The Clearinghouse Premier, currently in limited rollout, acts as a trusted intermediary for patch embargoes and vertical threat coordination. Financial services firms are the first adopters, with expansion planned into healthcare, government, and telecom.

The program’s importance lies in its response to AI-accelerated threats. Advanced models can discover thousands of vulnerabilities in minutes, compressing the time between discovery and exploit. For industries like finance and healthcare, where downtime or breaches can have systemic consequences, Lightwell offers a way to maintain operational continuity while staying ahead of attackers.

Partnerships are central to its rollout. Major banks including Goldman Sachs, JPMorgan Chase, Visa, Citi, and Wells Fargo are early adopters. Deloitte has joined as a collaborator, providing orchestration services, compliance reporting, and Forward Deployed Engineers to ensure validated fixes are deployed at machine speed. This adds a layer of trust and auditability that regulators demand in highly scrutinized sectors.

In essence, Lightwell is not just a patching service—it is a new industry model for securing open source software. By embedding AI-driven remediation into enterprise workflows and coordinating disclosures through a trusted clearinghouse, IBM and Red Hat are attempting to redefine how global industries defend against systemic cyber risks.

LTM Launches BlueVerse™ RightLogic to Address Cyber Risk in AI Era

  • New assessment and risk assurance framework helps enterprises gain unified visibility, prioritise remediation and scale AI securely
LTM, the Business Creativity partner to the world’s largest enterprises, has launched BlueVerseTM RightLogic, a cybersecurity assessment and risk assurance framework designed to help enterprises identify, assess and remediate cyber exposure as they accelerate AI adoption.

AI is now capable of autonomously identifying and exploiting vulnerabilities, while exposure across infrastructure, applications and supply chains continue to expand. This has elevated cyber risk from a technology concern to a board-level priority, with enterprises struggling to maintain visibility and respond at the speed of emerging threats.

BlueVerse RightLogic addresses this gap by providing a unified, business-aligned view of enterprise exposure and enabling a shift from fragmented, point-in-time assessments to continuous, evidence-led risk management. The framework combines an end-to-end AI and cyber exposure assessment engine with a structured execution model that spans from assessment to remediation.

At the core of the offering is an innovative, robust cybersecurity assessment model spanning software supply chain risk, legacy systems, network exposure, identity and access controls, AI-specific risks and governance readiness. The framework integrates an outside-in view of adversarial exposure with an inside-out assessment of enterprise readiness across people, process and technology, supported by a dedicated AI-specific risk lens.

AI-driven threats are autonomous, scalable and continuous, and they demand a fundamentally different approach to cybersecurity. With BlueVerse RightLogic, we enable organizations to quantify exposure, prioritize action and build a defensible security posture that supports safe and scalable AI adoption,” said Krishnan Iyer, Chief Growth Officer, LTM.

Delivered through a structured 4 to 6 week engagement, BlueVerse RightLogic provides rapid diagnostics, deep domain assessments, and a board-ready risk summary, followed by a prioritized remediation roadmap. The model extends into execution through a partner-led ecosystem that drives fixes across infrastructure, applications and open-source dependencies, enabling faster response cycles, improved risk visibility, and a governed pathway for secure AI adoption at scale.

To know more about LTM BlueVerse RightLogic, click here.

PwC India Launches Connected Cybersecurity Solutions Centre in Bengaluru to Secure Smart Factories, Critical Infrastructure & Emerging Tech

PwC India Launches Connected Cybersecurity Solutions Centre in Bengaluru to Secure Smart Factories, Critical Infrastructure & Emerging Tech
  • A first-of-its-kind lab and delivery centre that brings together OT, IoT, hardware testing and AI-led monitoring under one roof.
PwC India, on Wednesday, announced the launch of its Connected Cybersecurity Solutions Centre (CCSC) in Bengaluru, a step further in the firm's journey of building and securing the future of technology. Built around the theme "Securing the connected ecosystem," the Centre is designed to help organisations defend smart factories, connected products, critical infrastructure and emerging technology environments against an increasingly sophisticated threat landscape.

The CCSC houses two purpose-built zones — a Product Security Operations Centre (Product SOC) and a Hardware (Product) Testing Centre — that together replicate real-world environments across smart factory, EV charging, smart grid, drone, smart city and medical device use cases. Through interactive demos, accelerated proofs of concept, co-creation workshops and live attack-and-defence walkthroughs, clients can experience capabilities first-hand and seamlessly transition from demonstration to delivery.

Commenting on the launch, Sanjeev Krishan, Chairperson, PwC in India said, "The way our clients build, operate and grow is being fundamentally redefined by technology — and so is the way we, at PwC, choose to show up for them. The Connected Cybersecurity Solutions Centre is more than a lab; it is a statement of intent. It reflects how deeply technology, engineering and innovation are now woven into the fabric of our firm — from the assets we build, to the platforms we run, to the way our people solve problems. As emerging technologies reshape every industry, we want our clients to see a firm that doesn't just advise on transformation, but lives it."

The Centre is powered by PwC's proprietary suite of cyber accelerators, including Smart Product (IoT) Shield, Smart Factory (OT) Shield, the Technical Compliance Management System (TCMS), the Cyber Nerve Center (Fusion Centre), the Quantum & Crypto Service Platform, Digital Twin, Digital Assets (Blockchain) and Next-Gen Connectivity (5G) use cases. These solutions are unified by a common digital backbone of AI/ML, ELK, Edge Computing, Blockchain, PKI and Confidential Computing — enabling clients to stay secure across every stage of the product lifecycle, from R&D and design through production, after-sales and end-of-life.

"Cybersecurity decisions today are made at the speed of business, and our clients need partners who can move with them — from boardroom strategy to a working proof of concept on the shop floor. The CCSC is built precisely for that. Clients can walk in with a problem and walk out having seen their use case demonstrated, tested and validated on real hardware, real OT and real IoT environments. This dramatically shortens the journey from insight to impact, helps de-risk transformation programmes, and gives our clients far greater confidence in the security posture of their connected products and operations," said Siddharth Vishwnath, Partner and Leader – Risk Consulting, PwC India.

The CCSC features 11+ live demo stations spanning ransomware, lateral movement, PLC logic manipulation, SCADA tampering, GPS spoofing, CAN bus attacks, Bluetooth and RFID exploits, and rogue Wi-Fi takeovers — paired with PwC India's detection, monitoring, response and remediation capabilities.

The launch of the CCSC marks another deliberate step in PwC India's evolution from a professional services firm that advises on technology to one that is increasingly building and securing the future of technology — designing, engineering and owning the platforms behind its client outcomes. The Centre's accelerators — Smart Product Shield, Smart Factory Shield, TCMS, the Cyber Nerve Center, the Quantum & Crypto Service Platform and others — are proprietary platforms built, run and continuously enhanced by PwC's own engineering and product teams. Looking ahead, the Centre will serve as the central hub of an interconnected network of PwC labs — including the Experience Centres and the Gurugram Centre — evolving into a Connected Security Platform characterised by interconnected intelligence, zero-touch orchestration and cyber-autonomous infrastructure.

Wipro Expands Palo Alto Networks Partnership With Cortex XSIAM and CybershieldSM to Deliver AI‑powered Cyber Defense

Wipro Expands Palo Alto Networks Partnership With Cortex XSIAM and CybershieldSM to Deliver AI‑powered Cyber Defense

Wipro Limited (NYSE: WIT, BSE: 507685, NSE: WIPRO), a leading AI-powered technology services and consulting company, announced the expansion of its partnership with Palo Alto Networks, the global AI cybersecurity leader, to offer AI-driven Managed Detection and Response (MDR) services.

The partnership brings together Palo Alto Networks’ Cortex XSIAM with CyberShieldSM, Wipro’s managed security services capabilities in a more focused offering for modern security operations. The new offering will deliver proactive cyber defense with simplified workflows using machine learning, AI, and automation to predict and protect against future attacks. It will enable faster detection and response across complex environments, while filtering signals from noise, improving analyst efficiency, and increasing focus on critical, high-impact threats.

This offering is supported by Wipro’s WEGA and WINGS, AI delivery platforms that are a part of Wipro Intelligence™, suite of AI-powered platforms, solutions, and transformative offerings for workflow orchestration, service transition, and automation at scale across security operations.

“As organizations navigate a rapidly evolving landscape marked by accelerated AI adoption, the need for robust governance and strategic cost management has never been greater,” said Satish Yadavalli, Global Business Head - Cloud, Infrastructure, and Security Services, Wipro Limited. “Together with Palo Alto Networks, we are able to transform security operations through AI, automation, and platform consolidation, strengthening organizations’ security environments while optimizing costs and improving outputs.”

The expanded relationship builds on an existing foundation with Palo Alto Networks across cloud, network and security transformation, and reflects growing demand from clients for more integrated, AI-led security operations.

“AI-manufactured attacks require an AI-powered defense, and our partnership with Wipro helps deliver just that,” said Simone Gammeri, Senior Vice President and Chief Partnership Officer at Palo Alto Networks. “Our combined capabilities empower mutual customers to consolidate tools, eliminate data silos, and leverage AI and automation to reduce noise, accelerate response from days to minutes, and ultimately stop even the most sophisticated threats.”

The MDR services are delivered through Wipro’s eight Cyber Defense Centers (CDCs), anchored by the proprietary SOC GURU (Grand Unified Runbook Unleashed) framework—a unique IP that drives SOC transformation through attack- and alert-agnostic analysis. This unified, adaptive approach is designed to strengthen threat detection and response while supporting more resilient security operations.

This approach is already reflected in a recent engagement with a European gaming and entertainment leader, where Wipro and Palo Alto Networks helped transform security operations in a complex enterprise environment to deliver improved productivity, accelerated response, and reduced costs.





About Wipro Limited

Wipro Limited (NYSE: WIT, BSE: 507685, NSE: WIPRO) is a leading AI-powered technology services and consulting company focused on building innovative solutions that address clients’ most complex digital transformation needs. Leveraging our consulting-led approach and the Wipro Intelligence™ unified suite of AI-powered platforms, solutions and transformative offerings, we help clients realize their boldest ambitions to build intelligent and sustainable businesses. The Wipro Innovation Network–part of the Wipro Intelligence™ suite–underpins our commitment to client-centric co-innovation and co-creation by bringing together capabilities from the innovation labs and partner labs, academia, and global tech communities. With over 240,000 employees and business partners across 65 countries, we deliver on the promise of helping our customers, colleagues, and communities thrive in an ever-changing world. For additional information, visit us at www.wipro.com.

NetApp and Cisco Collaboration Strengthens Defense-in-Depth for Enterprise Cyber Resilience

NetApp and Cisco Collaboration Strengthens Defense-in-Depth for Enterprise Cyber Resilience
  • New NetApp Splunk SOAR playbook helps contain ransomware attacks and limit data loss
NetApp® (NASDAQ: NTAP), the Intelligent Data Infrastructure company, and Cisco, (NASDAQ: CSCO) today announced an expansion of their collaboration to help customers strengthen defense-in-depth strategies for customers. Combining Intelligent Data Infrastructure with advanced analytics and observability capabilities, NetApp and Splunk have delivered deep, real-time visibility into storage and infrastructure health. Together, they are helping customers turn operational data into actionable insights that improve reliability, security, and business outcomes. By expanding their collaboration with the new NetApp Splunk Security Orchestration, Automation, and Response (SOAR) playbook, NetApp and Splunk are helping joint customers contain ransomware attacks and limit data loss at the storage layer, enhancing the containment of the blast radius of cyberattacks while increasing the speed and reducing the cost of recovery.

“With AI accelerating both the speed and sophistication of cyberattacks, the window to respond has never been smaller,” said Sandeep Singh, Senior Vice President and General Manager, Platform at NetApp. “To limit the cost and impact of ransomware, organizations must act the moment a threat is detected, which means extending security automation into the storage layer where data lives. As the company delivering the most secure storage on the planet, NetApp is uniquely positioned to make storage an active part of a defense-in-depth strategy. By working with Cisco to enable Splunk SOAR workflows to take direct action on data stored in NetApp ONTAP®, we’re helping make a defense-in-depth security strategy simpler and more effective.”

To give customers the resiliency and flexibility they need to protect their data, Cisco and NetApp are releasing the NetApp Splunk SOAR playbook. Splunk Enterprise Security is already integrated with NetApp Ransomware Resilience to collect analytics from the data layer, enhancing incident triage and prioritization. With the new playbook, Splunk SOAR users can now use those signals as well as signals from other solutions to automatically take incident response actions directly on NetApp ONTAP storage as an integral part of their incident response. These actions include blocking a suspicious user, taking snapshots of the data and taking data volumes offline to protect against further infection. As a result, customers will be better able to contain ransomware attacks and limit data loss at the storage layer. Utilized as part of the organization’s defense in depth security strategy, the NetApp Splunk SOAR playbooks help to strengthen collaboration between security and storage teams.

Automating the response and recovery actions against cyber threats with the NetApp Splunk SOAR playbook improves security team metrics like mean time to contain (MTTC) and reduces the manual effort and skills required to protect data. As a result, NetApp and Cisco are making it faster and more efficient for enterprises to achieve cyber resilience.

Effective security strategies require visibility and action across the entire technology stack, including the data layer,” said David Dalling, GVP, Splunk Security at Cisco. “With the new NetApp Splunk SOAR playbook, ONTAP storage becomes an active participant in the security ecosystem, enabling organizations to contain threats directly targeting enterprise data. By connecting NetApp storage into Splunk SOAR workflows, we’re helping security and storage teams collaborate more seamlessly and respond to incidents with greater speed and confidence.”

The partnership between Splunk and NetApp helps customers run their businesses more securely and effectively, connecting operations across storage and security teams,” said Dallas Olson, Chief Commercial Officer at NetApp.By giving customers real-time visibility into what’s happening across their environments, NetApp and Splunk enable enterprises to reduce disruption and optimize performance so they can use their data to drive measurable business outcomes.”

The NetApp Splunk SOAR playbook is now available to download from SplunkBase.

Additional Resources Cyber Resilience: The Most Secure Storage on the Planet
Ransomware Resilience: Ransomware Protection Using AI-Based Detection

About NetApp

For more than three decades, NetApp has helped the world’s leading organizations navigate change – from the rise of enterprise storage to the intelligent era defined by data and AI. Today, NetApp is the Intelligent Data Infrastructure company, helping customers turn data into a catalyst for innovation, resilience, and growth.

At the heart of that infrastructure is the NetApp data platform – the unified, enterprise-grade, intelligent foundation that connects, protects, and activates data across every cloud, workload, and environment. Built on the proven power of NetApp ONTAP, our leading data management software and OS, and enhanced by automation through the AI Data Engine and AFX, it delivers observability, resilience, and intelligence at scale

Disaggregated by design, the NetApp data platform separates storage, services, and control so enterprises can modernize faster, scale efficiently, and innovate without lock-in. As the only enterprise storage platform natively embedded in the world’s largest clouds, it gives organizations the freedom to run any workload anywhere with consistent performance, governance, and protection.

With NetApp, data is always ready – ready to defend against threats, ready to power AI, and ready to drive the next breakthrough. That’s why the world’s most forward-thinking enterprises trust NetApp to turn intelligence into advantage.

About Cisco

Cisco (NASDAQ: CSCO) is the worldwide technology leader that is revolutionizing the way organizations connect and protect in the AI era. For more than 40 years, Cisco has securely connected the world. With its industry leading AI-powered solutions and services, Cisco enables its customers, partners and communities to unlock innovation, enhance productivity and strengthen digital resilience. With purpose at its core, Cisco remains committed to creating a more connected and inclusive future for all. Discover more on The Newsroom and follow us on X at @Cisco.

Cisco and the Cisco logo are trademarks or registered trademarks of Cisco and/or its affiliates in the U.S. and other countries. A listing of Cisco’s trademarks can be found at http://www.cisco.com/go/trademarks. Third-party trademarks mentioned are the property of their respective owners. The use of the word ‘partner’ does not imply a partnership relationship between Cisco and any other company.

Market Reports

Market Report & Surveys
IndianWeb2.com © all rights reserved