LIVE · cybersecurity feed
Live wire
Android’s October 2026 Updates Patch 25 VulnerabilitiesAtlassian Patches Critical Vulnerability Affecting 8 ProductsEven with OT network visibility, critical infrastructure operators struggle with legacy equipmentASOS Hackers Hijack App Notifications, Claim Snowflake Data BreachKarina Portugal Makes the Case for Know Your AgentAlert: FortiBleed remains active campaign, can lock out users or lead to ransomware attacksCVE-2026-93836 · Ninja Forms plugin flaw exploited to hack WordPress sitesCVE-2026-86360 · Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root AccessCVE-2026-21589 · Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 ProductsCVE-2026-88779 · Citrix NetScaler Hit by Third Actively Exploited Zero-Day
vulnerability

Automation, AI agents or people? Sorting out who handles each security finding

A recent survey of 200 senior security and technology leaders reveals significant concerns about the escalating complexity of software security programs, particularly in the wake of increased AI adoption. Over half of the respondents, primarily from companies with 10,000 or more employees, anticipate struggles in simplifying their security operations if current practices persist.

ZeroDay News ·

Source: Help Net Security

A recent survey of 200 senior security and technology leaders reveals significant concerns about the escalating complexity of software security programs, particularly in the wake of increased AI adoption. Over half of the respondents, primarily from companies with 10,000 or more employees, anticipate struggles in simplifying their security operations if current practices persist.

The core challenge identified is the post-scan process: determining the criticality of a flagged vulnerability, identifying its owner, and coordinating remediation across diverse teams and release schedules. This often leads to delays, with the median time to fully resolve a critical vulnerability currently standing at 43 days, according to Verizon's 2026 Data Breach Investigations Report.

AI is contributing to this pressure from two directions. While AI tools accelerate software development, AI-assisted scanning simultaneously uncovers a greater volume of weaknesses. Forty percent of respondents cited the sheer amount of AI-generated code awaiting human review as their most significant software security challenge. Although AI-generated code is not inherently insecure, its volume often overwhelms human review capacity. This figure represents the top concern for those respondents, indicating its prominence among the listed options.

To address this, a tiered strategy for AI-assisted vulnerability discovery was identified by 44% of respondents as the most critical transformation needed. This approach advocates for automation to handle deterministic tasks such as repeatable, low-risk findings, remediations, and mitigations. These tasks are well-suited for established workflows involving normalization, enrichment, ownership routing, ticket management, SLA management, and rescan verification.

The middle layer of this strategy would involve AI agents, which are software capable of performing multi-step tasks with limited supervision. These agents excel at deeper investigations and reasoning, such as assessing signals for reachability and exploitability, identifying correlated findings, and surfacing potential attack paths. Given the judgment calls involved, strong guardrails for auditability and review are essential.

Human involvement would be reserved for critical decisions and their consequences, including risk acceptance and exceptions. The goal is not to eliminate human oversight but to focus limited human time and attention on decisions requiring sound judgment and accountability. Ideally, this layered approach would also involve reviewing findings that reach human attention to identify opportunities to automate similar work in the future.

A primary concern for these leaders is the influx of low-context alerts—warnings that flag weaknesses without providing crucial information such as system reachability, exploitability, dependent business services, or responsible parties. This creates a dual problem of excessive volume and insufficient context for security teams.

Another significant challenge is the proliferation of security tools and the numerous handoffs required to address a finding. A single vulnerability might originate in one scanner, require context from multiple other systems, be prioritized by security, and then be assigned to a developer, cloud engineer, or external vendor. Each step in a separate workflow introduces context loss and delays. When considering tool consolidation, the advice is to merge tools with overlapping functions that produce undifferentiated findings, while retaining and connecting tools that offer significant depth or unique coverage through a common data layer. Key questions for each tool include its unique coverage, signal quality, integration capabilities, and user trust.

For reporting to the board, the primary metric should be the time to remediate meaningful, exploitable, and exposed systems, demonstrating an improving trend in risk management. Leaders also require visibility into organizational challenges, recognizing that organizations are often a collection of teams, assets, products, and business units, each contributing to overall exposure. This visibility helps identify areas needing support, where change is occurring, and potential hotspots across the organization.

vulnerabilityai
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerabilitycritical

Android’s October 2026 Updates Patch 25 Vulnerabilities

Android’s October 2026 security updates have addressed a total of 25 vulnerabilities across the platform. Among these, a critical flaw within Android’s System component has been highlighted, which could potentially allow for privilege escalation on affected devices. The updates are designed to enhance the overall security posture of Android devices by resolving these identified weaknesses.

vulnerabilitycritical

Atlassian Patches Critical Vulnerability Affecting 8 Products

Atlassian has released patches for a critical vulnerability impacting eight of its products. The flaw, if exploited, could allow unauthenticated attackers to gain access to specific files located within the web application's root directory. This type of access could potentially expose sensitive configuration or application data, depending on the contents of the accessible files.

vulnerability

OpenSSH 10.6 enables a post-quantum signature algorithm, so experimental keys need replacing

The OpenSSH project released version 10.6 on October 6, introducing a new hybrid post-quantum signature algorithm and addressing several security vulnerabilities. The maintainers indicated that future releases may occur more frequently to expedite bug fixes, noting a rise in security reports, many identified with the assistance of AI models.

CVE-2026-93524

Check your X.Org server version because a dozen vulnerabilities have been patched

X.Org has released patches for a dozen security vulnerabilities affecting its X server and Xwayland components, with updates available in versions xorg-server 21.1.25 and xwayland-24.1.14. Nine of these flaws are critical, potentially allowing for arbitrary code execution, while the remaining three could lead to server crashes or information disclosure.

ai

AI Agent Gateway: Open-source tool keeps credentials out of agent configs

Tuskira has released AI Agent Gateway, an open-source tool designed to enhance the security of AI agent deployments by centralizing credential management and access control. The gateway operates as an intermediary between AI agents and the services they interact with, including both tool servers (referred to as MCP tools) for platforms like GitHub and Jira, and various large language model…

nation-state

AI endpoint management: Visibility, compliance, and remediation

Organizations today face a growing challenge in managing their endpoint estates, which are expanding rapidly due to factors like hybrid work models, increased cloud adoption, and the use of contractor devices. This expansion, coupled with a constant stream of new Common Vulnerabilities and Exposures (CVEs) and escalating compliance demands, often overwhelms security teams. Manual tracking and…