惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

量子位
C
CXSECURITY Database RSS Feed - CXSecurity.com
Project Zero
Project Zero
O
OpenAI News
C
Cisco Blogs
Microsoft Azure Blog
Microsoft Azure Blog
Security Latest
Security Latest
T
Tor Project blog
S
SegmentFault 最新的问题
P
Privacy & Cybersecurity Law Blog
博客园 - 【当耐特】
V
Vulnerabilities – Threatpost
W
WeLiveSecurity
小众软件
小众软件
博客园 - 聂微东
Y
Y Combinator Blog
Spread Privacy
Spread Privacy
人人都是产品经理
人人都是产品经理
Know Your Adversary
Know Your Adversary
Scott Helme
Scott Helme
B
Blog RSS Feed
N
News | PayPal Newsroom
J
Java Code Geeks
T
The Blog of Author Tim Ferriss
TaoSecurity Blog
TaoSecurity Blog
D
Docker
阮一峰的网络日志
阮一峰的网络日志
NISL@THU
NISL@THU
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
L
LINUX DO - 最新话题
MongoDB | Blog
MongoDB | Blog
Recorded Future
Recorded Future
Webroot Blog
Webroot Blog
L
Lohrmann on Cybersecurity
博客园 - 三生石上(FineUI控件)
雷峰网
雷峰网
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
L
LangChain Blog
Cloudbric
Cloudbric
罗磊的独立博客
宝玉的分享
宝玉的分享
Jina AI
Jina AI
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
N
News and Events Feed by Topic
GbyAI
GbyAI
大猫的无限游戏
大猫的无限游戏
A
About on SuperTechFans
L
LINUX DO - 热门话题
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC

Cisco Blogs

Deloitte Japan Advances Security Operations with Cisco Foundation AI’s Open-Source Model CCNP Security News Roundup: Free SDSI Training, New Duo Course Cisco AI Defense Policy Studio: Turning Unwritten Policy into Adaptive AI Guardrails From Intelligence to Action: Operationalizing MS-ISAC Threat Data Across SLED Environments Scale. Speed. Trust: Three Imperatives for the AI Era Reflecting on Cisco Live: OT security is the new IT. Are you ready? Security in the Post-Mythos Era Fusing Security and Networking: Your Fastest Path to Profitability How we built an AI foundation for Marketing Revenue Operations at Cisco Cisco SASE with Meraki: Get in the Fast Lane to SASE Powering the AI-ready branch with agentic operations and quantum-era security Voices from the field: How data strengthens livelihoods in coastal communities Cisco Customer Achievement Awards AMER 2026: Honoring Those Transforming IT From tenant-aware to job-aware: scaling shared AI clusters with Cisco Nexus One Protecting SaaS AI Agents with Cisco AI Defense and AppOmni AI Agents Need Built-In Security. Here Is How Cisco Does It AI infrastructure has entered its operational era Cisco Silicon One: Purpose-Built for Secure Networking in the Agentic AI Era Accelerating Growth for Developers with Cisco Compatible AI Solutions in the Cisco 360 Partner Program Share Your Experience: Where the Human Voice Thrives in the Age of AI Layered Defense for the Plant Floor: Simplifying OT Security Extending Zero Trust Across the Agentic AI Workflow White House AI Executive Order: Advancing Innovation & Security Streamlining Partner Procurement: Introducing the ‘Shop Cisco Refresh’ eCommerce Platform How Cisco Cloud Control Changes the Partner Motion Powering resilient ecosystems | FY25 Purpose Report End-to-end AI networking: Cisco’s answer to the inferencing era Quantum Resilience Needs a Common Language. Here’s Where to Start. Security at Cisco Live: Going Shields Up for the Agentic Era From an Idea to a Live App on Cisco, in Minutes Agent Builder in Cloud Control Studio: A new way to extend and customize Cisco Cloud Control Cisco AI Canvas is here: the workspace for agentic operations Cisco Cloud Control: The Secure Harness for the Agentic Era Identity Elevated: A New Unified Identity Experience in Cisco Cloud Control Security Needs a New Operating Model Cisco AI Defense Gets Personal with Agent Security DevNet Sandbox: Building the Future of Developer Experiences Oscar’s Insights: A Conversation on BBVA Argentina’s Network Transformation Cisco Secure Access and Microsoft Purview Integration for Simplified Data Protection Cisco Secure Access and Island Browser Enable Zero Trust Everywhere Finding what lives between the alerts: Announcing Cisco Talos Threat Hunting From Log Flood to Threat Signal: Cisco and Splunk Bring Context to Modern Defense The Skills Payload: What’s Landing at Cisco Live 2026 More efficient and functional workplaces start with smart building data Cisco Secure Access and Microsoft Edge for Business Integration Must-See Cisco U. Theater Sessions at Cisco Live 2026 Las Vegas Navigating the Future of Connected Roadways: Cisco at ITS Americas 2026 In the AI era, defense starts with the network. Here’s how Cisco is doing it. Unlock the power of scale-across with Cisco converged silicon, systems, and optics Trusted network data for end-to-end visibility with Nexus Data Broker Maximizing Managed Security Services Sales & Profitability: Part 2 of 2, A Strategic Guide to Creating New Services Explore Enterprise Networking Automation at Cisco Live US 2026 A new model for infrastructure security: How Cisco defends against AI threats From Research to Reality: Launching the 9th Annual Cisco Partner Innovation Challenge Unlocking Partner Profitability with Lifecycle Advantage APIs Why Financial Agility is the New Competitive Edge Proprietary Problems: No Frontier Model Is Multi-Turn Immune Securing campus and branch networks from boot to transport with full-stack PQC Why Network Segmentation Projects Fail: Four Patterns Accelerating Enterprise-Scale AI Development & Experimentation Cisco’s Risk-Based Vulnerability Disclosure in the Age of AI Powering Modern Data Workloads with Cisco UCS and Qumulo The Fundamentals of AI: What every curious person should know about how language models work The impact of AI on wide area network traffic: we need to talk Cisco Live 2026 Las Vegas: Explore AI and automation across the network One open NOS, any workload: SONiC on Cisco Enhancing Cisco Secure Email Gateway: Safer Clicks and Cleaner Files Cisco Partners With College Board to Launch AP Cybersecurity and Expand Career-Connected Learning Fueling “The Greatest Spectacle in Racing®” AI-generated reporting: Lessons learned from Cisco Talos Incident Response Cisco Named a Leader in the 2026 Gartner® Magic Quadrant™ for Enterprise Wired and Wireless LAN Infrastructure AI network performance with Cisco Intelligent Packet Flow Building a world-class employee experience | FY25 Purpose Report Real-World Skills for Real World Challenges: AI-Led Updates Across Cisco Certification Portfolio Learn with Cisco at Cisco Live 2026: Your Week for Skills, Certs, and What’s Next Cisco N9000 excels in EANTC 2026 VXLAN EVPN and timing tests Innovating at the Speed of Business: Announcing the Customer Achievement Awards AMER 2026 Finalists Future of Sports Analytics: Building Trust and Intelligence with SūmerSports and Cisco Accelerate Your Career and Impact with CCNA Certifications Skills-based volunteering for the AI era: Inside Cisco’s first Tech for Social Good Hackathon Cisco Live 2026: Bringing the Future of Customer Experience to Las Vegas Mission-First: Equipping the Digital Warfighter at AFCEA TechNet Cyber 2026 Edge opportunity for service providers: Turn infrastructure into new services MRC and SRv6: How Foundational Networking Innovations Are Enabling the Next Generation of AI Supercomputers The SMB Marketing Reset: Winning Customer Trust in a Digital-First Economy Inside the SOC: AI-powered DNS defense against ransomware Our Path Forward Securing the Federal Digital Experience with Cisco ThousandEyes for Government Cisco at ONUG Dallas 2026: Securing the AI Data Center in the Agentic Era Cisco and Red Hat are powering intelligent core to edge: Red Hat Summit insights Building the Capabilities That Win: How Cisco Partners Can Lead in the SMB & Mid-Market Era How Two Hours Felt Bigger Than My To-Do List Announcing Foundry Security Spec Ace the CCIE Collaboration Lab: Success Tips from a TAC Engineer Turned CCIE Protecting Agents with Cisco AI Defense and Google Agent Development Kit Powering an Inclusive Future: Your guide to the Purpose Pavilion at Cisco Live Las Vegas The Infrastructure Behind the Mission: SOF Week 2026 Cisco Networking App Marketplace Partners at Cisco Live 2026 Beyond the Pilot: Building the Clinical Data Fabric for the Agentic Era Benchmarking scale-out AI fabrics with Cisco N9000 + AMD Pensando™ Pollara 400 NICs
Strengthening the Foundation: A Predictable, Customer focused Response to AI-Accelerated Vulnerability Discovery
Russ Smoak · 2026-06-02 · via Cisco Blogs

Why we are changing our cadence

The fundamental scale of vulnerability discovery has shifted. Frontier AI models and agentic analysis harnesses are now surfacing bugs across large code bases at a rate that the traditional, ad-hoc disclosure-and-patch model was never designed to absorb, not by Cisco, and not by the operators who run our gear. At the same time, the window between disclosure and exploitation has effectively closed. Manual, one-off advisories at unpredictable intervals are no longer the right tool for the job.

Starting in July, and for the foreseeable future, we are moving to a scheduled, twice-monthly security disclosure model, paired with seven days of advance notification of which technologies will be covered in each release. This is a deliberate, engineered response to a structural change in the threat landscape, not a reaction to any single incident. This is a hardening program run at scale, with the discipline customers expect from infrastructure they depend on.

What is changing

Scheduled disclosures — 1st and 3rd Wednesdays. Beginning in July, Cisco is reserving the first and third Wednesday of each month for security hardened software publications.

Seven-day advance notice. Seven days before each release, PSIRT will publish the list of technologies and platforms included in that drop. If nothing is planned, there will be no communication. You will know what is coming, on which products, before it lands — so you can pre-stage change windows, lab validation, and maintenance approvals. Cisco is committed to thoughtfully bundling products to minimize overlap in upgrades.

Our core Network Operating Systems products (NOS) are being scheduled as the first products to be released. Core operating system products include Cisco IOS XE, IOS XR, NX-OS, Firepower/ASA, and SD-WAN. Our plan is for the NOS products to be released quarterly. Cisco will not release multiple core NOS products on the same day. Other products may be released more often.

Systemic fixes, not just point patches. Our agentic discovery framework — multiple specialized agents covering static code analysis, live system testing, configuration review, and exploit simulation — runs portfolio-wide. That breadth lets us identify recurring architectural patterns and remediate the underlying class of defect across products, not just the instance that was reported. Security engineers remain in-the-loop for validation, prioritization, and verification.

Bundled and streamlined CVEs. The security hardened releases will not have individual CVEs assigned to each bug as they have pervasive fixes and should be qualified and deployed urgently. Individual CVE assessment and corner-case workarounds will not be manageable. Cisco PSIRT will provide ‘bundled’ CVEs (Common Vulnerability Exposures) tied to CWE categories (Common Weakness Enumerations). For example:

  • CVE-2026-20xxx – Multiple fixes for Input Validation – CWE-20
  • CVE-2026-20xxx – Multiple fixes Access Control – CWE- 284

This change to how we assign CVEs is not about sweeping issues away or reducing transparency; it reflects a shift in what keeps customers secure. Assessing security risk CVE-by-CVE and applying point mitigations is no longer fit for purpose. Any release predating our security-hardened versions carries materially higher risk, and that gap will only widen as adversaries use AI to develop exploits at machine speed. The most effective protection is running a current, hardened release, not patching individual findings across older ones.

We remain committed to disclosure and transparency. When a vulnerability warrants an individual CVE assignment, (e.g., requiring compensating controls, known exploitation, or otherwise demands defender action), Cisco will assign a CVE and provide robust details. We recognize this shifts emphasis from per-issue detail toward release-level assurance, but this is where the infrastructure industry must move towards defending against this new landscape.

What this means for you

We’ve listened to and understood the concerns: more findings, more patches, more operational load, and the fear of being exposed to the gap between discovery and deployment. The new model is designed specifically to reduce that pressure, not add to it.

  • Predictability replaces surprises. A fixed cadence and a 7-day pre-announcement mean patch management becomes a planned activity, not a fire drill. You can align it with your existing change-control process.
  • Batched, not buried. Consolidating fixes into scheduled releases reduces the number of separate maintenance events, the volume of one-off advisories to triage, and the regression-test surface for each deployment.
  • Risk is going down, not up. AI-accelerated discovery means vulnerabilities that previously sat latent in the code base for years are being found and fixed by us, on a clock we control, before they are weaponized against you. The release volume reflects debt being cleared, not new fragility being introduced.
  • You are not behind. If a finding is being addressed in a scheduled release, upgrading should negate the need to implement corner-case mitigations that do not scale.

What PSIRT will publish

For each release window, PSIRT will provide:

  • The 7-day advance notice listing affected technologies and platforms
  • The release-note contents on publication day, including bundled CVE details correlated to fixed software releases.
  • Summary details on what has been addressed

What stays the same

Our disclosure principles, our coordination with the broader security community, and our obligations to customers under existing support contracts are unchanged. The Cisco PSIRT is the gold standard for vulnerability disclosure and will drive this revolution – with significantly expanded tooling and cadence built for the new rate of discovery.

Emergencies will happen. Our process will remain unchanged for responding and working out of our normal release cycles to address security incidents, active exploitation and external discovery of zero-day vulnerabilities.

How we are prioritizing engineering capacity

We are explicitly placing focus on key AI-discovered findings and the resulting systemic hardening ahead of new feature work in the affected platforms. That is a direct trade-off, and it is the right one. Resilient, well-maintained infrastructure is the product. Hardening our software is, for this period, the highest-value engineering work we can deliver to customers.

Furthermore, we are integrating advanced agentic capabilities in secure and responsible ways into our development and testing environments. By leveraging AI-driven testing and automated patching workflows (with security engineers firmly “on-the-loop”) we are accelerating our ability to identify, validate, and deploy fixes with greater speed and precision.

Easing the Patching Process

We continue to prioritize efforts to make patching easier across our product portfolio. Our controller platforms include capabilities to deploy patches at scale. Our investment in Live Protect is specifically designed to help organizations bridge the gap between when a vulnerability is uncovered, and the organization can patch.

Cisco IQ provides organizations with the information necessary to understand the security state of their installed base – CVE exposure, hardening, and provides guidance to allow organizations to address the related risks. Additionally, Cisco Services is available to assist organizations in evolving security processes for the AI-era.

Closing

This is a transition we have prepared for. The engineering teams, the PSIRT organization, the release infrastructure, and the customer-facing tooling are aligned behind it. The goal is straightforward: get fixes into your hands faster, on a schedule you can plan against, with enough advance notice to deploy them on your terms.

We will continue to refine the cadence, the notification format, and the supporting tooling based on what we hear from you in the first several cycles. Direct feedback from operators has shaped this model, and it will continue to shape how it evolves.

Thank you for the partnership. The work ahead is substantial, but it is the right work, and we are ready to partner with our customers to drive a new standard of security and resiliency.