惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

人人都是产品经理
人人都是产品经理
有赞技术团队
有赞技术团队
WordPress大学
WordPress大学
月光博客
月光博客
T
Tailwind CSS Blog
阮一峰的网络日志
阮一峰的网络日志
小众软件
小众软件
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Last Week in AI
Last Week in AI
大猫的无限游戏
大猫的无限游戏
S
SegmentFault 最新的问题
罗磊的独立博客
Jina AI
Jina AI
酷 壳 – CoolShell
酷 壳 – CoolShell
宝玉的分享
宝玉的分享
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园 - 三生石上(FineUI控件)
量子位
雷峰网
雷峰网
Apple Machine Learning Research
Apple Machine Learning Research
美团技术团队
博客园 - 聂微东
V
V2EX

Security @ Cisco Blogs

Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time Thrown into the SOC: A Black Hat First-Timer’s Story Troubleshooting Wi-Fi at Black Hat USA 2026 with ThousandEyes Distributed Latency Monitoring at Black Hat Black Hat USA 2026: Safeguarding DNS with Secure Access Building a Risk-Based Secure Network Analytics Detection with Splunk Detection Editor (Alpha) Crypto Agility: Why PQC Is Not a One-Time Upgrade From Isolated Agents to Collective Intelligence: Why A2A Is the Protocol the Agentic SOC Has Been Waiting For Microsegmentation’s Moment Is Now: Cisco Named a Leader in The Forrester Wave™: Microsegmentation Solutions Identity Everywhere: Bringing Infrastructure Identity to Agentic IT Cisco Named a Leader in the 2026 IDC MarketScape for Worldwide SASE Meet Instant Attack Verification: Agentic AI for Tier-1 and Tier-2 SOC investigation Elevating Federal Cybersecurity: Cisco’s Path from FedRAMP Certified Class C (Moderate) to Certified Class D (High) Elevating Trust: Email Threat Defense Achieves FedRAMP Class D (High) Certification Is your SD-WAN ready for AI-powered operations? The Zero Trust Imperative for the Frontier AI Era Assuming Failure: The Mindset Shift That Actually Improves Your Defensive Outcomes The Journey towards Logically Air-Gapped Deployment Cisco Firewall Migration Manager: A Faster, Simpler, More Confident Path to Secure Firewall We third-party tested our firewall built for AI-scale. The test tools hit their limit first. SharpHound Recon Attack - How AI enhanced the threat hunt Machine Speed, Human Judgement: How AI Changed the SOC in 2026 Elevating Expertise in the SOC Educate at Event Speed: Cisco Live Security Operations Center What Working the Cisco Live SOC Taught Me About AI, Detection, and Response Cable to Cloud - A Product Engineer's Journey Through the Cisco Live AMER 2026 SOC The Experience Dividend: How Better Digital Experience Protects Revenue, Trust, and Growth AIM: Building an Agentic Tier-2 SOC Analyst at Cisco Live AMER 2026 Building the Agentic SOC at Cisco Live Americas 2026 Ten Years in the SOC at RSAC: What We Learned in 2026
Frontier AI just raised the stakes, and the old playbook ...
Jason Maynard · 2026-09-04 · via Security @ Cisco Blogs

We all know the uncomfortable truth. No matter how many tools you buy or how mature your processes are, you’ll never achieve 100% prevention 100% of the time. Project Glasswing and Frontier models just made that truth louder.

In May 2026 Anthropic released the first public initial update on Project Glasswing. In roughly one month, partners found more than 10,000 high- or critical-severity vulnerabilities. Some teams saw their bug-finding rates jump by more than 10×. Mozilla fixed 271 issues in a single Firefox release. Cloudflare pulled 2,000 findings with a false-positive rate better than their human testers. The open-source community got hit with thousands more.

The bottleneck has moved and finding vulnerabilities is no longer the hard part. Fixing them at the same velocity as vulnerability discovery is an unrealistic task today.

The 2026 Verizon DBIR already showed the shift before Glasswing even landed: vulnerability exploitation became the #1 initial access vector at 31%, overtaking credential abuse for the first time ever. Only 26% of CISA KEVs (known exploited vulnerabilities) were fully remediated, and median time to fix climbed to 43 days. Frontier models are about to pour gasoline on that fire; the fundamentals matter more than ever.

Cisco ran its own experiment leveraging a variety of frontier models. Cisco scanned 1.8 billion lines of code across the portfolio against 25 languages in eight weeks. This work would have taken roughly eight years the old way. Cisco leveraged harnesses to improve the fidelity and was able to keep false-positive rate under 3%. Closer to home, the Government of Alberta used Claude to review 466 million lines of code across 27 ministries in about 20 hours. That’s not theoretical. That’s operational reality by an incredible team of practitioners.

So, what does this mean for the rest of us?

It means the “hope of a single control will save us” mindset is finished. We need to assume failure earlier and design for resilience and speed of detection/response. The same rational I have been pushing around layered defense and MITRE ATT&CK mapping. Assume breach to build better defensive outcomes.

Cisco has been leading the industry with thought leadership, innovation, and opensource.

  • Foundry Security Spec: a model-agnostic blueprint so teams can turn frontier models into something auditable instead of a noisy chat window. This allows organizations to build harnesses that fit their unique environment providing higher fidelity outcomes. This initiative was called out by Anthropic’s initial Glasswing report in May. Foundry-Security-Spec
  • CodeGuard: is an open-source, model-agnostic security framework that embeds secure-by-default practices into AI coding agent workflows. It provides comprehensive security rules that guide AI assistants to generate more secure code automatically. Project CodeGuard
  • Foundation-Sec-8B: Model Card: open-weight model that extends Llama-3.1-8B model through continued pretrained on a curated corpus of cybersecurity-specific text, including threat intelligence reports, vulnerability databases, incident response documentation, and security standards. It has been trained to understand security concepts, terminology, and practices across multiple security domains. The model is designed to serve as a domain-adapted base model for use in applications such as threat detection, vulnerability assessment, security automation, and attack simulation. Foundation-Sec-8B
  • Antares: small, open-weight models that actually localize known vulnerabilities inside large codebases without sending your source to the cloud. 🌟 Antares
  • DefenseClaw: Security governance for the entire AI agent lifecycle. Scan skills and MCP servers before admission, inspect prompts and tool calls at runtime, pause risky actions for human approval, and export the evidence to your existing security stack. DefenseClaw
  • The LLM Security Leaderboard: so, you can see how models actually hold up under single turn and multi-turn attacks before you put them into production. Cisco LLM Security Leaderboard

Cisco’s own “Shields Up” guidance is pretty clear on the customer side:

  • Strengthen the fundamentals (phishing-resistant MFA, least privilege including for agents, real asset visibility).
  • Kill the end-of-life stuff that frontier models will chew through first.
  • Automate detection, triage, and containment at machine speed.
  • Put runtime protections closer to the workloads.
  • Use AI for defense, not just discovery.

And yes, Cisco IQ is the practical place a lot of this comes together for customers. Continuous visibility, prioritized exposure, adaptive assessments, and the resilient infrastructure services that are built for the speed we’re now operating at.

Ask yourself honestly:

  • Where am I still hoping that good enough is enough?
  • Do you have the fundamentals in place and what should I prioritize?
  • Have I mapped my current controls against the attack chain knowing the discovery rate just accelerated?
  • If the adversary lands tomorrow with an AI-assisted exploit chain, how freely can they move?
  • How resilient is my architecture and can I defend against vulnerabilities when patching is not available?
  • Am I still treating modernization as a cost conversation instead of a security imperative?

The tools and the playbooks exist. The only remaining variable is whether we move at the speed the threat now demands.

I’d love to hear what you’re seeing in your environments especially around the remediation bottleneck. Drop a comment or reach out.

— Jason Maynard
Field CTO, Cybersecurity – Canada, Cisco
YouTube Channel

Authors