惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

雷峰网
雷峰网
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园 - 三生石上(FineUI控件)
博客园 - 聂微东
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
Hugging Face - Blog
Hugging Face - Blog
Apple Machine Learning Research
Apple Machine Learning Research
博客园 - Franky
MyScale Blog
MyScale Blog
A
About on SuperTechFans
博客园_首页
B
Blog RSS Feed
Martin Fowler
Martin Fowler
大猫的无限游戏
大猫的无限游戏
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Vercel News
Vercel News
C
Check Point Blog
H
Hackread – Cybersecurity News, Data Breaches, AI and More
博客园 - 【当耐特】
M
MIT News - Artificial intelligence
宝玉的分享
宝玉的分享
T
Tailwind CSS Blog
I
InfoQ
罗磊的独立博客

Help Net Security

ChatGPT advanced account security adds passkeys and hardware keys Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for months Automating Pentest Delivery: A Step-by-Step Guide - PlexTrac Open-source privacy proxy masks PII before prompts reach external AI services Shadow AI risks deepen as 31% of users get no employer training Identity is the control plane for distributed infrastructure AI traffic is getting bigger, louder, and less predictable New infosec products of the month: April 2026 cPanel zero-day exploited for months before patch release (CVE-2026-41940) Cisco releases open-source toolkit for verifying AI model lineage Met Police face criticism for using AI to spy on their own officers Nine-year-old Linux kernel flaw enables reliable local privilege escalation (CVE-2026-31431) Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security IP Fabric MCP server adds governance and control to enterprise AIOps workflows - Help Net Security Aqua Compass MCP server enables real-time investigation and containment of runtime threats - Help Net Security Google brings instant email verification to Android, no OTP needed - Help Net Security If cyber espionage via HDMI worries you, NCSC built a device to stop it - Help Net Security Apple fixes iPhone bug that let FBI retrieve deleted Signal messages(CVE-2026-28950) - Help Net Security GopherWhisper APT group hides command and control traffic in Slack and Discord - Help Net Security OpenAI tackles a bad habit people have when interacting with AI - Help Net Security A year in, Zoom's CISO reflects on balancing security and business - Help Net Security Scenario: Open-source framework for automated AI app red-teaming - Help Net Security GDPR works, but only where someone enforces it - Help Net Security Ransomware, fraud, and lawsuits drive cyber insurance claims to new peaks - Help Net Security Google’s Workspace Intelligence promises privacy while running on your data - Help Net Security Cyberattack on French government agency triggers phishing alert - Help Net Security Claude Mythos finds 271 Firefox flaws, Mozilla believes zero-days are numbered - Help Net Security Prove Identity Platform connects verification, authentication, and fraud prevention - Help Net Security New Mirai variants target routers and DVRs in parallel campaigns - Help Net Security Acronis GenAI Protection gives MSPs control over AI usage and data risks - Help Net Security
AWS Continuum brings AI models to code vulnerability mana...
Sinisa Markovic · 2026-06-18 · via Help Net Security

AWS Continuum for code vulnerabilities, a system built to handle a vulnerability across its lifecycle, from discovery through to a fix, is now available in gated preview. It reasons over a customer’s environment, confirms which findings are real, and works toward resolution. It is model agnostic and draws on multiple frontier models, assigning each to the work where it performs best. AWS designed it to take in newer models as they become available.

AWS Continuum

“We need to shift to the new world: telemetry, context, reasoning, and actions. An approach that produces outcomes. The latest cybersecurity frontier models further made this shift urgent. Models like Claude Mythos can now find software vulnerabilities and reason through complex attack paths at machine-speed, leading to an exponentially increasing backlog of vulnerabilities,” Chet Kapoor, VP of Search, Security, and Observability at AWS, explained.

Four phases of operation

Continuum for code vulnerabilities runs in four continuous phases.

In discovery, the system ingests a customer’s existing backlog and runs its own scan of the environment, producing a wider view of vulnerabilities and the attack paths tied to them.

In prioritization, it weighs each finding against context such as whether the affected component is deployed, whether it is reachable, whether it sits in a production path, and what the business impact would be if exploited. The output is an evidence-backed list of priorities.

In validation, the system filters false positives and builds working exploit examples in a sandboxed environment, giving reproducible evidence of each issue.

In mitigation and remediation, it reviews existing defenses around a confirmed issue, including blocking controls, compensating controls, and detection mechanisms. It then recommends a network change, a policy change, or a code patch. The patch recommendation passes through the same validation system that confirmed the vulnerability. The product also supplies blast radius visibility and rollback paths where feasible.

The system reasons over structured and unstructured data. Structured inputs include infrastructure, permissions, network topology, and code. Unstructured inputs include documents, communications, and business priorities that describe how an organization operates and where its risk lies.

Graduated automation and added capabilities

Continuum begins in learn mode with a human reviewing its work, and every recommendation arrives with the reasoning behind it. Customers can move it to enforce mode, where remediation becomes increasingly automated according to categories and risk profiles they define.

AWS folded several existing tools into the product. The penetration testing and code scanning functions of the AWS Security Agent now run as Continuum pen testing and Continuum code scanning, both in preview. The company also launched Continuum threat modeling in preview, which generates threat models from design documents or source code and produces output in STRIDE format. These functions feed detection and analysis into the broader Continuum loop of discovery, prioritization, validation, and remediation.

Download: Secure Foundations for AI Workloads on AWS