惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

D
DataBreaches.Net
B
Blog
博客园_首页
C
Check Point Blog
Microsoft Security Blog
Microsoft Security Blog
MyScale Blog
MyScale Blog
P
Proofpoint News Feed
Engineering at Meta
Engineering at Meta
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
B
Blog RSS Feed
M
MIT News - Artificial intelligence
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
WordPress大学
WordPress大学
宝玉的分享
宝玉的分享
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
The Cloudflare Blog
量子位
V
V2EX
Y
Y Combinator Blog
Hugging Face - Blog
Hugging Face - Blog
Martin Fowler
Martin Fowler
Recent Announcements
Recent Announcements
I
InfoQ
博客园 - 【当耐特】

Help Net Security

ChatGPT advanced account security adds passkeys and hardware keys Week in review: High-severity LPE vulnerability in the Linux kernel, cPanel 0-day exploited for months Automating Pentest Delivery: A Step-by-Step Guide - PlexTrac Open-source privacy proxy masks PII before prompts reach external AI services Shadow AI risks deepen as 31% of users get no employer training Identity is the control plane for distributed infrastructure AI traffic is getting bigger, louder, and less predictable New infosec products of the month: April 2026 cPanel zero-day exploited for months before patch release (CVE-2026-41940) Cisco releases open-source toolkit for verifying AI model lineage Met Police face criticism for using AI to spy on their own officers Nine-year-old Linux kernel flaw enables reliable local privilege escalation (CVE-2026-31431) Hacker with a special interest in breaching sports institutions ends behind bars - Help Net Security IP Fabric MCP server adds governance and control to enterprise AIOps workflows - Help Net Security Aqua Compass MCP server enables real-time investigation and containment of runtime threats - Help Net Security Google brings instant email verification to Android, no OTP needed - Help Net Security If cyber espionage via HDMI worries you, NCSC built a device to stop it - Help Net Security Apple fixes iPhone bug that let FBI retrieve deleted Signal messages(CVE-2026-28950) - Help Net Security GopherWhisper APT group hides command and control traffic in Slack and Discord - Help Net Security OpenAI tackles a bad habit people have when interacting with AI - Help Net Security A year in, Zoom's CISO reflects on balancing security and business - Help Net Security Scenario: Open-source framework for automated AI app red-teaming - Help Net Security GDPR works, but only where someone enforces it - Help Net Security Ransomware, fraud, and lawsuits drive cyber insurance claims to new peaks - Help Net Security Google’s Workspace Intelligence promises privacy while running on your data - Help Net Security Cyberattack on French government agency triggers phishing alert - Help Net Security Claude Mythos finds 271 Firefox flaws, Mozilla believes zero-days are numbered - Help Net Security Prove Identity Platform connects verification, authentication, and fraud prevention - Help Net Security New Mirai variants target routers and DVRs in parallel campaigns - Help Net Security Acronis GenAI Protection gives MSPs control over AI usage and data risks - Help Net Security
Cato cuts vulnerability protection time to 45 minutes wit...
Industry News · 2026-06-01 · via Help Net Security

Cato Networks announced a new capability that reduces time-to-protect for newly disclosed vulnerabilities to 45 minutes. The company attributes this reduction to the use of agentic threat research designed to accelerate protection against emerging exploits.

Traditional appliance-based security depends on a slow customer-operated patching cycle: vendors develop protections, customers receive updates, teams test them, and thousands of distributed appliances must be upgraded or configured. In the AI era, that model cannot keep pace with exploit velocity.

“Attackers move in minutes. Appliance-centric security still moves in patch cycles,” said Shlomo Kramer, CEO of Cato Networks. “Cato closes the gap by turning new CVE intelligence into protections deployed globally across our cloud service, with zero customer effort. In the AI era, security architecture is no longer a matter of efficiency. It is a do-or-die security decision.”

When exploits move at AI speed, architecture becomes the difference

Frontier AI models, like Anthropic’s Claude Mythos and OpenAI’s ChatGPT-cyber, are accelerating the scale and speed of CVE disclosure. According to NIST, CVE submissions increased by 263% between 2020 and 2025, and submissions during the first three months of 2026 were nearly one-third higher than the same period last year.

Meanwhile, traditional patching cannot keep pace. Verizon’s 2025 DBIR found that only about 54% of edge device vulnerabilities were fully remediated throughout the year, with a median remediation time of 32 days. Legacy security operations were not designed for the volume and velocity of the AI era.

The result: Security teams are no longer fighting time-to-protect, they are fighting to reduce time-to-exploit.

Cato: Built to close the protection gap

Cato brings agentic acceleration to a CVE protection lifecycle already proven at cloud scale. For nearly a decade, Cato has monitored CVEs, developed protections, validated efficacy, and deployed updates automatically across the Cato Cloud with near-zero false positives, enabling record setting CVE mitigation even before the development of agentic researchers. Agentic CVE mitigation builds on this proven operating model, using AI agents to accelerate each step of the process and deliver faster protection to customers.

Cato’s agentic CVE mitigation runs the full protection lifecycle with human supervision, but without human involvement:

  • Monitor and triage publication of disclosed vulnerabilities from multiple sources
  • Extract IoCs and exploit reproduction in a lab environment
  • Develop threat signatures based on Cato’s unique and contextual language
  • Test and simulate threat signatures to eliminate false positives and disruption
  • Deploy threat signature to the global Cato Cloud Platform

Cato’s cloud-native platform is updated automatically, removing the burden of customer-owned patching across a distributed security infrastructure. Cato brings together the three architectural requirements for agentic security operations: the network to see attacks, the platform to correlate context, and the cloud to enforce protection globally. This combination enables Cato to operationalize security at machine speed.

Agentic security requires the right architecture

Cato’s agentic CVE mitigation demonstrates a broader industry shift: Security operations are moving from manual, customer-operated workflows to continuous, machine-scale protection delivered through cloud-native platforms. By automating vulnerability analysis, exploit reproduction, protection generation, and validation, Cato reduced protection generation time to as little as 45 minutes.

“The breakthrough here is not just speed,” said Elad Menahem, SVP of Research at Cato Networks. “It’s that vulnerability response itself can now operate continuously and at machine scale.”