惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

B
Blog
D
Docker
J
Java Code Geeks
腾讯CDC
Blog — PlanetScale
Blog — PlanetScale
G
Google Developers Blog
M
MIT News - Artificial intelligence
L
LangChain Blog
T
The Blog of Author Tim Ferriss
P
Proofpoint News Feed
MyScale Blog
MyScale Blog
博客园 - Franky
GbyAI
GbyAI
Hugging Face - Blog
Hugging Face - Blog
aimingoo的专栏
aimingoo的专栏
Last Week in AI
Last Week in AI
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 聂微东
N
Netflix TechBlog - Medium
B
Blog RSS Feed
Y
Y Combinator Blog
阮一峰的网络日志
阮一峰的网络日志
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Google DeepMind News
Google DeepMind News

Security @ Cisco Blogs

Black Hat USA 2026: Building the Agentic SOC, One Live Event at a Time Thrown into the SOC: A Black Hat First-Timer’s Story Troubleshooting Wi-Fi at Black Hat USA 2026 with ThousandEyes Distributed Latency Monitoring at Black Hat Black Hat USA 2026: Safeguarding DNS with Secure Access Building a Risk-Based Secure Network Analytics Detection with Splunk Detection Editor (Alpha) Frontier AI just raised the stakes, and the old playbook won’t hold up Crypto Agility: Why PQC Is Not a One-Time Upgrade From Isolated Agents to Collective Intelligence: Why A2A Is the Protocol the Agentic SOC Has Been Waiting For Microsegmentation’s Moment Is Now: Cisco Named a Leader in The Forrester Wave™: Microsegmentation Solutions Identity Everywhere: Bringing Infrastructure Identity to Agentic IT Cisco Named a Leader in the 2026 IDC MarketScape for Worldwide SASE Meet Instant Attack Verification: Agentic AI for Tier-1 and Tier-2 SOC investigation Elevating Federal Cybersecurity: Cisco’s Path from FedRAMP Certified Class C (Moderate) to Certified Class D (High) Elevating Trust: Email Threat Defense Achieves FedRAMP Class D (High) Certification Is your SD-WAN ready for AI-powered operations? The Zero Trust Imperative for the Frontier AI Era Assuming Failure: The Mindset Shift That Actually Improves Your Defensive Outcomes The Journey towards Logically Air-Gapped Deployment Cisco Firewall Migration Manager: A Faster, Simpler, More Confident Path to Secure Firewall We third-party tested our firewall built for AI-scale. The test tools hit their limit first. SharpHound Recon Attack - How AI enhanced the threat hunt Machine Speed, Human Judgement: How AI Changed the SOC in 2026 Elevating Expertise in the SOC Educate at Event Speed: Cisco Live Security Operations Center What Working the Cisco Live SOC Taught Me About AI, Detection, and Response Cable to Cloud - A Product Engineer's Journey Through the Cisco Live AMER 2026 SOC The Experience Dividend: How Better Digital Experience Protects Revenue, Trust, and Growth AIM: Building an Agentic Tier-2 SOC Analyst at Cisco Live AMER 2026 Building the Agentic SOC at Cisco Live Americas 2026
Cisco’s Risk-Based Vulnerability Disclosure in the Age of AI
Russ Smoak · 2026-05-23 · via Security @ Cisco Blogs

As the cybersecurity landscape rapidly evolves, driven by groundbreaking advancements in artificial intelligence (AI), Cisco is adapting its vulnerability disclosure practices to meet the challenges and opportunities presented by these technologies. Notably, the recent introduction of frontier models with advanced cybersecurity reasoning capabilities is transforming how vulnerabilities are discovered, analyzed, and mitigated. These AI capabilities enable unprecedented speed and scale in identifying security issues, while also allowing network defenders to continuously evolve to address emerging threats. Cisco recognizes that network infrastructure is critical, and demands for availability are unrelenting. The AI evolution puts pressure on defenders to absorb and deploy software at a greater pace.

Harnessing AI to Enhance Cybersecurity

Cisco is actively leveraging advanced AI Models to accelerate finding vulnerabilities and driving remediation. Deploying these models into our security processes allows us to find and fix vulnerabilities at a pace previously unattainable. At the same time, we recognize that adversaries will also take advantage of these evolving AI capabilities, increasing the urgency and complexity of cybersecurity defense. We prioritize cutting edge technologies and research to continuously evolve our tools, techniques, and processes by incorporating capabilities such as: AI-augmented scenarios into red teaming exercises, and deep security evaluations of our products against the sophisticated tactics enabled by these models.

Prioritizing Risk to Empower Customers

Cisco has a long history of disclosing vulnerabilities. Our public facing Security Vulnerability Policy (SVP) describes our process in detail including how to report and receive vulnerability information. We continue to adjust our practices within the goals of our overall policy: security, transparency, trust.

Cisco is evolving our risk-based vulnerability disclosure model. This approach focuses on increasing the visibility of detailed technical information for vulnerabilities that pose the highest risk—those that are critical, actively exploited, or have a higher likelihood of exploitation. By prioritizing disclosures based on risk, we enable customers to focus on their patching and mitigation efforts where they are most needed and urgent.

For vulnerabilities that are found internally and assessed as lower likelihood for exploitation and lower impact, Cisco may change the level of detail we share, moving our focus to remediation and upgrades. This means that some internally found issues that have a CVSS score in the range for a standalone advisory will no longer be communicated as standalone disclosure.

Updating the Disclosure Cycle for Lower Severity Vulnerabilities

To aid in risk management, Cisco will provide high-level data on our website for releases that contain patches for internally discovered vulnerabilities. This is intended to direct customers to security hardened releases that should be downloaded and qualified for deployment. This update to the traditional disclosure sequence allows customers to understand when releases contain general security patches. Cisco may release further data summarizing changes to the software to address the findings after the initial posting of the software.

Maintaining Our Commitment to Third-Party and Open-Source Code

Our existing practices for vulnerabilities in third-party or open-source components remain unchanged. For high severity issues in these areas, we will continue to post timely responses and provide regular updates as patches are developed and released.

Looking Ahead: The Future of AI and Cybersecurity

The capabilities of frontier AI models will continue to evolve, driving both innovation and new challenges in cybersecurity. Cisco will continue to adapt and lead in this dynamic environment by leveraging AI-driven insights for our security operations and disclosure practices. Our goal is to empower customers with timely, prioritized, and actionable information, enabling them to strengthen their security posture in an increasingly complex threat landscape.

Cisco will use our voice in the vulnerability disclosure space with the intent of driving pragmatic changes that help the industry align and scale to this expected increase in volume.

Cisco’s Product Security Incident Response Team (PSIRT) remains dedicated to collaborating with customers, researchers, and industry partners to deliver transparent, risk-focused vulnerability disclosures that reflect the realities of AI-enhanced cybersecurity.

Authors

Cisco Cybersecurity Viewpoints

Where security insights and innovation meet. Read the e-book, see the video, dive into the infographic and more...

Why Cisco Security?

Explore our Products & Services