Urgent.News

What's breaking now, across thousands of outlets.

AI

Cyber risk management redefined through AI-speed detection and zero-day remediation

As many organizations struggle to survive by rebuilding their cyber risk management with expediency in mind, Frontier AI is turning newly discovered vulnerabilities into usable weapons within hours. According to Sumedh Thakar (pictured), president and chief executive officer at Qualys, this need to compress the window between vulnerability discovery and weaponization is a sentiment he […] The…

Cyber risk management redefined through AI-speed detection and zero-day remediation

In the rapidly evolving landscape of cyber risk management, Frontier AI is redefining the approach by accelerating detection and remediation of vulnerabilities. Sumedh Thakar, president and CEO of Qualys, emphasized this need at Black Hat 2026, stating that the gap between vulnerability discovery and weaponization poses a significant challenge for organizations.

Thakar proposed a three-pronged solution: AI-speed detection, hyper-prioritization via exploit validation, and zero-day autonomous remediation to address this issue in hours.

Qualys' agentless scanning capability, combined with an AI governance platform called TotalAI, plays a pivotal role in this process. The company's exploit validation mechanism involves sending harmless payloads to identified vulnerabilities to determine whether defenses can block the attack. If a DNS resolution is successful, it confirms the vulnerability is exploitable, elevating it in the remediation queue.

This validation, coupled with an AI-generated patch reliability score, gives security teams the confidence to deploy autonomous patches without the fear of system outages.

Thakar highlighted the shift in AI governance from blocking shadow AI to understanding its presence. He stressed that organizations lacking shadow AI problems might actually have a business problem, indicating underutilization of AI. Qualys' TotalAI platform provides security teams with visibility into AI model usage, tests for inappropriate outputs, monitors data usage for training, and aids in setting policies for sanctioned AI infrastructure.

A key innovation discussed was the Risk Operations Center (ROC), which consolidates various cyber risks—cloud risk, identity risk, misconfiguration risk, and vulnerability risk—into a single, normalized view. This integration maps technical findings against business context and translates them into financial terms that executives can understand.

Thakar likened this to purchasing car insurance, where understanding the value of the asset and the associated risk is crucial. By providing a clear, dollar-value exposure assessment, the ROC addresses the fragmented dashboard issue faced by CISOs, enabling them to answer critical queries about potential financial loss for a business unit.

Written by urgent.news from SiliconANGLE's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at siliconangle.com →

More in AI

More from Friday 7 August →