Reports
AI-generated structured vendor updates
OpenAI and Anthropic Jointly Push 30-Day Federal Review for Frontier AI Models
OpenAI and Anthropic propose a 30-day federal review for frontier AI models before release, citing security risks. The August 1 deadline defines coverage thresholds, sparking a policy battle between closed-source advocates and open-source supporters including NVIDIA, Meta, and Microsoft. Chinese open models GLM-5.2 and Kimi K3 are central to the debate.
Zscaler报告显示企业100%存在未治理AI暴露面
...
Microsoft's Project Perception Automates Vulnerability Remediation with Multi-Model AI Orchestration
In response to competitors like Anthropic and Palo Alto, Microsoft's Project Perception leverages multi-model AI orchestration to automate vulnerability discovery and remediation. This product signifies a transition from manual security operations to autonomous self-healing systems, with control shifting from security analysts to an AI-driven platform.
Microsoft July Patch Tuesday Hits Record 622 CVEs, AI Infrastructure Vulnerabilities Emerge as New Attack Surface
Microsoft's July 2026 Patch Tuesday addresses a record 622 CVEs, including three critical AI vulnerabilities: Copilot RCE (CVSS 9.6), Azure OpenAI EoP (CVSS 9.9), and M365 Copilot EoP (CVSS 9.3). The attack surface expands from OS to AI service infrastructure, signaling an era of AI-driven vulnerability inflation.
CrowdStrike Integrates Claude Compliance API, Bringing AI Agent Monitoring into SOC
CrowdStrike integrates Anthropic's Claude Compliance API into its Falcon platform, enabling unified monitoring of Claude AI activities alongside endpoint, identity, and cloud telemetry. This formalizes AI agent security as a standard SOC function, reflecting the industry-wide shift of security budgets towards specialized vendors.
Active Exploitation of CVE-2026-0257: GlobalProtect VPN Authentication Bypass Threatens Enterprise Networks
Palo Alto Networks confirms active exploitation of CVE-2026-0257 in GlobalProtect VPN. Attackers exploit shared certificates between HTTPS and authentication override to forge cookies, impersonating admins. CISA added to KEV. Urgent upgrade or dedicated cookie encryption certificate recommended.
Cisco AI Orders Surge to $9B, but SD-WAN Zero-Day for Third Year Reveals Systemic Security Gap
Cisco Q3 FY2026 raises AI infra order target to $9B, yet a CVSS 10.0 authentication bypass zero-day in SD-WAN Controller (CVE-2026-20182) is exploited by the same APT for the third consecutive year. This reveals a systemic gap in Cisco's security engineering as it pivots to AI, and a fundamental flaw in SD-WAN control plane architecture.
CISA Agentic AI Security Deployment Guide: Government Framework Reshapes Enterprise AI Procurement Standards
...
In-depth Analysis of CISA Agentic AI Security Guidelines
CISA released the world's first Agentic AI security deployment guidelines on May 1, 2026, marking a critical transition from theoretical discussions to mandatory compliance requirements.
Cisco Report Links EOL Device Vulnerabilities to AI Infrastructure Needs
Cisco Talos report shows 40% of high-threat vulnerabilities target EOL devices, with policy mandates driving forced retirement. This links infrastructure modernization directly to AI security deployment, providing compliance basis for network updates.
Check Point AI Factory Blueprint: Security Control Shifts to NVIDIA DPU and LLM Layer
Check Point unveils AI Factory Security Blueprint, tightly integrating its firewall with NVIDIA BlueField DPU via DOCA. The architecture enforces security at four layers: LLM, AI infrastructure, perimeter, and workload. The new AI Factory Firewall delivers hardware-accelerated threat prevention without consuming CPU/GPU cycles, aiming to embed security into the AI fabric.