en.Wedoany.com Reported - As the number of vulnerabilities continues to rise and the remediation window keeps shrinking, Cisco is adjusting its vulnerability disclosure strategy. The company believes that artificial intelligence, while accelerating vulnerability discovery, may also increase the volume of alerts security teams need to handle, thereby introducing new challenges.

Cisco stated that the company is shifting to a risk-based disclosure strategy, focusing on issues that are being actively exploited or have a high probability of exploitation. Russ Smoak, Cisco's Vice President of Information Security, noted: "Cisco is actively leveraging advanced AI models to accelerate vulnerability discovery and drive remediation. Deploying these models into our security processes allows us to find and fix vulnerabilities at unprecedented speed." He also pointed out that attackers will similarly utilize these evolving AI technologies, further increasing the difficulty and urgency of cybersecurity defense.
Under the new strategy, the handling of low-risk issues has also changed. Cisco indicated that some internally discovered vulnerabilities that would have previously warranted individual advisories may no longer be disclosed separately. The company plans to instead provide overview information on software versions containing security patches, guiding users to prioritize adopting security-hardened versions. Specific code change details regarding these issues may be published at some point after the initial version release.
For issues classified as high-severity, findings that are actively exploited, and vulnerabilities with a high probability of exploitation, Cisco will maintain its detailed disclosure process. The company added that vulnerability handling procedures for third-party and open-source components will remain unchanged. Smoak concluded: "Cisco will lend our voice in the vulnerability disclosure space, aiming to drive pragmatic change and help the industry coordinate and adapt to the anticipated volume growth."
This article is compiled by Wedoany. All AI citations must indicate the source as "Wedoany". If there is any infringement or other issues, please notify us promptly, and we will modify or delete it accordingly. Email: news@wedoany.com










