Productspublished

Sophos Builds AI Feature to Check Whether Vulnerabilities Are Actually Exploitable

The planned Managed Risk feature would combine customer environment data with OpenAI cyber models, shifting vulnerability triage from generic severity scores toward evidence of an attack route. Sophos has not set an early-access or general-availability date.

By 3 min read
Sophos Builds AI Feature to Check Whether Vulnerabilities Are Actually Exploitable
Sophos Builds AI Feature to Check Whether Vulnerabilities Are Actually Exploitable

Listen to this story

The audio brief

About 1:33
0:001:33
Read transcript
Sophos is building a feature that could change how security teams decide which vulnerabilities deserve attention first. Called Exploit Path Verification, or EPV, it is planned for Sophos Managed Risk and would use OpenAI’s GPT cyber models to assess whether a flaw can actually lead to compromise in a specific customer environment. The key shift is from generic severity scores to evidence about an attack route. EPV would examine whether an asset is reachable, what network and endpoint controls are active, which privileges and identities are involved, whether the system is patched, and whether attackers have a known exploit. It would also look for chains in which several lower-severity weaknesses combine into a usable path. The proposed results are straightforward: Confirmed Exploitable, Blocked by a Control, or Not Reachable or Insufficient Evidence. Sophos says the system should distinguish a control that blocks an entire technique from one that stops only a public proof of concept. It would also draft remediation language for a ticket. This is not meant to be an autonomous verdict engine. Each result will be labeled AI-generated, include supporting evidence, and be reviewed by Sophos analysts. The feature is aimed at enterprise and mid-market Managed Risk customers, not standalone scanner users. Sophos joined OpenAI’s Daybreak Defense Network in June, but testing and launch dates remain undisclosed. The important question is whether that evidence, plus human review, proves reliable enough to change patch priorities when EPV becomes available.

Story brief

3 key points

Sophos is developing Exploit Path Verification (EPV), a planned addition to Managed Risk that uses OpenAI’s GPT cyber models to assess whether vulnerabilities can produce an attack path in a specific customer environment. It will consider reachability, controls, privileges, patch state, and known exploits, including chains of lower-severity flaws. Verdicts will include supporting evidence and human analyst review,...

  1. 01

    EPV is aimed at enterprise and mid-market Sophos Managed Risk customers, not standalone scanner users.

  2. 02

    Proposed verdicts include Confirmed Exploitable, Blocked by a Control, and Not Reachable or Insufficient Evidence.

  3. 03

    The system is designed to distinguish broad technique-blocking controls from defenses that stop only a public proof of concept.

Sophos is building a feature that would judge whether a vulnerability is actually exploitable in a customer’s environment, rather than asking security teams to prioritize fixes mainly by severity score. Exploit Path Verification, or EPV, is planned for Sophos Managed Risk and will use OpenAI GPT cyber models through the Daybreak Defense Network.

The distinction is central to the product’s pitch. A scanner can surface a critical flaw without establishing whether network controls prevent an attacker from reaching it. It can also miss the practical danger created when several lower-severity findings connect into one route to a breach. Sophos is positioning EPV as a way to rank work by the conditions in a particular environment, not by a generic score alone.

EPV is designed to reason over asset and patch state, endpoint-protection policy, network reachability, identity and privilege information, and the availability of known exploits. It would then return an evidence-backed verdict. The intended workflow turns a broad inventory of flaws into a narrower question: can an attacker get from this weakness to a usable outcome here?

  • Confirmed Exploitable: the feature’s proposed finding when the available evidence supports an exploitable path.
  • Blocked by a Control: the proposed finding when a control prevents the path from working.
  • Not Reachable or Insufficient Evidence: proposed findings for weaknesses an attacker cannot reach or cases where the system cannot support a conclusion.

The feature is also intended to look beyond isolated findings. Sophos says it will identify chained paths, where multiple lower-severity issues combine into an exploitable route. It is also being designed to distinguish a control that blocks a whole technique class from one that stops only a common public proof of concept, then draft remediation text suitable for a ticket.

Sophos is keeping people in the decision loop. Every EPV verdict will be marked as AI-generated and show its evidence, while Sophos analysts review the results delivered to customers. That design makes the model an advisory layer over the managed-risk service, rather than an autonomous system that silently declares a vulnerability safe or urgent.

The rollout extends an existing connection between the companies. Sophos joined OpenAI’s Daybreak Defense Network in June, according to Sophos, and OpenAI separately lists Sophos among its technology partners in the Daybreak Cyber Partner program. OpenAI says the program lets approved partners put its cyber models into security products, services and customer engagements, with access to the underlying models retained by the partner rather than passed directly to customers.

OpenAI describes Daybreak as a route for bringing cyber models into established defensive operations, including vulnerability validation and remediation. Its safeguards can include identity verification, defined testing scopes, logging, monitoring and human oversight. Those constraints matter when a model is being used to reason about exploit paths: the same details that help defenders validate risk are sensitive security information.

For now, the immediate boundary is narrow. EPV is in development for enterprise and mid-market Sophos Managed Risk customers, and Sophos has not disclosed when those customers can test it. The consequential question at launch will be whether the evidence and analyst review make its exploitability calls reliable enough to change which patches security teams tackle first.

Sources

  1. markets.businessinsider.comSophos To Bring OpenAI GPT Cyber Models Into Managed Risk Offering, Helping Defenders Validate Exploit Paths
  2. openai.comPutting frontier cyber models in more trusted hands