Cisco is evolving its vulnerability disclosure practices in response to AI-driven changes in the cybersecurity landscape. The company is shifting to a risk-based model that prioritizes detailed technical disclosures for high-risk, actively exploited, or critical vulnerabilities. For internally discovered lower-severity issues, Cisco may reduce standalone advisory detail and instead direct customers to security-hardened releases. Practices for third-party and open-source component vulnerabilities remain unchanged for high-severity issues. Cisco is also using AI to accelerate vulnerability discovery and remediation internally, while acknowledging adversaries will leverage the same capabilities.
Table of contents
Harnessing AI to Enhance CybersecurityPrioritizing Risk to Empower CustomersUpdating the Disclosure Cycle for Lower Severity VulnerabilitiesMaintaining Our Commitment to Third-Party and Open-Source CodeLooking Ahead: The Future of AI and CybersecuritySort: