返回新聞
安全性AI Understanding 簡報

Cognizant 警告人工智慧加速漏洞發現但修復滯後

Cognizant 全球網路安全負責人表示,人工智慧正在加速識別網路缺陷,但企業卻難以足夠快地修補這些缺陷,造成了越來越大的風險差距。

4 min readRead the linked source
Source-provided image accompanying Cognizant warns AI speeds vulnerability discovery but remediation lags
來源參考來源記錄
出版商
newindianexpress.com
來源連結
newindianexpress.comhttps://www.newindianexpress.com/business/2026/Sep/28/ai-speeds-up-vulnerability-discovery-but-enterprises-struggle-to-fix-risks-cognizant
來源類型
連結來源-主要來源狀態尚未確定。
背景60 秒內了解這一點

從這裡開始

關鍵術語

人工智慧(AI)
建構執行需要模式識別、推理、語言或決策的任務的系統的廣泛領域。
及時注射
一種攻擊模式,其中惡意指令被插入到模型輸入或檢索的內容中。
提示
提供給生成模型的輸入指令和上下文。
測試一下自己人工智慧道德測驗

發生了什麼事

Cognizant’s global cybersecurity head Vishal Salvi told The New Indian Express that artificial intelligence is now enabling enterprises to discover cyber‑security vulnerabilities at “machine‑speed,” but the remediation process remains constrained by traditional business cycles, testing procedures and operational bottlenecks. Salvi described the situation as a “machine‑speed offence versus calendar‑speed defence,” noting that the gap between detection and fix is widening. He also warned that AI itself is becoming a new attack surface, with risks tied to models, prompts, agents and autonomous actions. While AI tools are already being used for vulnerability discovery, threat detection and incident investigation, Salvi emphasized that final decisions still require human judgement. He projected that the next major shift will be applying AI to remediation, helping organisations prioritise, validate and resolve vulnerabilities more quickly. Salvi highlighted a broader move from pure vulnerability management toward “exposure management,” where the focus is on reducing overall risk exposure rather than fixing individual flaws. For AI agents, he said enterprises are treating them as digital employees, applying zero‑trust principles, identity controls and runtime monitoring to curb potential misuse.

In a recent interview with The New Indian Express, Vishal Salvi, Cognizant’s global head of cybersecurity, explained that AI tools now enable organisations to scan codebases, configurations and network assets far faster than manual methods. He cited the ability of AI to correlate disparate signals, reduce noise and surface hidden relationships between vulnerabilities, technical debt and software dependencies.

Despite these advances, Salvi said that the remediation side remains hampered by legacy processes. Business approvals, testing cycles, and operational constraints often stretch the time needed to deploy patches from days to weeks, creating a “calendar‑speed defence” that lags behind the “machine‑speed offence” of AI‑driven discovery.

Salvi also warned that AI introduces its own security challenges. Models, prompts, and autonomous agents can become new vectors for exploitation if they are granted excessive permissions or lack robust safeguards. He highlighted the need for identity management, zero‑trust controls and continuous runtime monitoring for AI agents, treating them as digital employees rather than static tools.

Looking ahead, Salvi predicts that AI will not only discover vulnerabilities but also assist in remediation—prioritising fixes, validating patches and even automating certain remediation steps. However, he stressed that ultimate decision‑making must remain human‑led to ensure accountability and governance.

來源詳情: newindianexpress.com ↗

為什麼這很重要

The interview underscores a pivotal tension in the AI era: while AI can dramatically accelerate the discovery of security weaknesses, the slower pace of remediation can leave organisations exposed to attacks that exploit newly identified flaws. This dynamic has practical implications for any enterprise that relies on large, complex IT stacks, especially those that have accumulated technical and security debt. If remediation cannot keep up, the speed advantage of AI may paradoxically increase overall risk, as attackers can also leverage AI‑driven tools to exploit unpatched vulnerabilities. Salvi’s remarks also flag the emergence of AI‑specific attack vectors—such as malicious prompts or rogue agents—that extend traditional threat models. Understanding these new vectors is essential for policymakers and security teams as they craft guidelines for responsible AI deployment. Moreover, the shift toward exposure management suggests a strategic re‑orientation that could influence budgeting, staffing and vendor selection across the cybersecurity industry.

The speed disparity between AI‑driven detection and slower remediation creates a window of heightened exposure that attackers can exploit, especially as AI tools become more widely available to both defenders and adversaries.

AI‑specific attack surfaces—such as malicious or rogue autonomous agents—expand the traditional threat landscape, requiring new security controls, policy frameworks, and audit mechanisms.

The shift toward exposure management reflects a broader industry trend to assess risk holistically rather than patching individual flaws, which could reshape how security budgets are allocated and how success is measured.

If AI‑assisted remediation does not materialise as promised, enterprises may face escalating costs and reputational damage from repeated breach incidents, underscoring the urgency of developing practical, scalable solutions.

Interactive Mechanism

互動機制:它實際上是如何運作的

以互動方式探索這項發展背後的基礎技術。

Agent Lifecycle Stage:
1
User Intent & Planning: "Audit customer refund request #4092 and settle payment."
2
Tool Calling: Emits structured JSON call crm_get_transaction(id='4092').
3
Guardrail & Verification:🛡️ Paused: High-value action requires human operator sign-off.
4
Final Settlement: Refund recorded, email receipt dispatched, and audit log stored.
Core takeaway: An AI agent is not just a language model—it is a closed loop of planning, tool invocation, and environment feedback. Production systems require self-healing retries and strict human approval guardrails.
互動式概念檢查+10 Points
AI Ethics Quiz

Why can ethical evaluation not be reduced to one model score?

接下來看什麼

Key indicators to monitor include: (1) adoption rates of AI‑assisted remediation platforms and any measurable reductions in patch‑time metrics; (2) emergence of industry standards or regulatory guidance addressing AI‑driven attack surfaces, especially around model and agent governance; (3) reports of incidents where AI agents with excessive permissions cause operational disruptions; and (4) corporate announcements of zero‑trust frameworks specifically extended to AI agents. Tracking these developments will reveal whether the promised AI‑accelerated remediation gains materialise and how quickly enterprises can close the detection‑remediation gap.

Vendor announcements of AI‑powered remediation suites and any disclosed metrics showing reduced mean‑time‑to‑patch (MTTP).

Regulatory bodies releasing guidelines or standards for AI model security, hygiene, and agent governance.

Incident reports where AI agents with over‑privileged access cause data leaks, service disruptions, or other operational harms.

Adoption of zero‑trust architectures that explicitly incorporate AI agents, including identity‑as‑a‑service (IDaaS) solutions tailored for autonomous systems.

相關指引和測驗

AI 倫理人工智慧代理AI 的未來測試你所知道的—嘗試免費的人工智慧測驗在我們的詞彙表中尋找人工智慧術語關注AI監管追蹤器
覺得有用嗎?