Sophos Will Build Exploit Path Verification in Managed Risk
2 companies named across 2 categories, one of 62 articles referencing OpenAI. Previous coverage: Proofpoint Introduces SOC Analyst Agent With OpenAI Daybreak Models (Sep 2026).
Sophos said it will build Exploit Path Verification (EPV) as a capability within Sophos Managed Risk to help security teams determine which vulnerabilities an attacker can reach in their environment. The effort addresses a gap between what scanners surface and what teams can prioritize to fix.
In the current workflow described in the release, scanners can produce thousands of exposures and severity scores, but those scores do not indicate whether a flaw is blocked by a control or whether low-severity findings combine into a path that enables exploitation. EPV was designed to support prioritization based on exploitability in the specific environment.
EPV is being built to reason over asset and patch state, endpoint protection policy, network reachability, identity and privilege facts, and known exploit availability. It returns an exploitability verdict labeled as one of: Confirmed Exploitable, Blocked by a Control, Not Reachable, or Insufficient Evidence.
According to the release, EPV will be used to identify chained paths where multiple lower-severity findings form an exploitable route, assess whether a control blocks a technique class or only a public proof of concept, and draft remediation text for a ticket. Sophos said it will build EPV with OpenAI’s GPT cyber models through the Daybreak Defense Network, and Sophos analysts will review results. John Peterson, chief technology officer, Sophos, said, “One of the most common challenges we hear from security teams today is the volume of findings they need to sift through, and the lack of clarity of which findings matter most, or in other words, put them at greatest risk,” and added, “Exploit Path Verification is being built to make it clear what in their environment is reachable by an attacker, with the evidence to prove it, so they fix what counts first.”
Press release, provided by Globe Newswire on behalf of Sophos. Read the original.