Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Tuesday, 16 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

AI-Powered Attackers Force Security Teams to Rethink Speed of Response

by Guru Writer
June 16, 2026
in AI and Machine Learning, News
AI Appreciation Day: Celebrating Progress, Embracing Responsibility
Share on FacebookShare on Twitter

Security teams are facing a new and accelerating threat: attackers armed with sophisticated AI models that can chain together multiple application vulnerabilities into fully formed exploits within minutes. That is the stark reality underpinning a raft of new capabilities announced today by Black Duck for its Polaris Platform.

The company is positioning the enhancements around what it calls ‘Mythos readiness,’ a reference to advanced AI models now being used by threat actors. The urgency is not theoretical. Black Duck reports that Polaris scan volumes more than doubled in the first five months of 2026 alone, as organisations scrambled to keep pace with the threat landscape.

“The window between vulnerability discovery and exploitation has collapsed, turning software risk into an immediate and potentially existential business risk,” said Dipto Chakravarty, Chief Product & Technology Officer at Black Duck. The company says its goal is to shift organisations from slow, manual remediation cycles towards what it describes as a VulnOps model, fast, automated vulnerability operations.

Closing the gaps that attackers exploit

A key thrust of the update is eliminating blind spots in application security testing. Black Duck’s own audit data suggests that most teams are tracking only about half of the open source software they actually use, leaving unpatched components as easy targets for AI-powered attacks.

New capabilities in the Polaris fAST SCA tool now extend to full binary and container analysis, alongside source and package manager detection, enabling teams to generate complete Software Bills of Materials (SBOMs). The platform also introduces continuous source code management (SCM) monitoring, meaning every repository and branch is automatically tracked and tested, including so-called shadow AI projects that may have been started without security oversight.

Event-driven static analysis (SAST) and software composition analysis (SCA) testing can now be triggered automatically on pull requests and merges, with results fed directly back to developers as pull request comments to speed up remediation.

Bracing for the vulnerability flood

Perhaps the most alarming projection in Black Duck’s announcement is around the sheer volume of vulnerabilities expected in the coming years. As open source maintainers increasingly use AI to find and patch flaws in widely used components, the number of new vulnerability disclosures is expected to exceed 50,000 in 2026, potentially rising to nearly 200,000 by 2028.

To help teams cope, Polaris now layers reachability analysis with exploitability data from Black Duck Security Advisories and CISA’s Known Exploited Vulnerabilities catalogue to help organisations go beyond raw CVSS scores and prioritise the vulnerabilities that pose the greatest genuine risk. New automated fix pull requests allow high-priority vulnerabilities to be fast-tracked for remediation, keeping a human in the loop for final approval before any code change is merged.

AI working for the defender

The update also brings AI capabilities directly into developer workflows. A new AI False Positive Detection feature delegates the research and de-prioritisation of false positive findings to a built-in agent drawing on Black Duck’s ContextAI model, reducing noise for security analysts.

A new Polaris MCP server allows teams using agentic coding tools, including Claude Code and GitHub Copilot, to query Polaris scan results, prioritisation data, and remediation guidance using Model Context Protocol, integrating security insight directly into AI-assisted development pipelines.

The latest Code Sight IDE plug-in update, meanwhile, enables developers to access AI-based security analysis and apply one-click code fixes from within their existing development environment, powered by Black Duck Signal.

ShareTweet
Previous Post

US Tech Dependence Is Becoming a Data Security Risk; and Consumers Are Waking Up to It

Recent News

AI Appreciation Day: Celebrating Progress, Embracing Responsibility

AI-Powered Attackers Force Security Teams to Rethink Speed of Response

June 16, 2026
US Tech Dependence Is Becoming a Data Security Risk; and Consumers Are Waking Up to It

US Tech Dependence Is Becoming a Data Security Risk; and Consumers Are Waking Up to It

June 16, 2026
Hackers Hijack Terminal Server to Launch 8.9 Million-Email Boots Phishing Campaign

Hackers Hijack Terminal Server to Launch 8.9 Million-Email Boots Phishing Campaign

June 16, 2026
The AI Boom Is an Energy Boom: Kelcy Warren on How Data Centers Are Reshaping Natural Gas Demand

The AI Boom Is an Energy Boom: Kelcy Warren on How Data Centers Are Reshaping Natural Gas Demand

June 16, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol