2 Sources
[1]
Sophos to Integrate OpenAI GPT Cyber Models to Verify Real-World Exploit Paths
Sophos announced Exploit Path Verification (EPV), a new capability that will be built into Sophos Managed Risk to help security teams better prioritize Security teams face a widening gap between the vulnerabilities they can find and the ones they can fix. Scanners surface thousands of exposures and severity scores and rank them, but a severity score cannot tell whether a critical flaw sits behind a control that blocks it, or whether two low-severity findings chain into the path that leads to a breach. As a result, security teams often patch by generic score, rather than by whether an attacker could reach and use a flaw in their specific environment. Sophos is designing EPV to close that gap. It is being built to reason over asset and patch state, endpoint protection policy, network reachability, identity and privilege facts, and known exploit availability, and returns a clear evidence-backed exploitability verdict: "One of the most common challenges we hear from security teams today is the volume of findings they need to sift through, and the lack of clarity of which findings matter most, or in other words, put them at greatest risk," said John Peterson, chief technology officer, Sophos. "Exploit Path Verification is being built to make it clear what in their environment is reachable by an attacker, with the evidence to prove it, so they fix what counts first." EPV extends Sophos' work with OpenAI. Through the OpenAI Daybreak Defense Network (formerly OpenAI Daybreak Cyber Partner Program), which Sophos joined in June 2026, the company brought frontier cyber models into MDR investigation, advisory assessments, and workflows that help customers discover, validate, and remediate exposure. EPV will build on that work inside a product customers already run. OpenAI's GPT cyber models provide frontier reasoning to help assess exploitability. Sophos supplies the environment-specific evidence and product controls, and its analysts review the results delivered to customers. "Our goal through the OpenAI Daybreak Defense Network is to give defenders the advantage of frontier AI, safely," said McCall McIntyre, Head of Global Cyber Partnerships, OpenAI. "Sophos has been a thoughtful partner since joining the program, and Exploit Path Verification is a clear example of frontier reasoning applied to a real defensive problem, with the guardrails that responsible deployment demands." Sophos defends more than 625,000 organizations worldwide, including 40,000 managed detection and response (MDR) customers across enterprise, mid-market, and commercial segments, delivered through one of the industry's largest partner ecosystems. That reach is central to EPV's purpose. Verified exploitability should not be a capability reserved for the largest security teams with the deepest budgets. EPV is in development for enterprise and mid-market business customers of Sophos Managed Risk. Sophos will announce availability, including early access and general availability timing, at a later date.
[2]
Sophos to bring OpenAI GPT cyber models into managed risk offering, helping defenders validate exploit paths
The company is building a new Exploit Path Verification (EPV) capability that will tell security teams which vulnerabilities an attacker can reach in their environment, turning long exposure lists into evidence-backed priorities Sophos today announced Exploit Path Verification (EPV), a new capability that will be built into Sophos Managed Risk to help security teams better prioritize and manage exploitable vulnerabilities in their environment. The capability will be built with OpenAI's GPT cyber models through the Daybreak Defense Network, to return verified, evidence-backed verdicts that give defenders the clarity they need to fix the exposures that matter first. Availability will be announced at a later date. Security teams face a widening gap between the vulnerabilities they can find and the ones they can fix. Scanners surface thousands of exposures and severity scores and rank them, but a severity score cannot tell whether a critical flaw sits behind a control that blocks it, or whether two low-severity findings chain into the path that leads to a breach. As a result, security teams often patch by generic score, rather than by whether an attacker could reach and use a flaw in their specific environment. Sophos is designing EPV to close that gap. It is being built to reason over asset and patch state, endpoint protection policy, network reachability, identity and privilege facts, and known exploit availability, and returns a clear evidence-backed exploitability verdict: * Confirmed Exploitable * Blocked by a Control * Not Reachable * Insufficient Evidence EPV will also be designed to identify chained paths where multiple lower-severity findings combine into one exploitable route, assess whether a control blocks a technique class or only a common public proof of concept, and draft remediation text ready for a ticket. The capability will be advisory and additive by design. Every verdict is labeled as AI-generated with its evidence visible, and Sophos analysts review the results. "One of the most common challenges we hear from security teams today is the volume of findings they need to sift through, and the lack of clarity of which findings matter most, or in other words, put them at greatest risk," said John Peterson, chief technology officer, Sophos. "Exploit Path Verification is being built to make it clear what in their environment is reachable by an attacker, with the evidence to prove it, so they fix what counts first." EPV extends Sophos' work with OpenAI. Through the OpenAI Daybreak Defense Network (formerly OpenAI Daybreak Cyber Partner Program), which Sophos joined in June 2026, the company brought frontier cyber models into MDR investigation, advisory assessments, and workflows that help customers discover, validate, and remediate exposure. EPV will build on that work inside a product customers already run. OpenAI's GPT cyber models provide frontier reasoning to help assess exploitability. Sophos supplies the environment-specific evidence and product controls, and its analysts review the results delivered to customers. "Our goal through the OpenAI Daybreak Defense Network is to give defenders the advantage of frontier AI, safely," said McCall McIntyre, Head of Global Cyber Partnerships, OpenAI. "Sophos has been a thoughtful partner since joining the program, and Exploit Path Verification is a clear example of frontier reasoning applied to a real defensive problem, with the guardrails that responsible deployment demands." Sophos defends more than 625,000 organizations worldwide, including 40,000 managed detection and response (MDR) customers across enterprise, mid-market, and commercial segments, delivered through one of the industry's largest partner ecosystems. That reach is central to EPV's purpose. Verified exploitability should not be a capability reserved for the largest security teams with the deepest budgets. EPV is in development for enterprise and mid-market business customers of Sophos Managed Risk. Sophos will announce availability, including early access and general availability timing, at a later date.
Share
Copy Link
Sophos unveiled Exploit Path Verification, an AI-powered capability built with OpenAI GPT cyber models for Sophos Managed Risk. The tool helps security teams validate which vulnerabilities attackers can actually reach in their environment, addressing the challenge faced by over 625,000 organizations that struggle to prioritize thousands of vulnerability findings.

Sophos announced Exploit Path Verification (EPV), a new capability being developed for Sophos Managed Risk that leverages OpenAI GPT cyber models to help security teams identify which vulnerabilities in their environment are genuinely exploitable by attackers
1
2
. The AI-powered capability addresses a critical gap security teams face: while vulnerability scanning tools surface thousands of exposures with severity scores, these scores cannot determine whether a critical flaw sits behind protective controls or whether multiple low-severity findings chain into an exploitable route1
.EPV is designed to reason over multiple data points including asset and patch state, endpoint protection policy, network reachability, identity and privilege facts, and exploit availability
2
. The system returns evidence-backed verdicts in four categories: Confirmed Exploitable, Blocked by a Control, Not Reachable, or Insufficient Evidence2
. This approach moves security teams away from patching by generic severity scores toward fixing vulnerabilities that attackers can actually reach and exploit in their specific environment1
. The capability will also identify chained exploit paths where multiple lower-severity findings combine into one exploitable route, assess whether controls block entire technique classes or only common public proofs of concept, and draft remediation text ready for ticketing systems2
.The development extends Sophos' partnership with OpenAI through the Daybreak Defense Network, which Sophos joined in June 2026
1
. OpenAI GPT cyber models provide frontier reasoning to assess exploitability, while Sophos supplies environment-specific evidence and product controls2
. Every verdict is labeled as AI-generated with visible evidence, and Sophos analysts review results before delivery to customers, ensuring responsible deployment with necessary guardrails2
. "Our goal through the OpenAI Daybreak Defense Network is to give defenders the advantage of frontier AI, safely," said McCall McIntyre, Head of Global Cyber Partnerships at OpenAI1
.Related Stories
"One of the most common challenges we hear from security teams today is the volume of findings they need to sift through, and the lack of clarity of which findings matter most, or in other words, put them at greatest risk," said John Peterson, chief technology officer at Sophos
2
. Sophos defends more than 625,000 organizations worldwide, including 40,000 managed detection and response (MDR) customers across enterprise, mid-market, and commercial segments1
. EPV is being developed specifically for enterprise customers and mid-market customers of Sophos Managed Risk, ensuring verified exploitability becomes accessible beyond organizations with the largest security budgets2
. Sophos will announce availability, including early access and general availability timing, at a later date1
.Summarized by
Navi
07 Aug 2026•Technology

22 Jun 2026•Technology

01 Jun 2026•Technology

1
Technology

2
Policy and Regulation

3
Technology
