Skip to main content

Share story

Security AI

AWS releases instructions for evidence-based AI vulnerability triage

AWS releases instructions for evidence-based AI vulnerability triage Image: Primary
AWS released a steering file that directs AI coding assistants to verify code paths before reporting vulnerabilities and to incorporate deployment controls into security priorities. The persistent instructions require confirmed functions, call paths and data flows rather than accepting a model's narrative as evidence. AWS says verification eliminated fabricated paths in its testing. In a purpose-built application containing ten known vulnerabilities, the configured model found nine and documented why two infrastructure-mitigated findings deserved lower priority. It omitted a hardcoded credential defined in unused unit-testing code. AWS describes the confidence weights as a starting point that teams should calibrate against their own labeled findings.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from AWS Security Blog and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Science Security
Science Security

Preprint finds sensitive-topic leakage in AI model routing logs

Researchers report in a preprint that logs recording which AI model handles a request can expose sensitive-topic patterns even when content logging is disabled. Their studies used 1.7 million real requests and tested systems that ...

Products Security
Products Security

Databricks makes user-scoped app authorization generally available

Databricks made on-behalf-of-user authorization generally available for apps that access supported platform APIs. Apps can now act with a signed-in user's identity, letting Unity Catalog enforce existing data permissions, row filt...

Security AI
Security AI

Cloudflare opens early beta of AI-assisted security investigations

Cloudflare says an early beta of its multi-agent investigation system is available in Managed Defense for eligible application-security alerts and cases. The system assembles evidence, links related alerts and recommends next step...

AI Products
AI Products

Anthropic releases Haiku 5.5 and halves Sonnet 5.5 cache-read prices

Anthropic released Claude Haiku 5.5 on its developer platform, Amazon Web Services, Google Cloud and Microsoft Azure, and cut Sonnet 5.5 cache-read prices by 50%, from $0.20 to $0.10 per million tokens. Haiku 5.5 adds adjustable e...