MALAYSIA, 8 SEPTEMBER 2026 – Global cybersecurity firm Sophos has announced Exploit Path Verification (EPV), a new capability integrated into its Sophos Managed Risk service designed to help security teams manage critical vulnerabilities across their digital infrastructure.
Developed using OpenAI’s GPT cyber models through the Daybreak Defense Network, EPV delivers verified, evidence-backed verdicts that enable security defenders to identify and resolve high-priority exposures.
Modern security teams face an increasing volume of detected system exposures that often outpace their capacity to deploy patches. Traditional scanning tools assign severity ratings based on generic scores, which frequently fail to account for existing internal controls or complex exploit chains where multiple low-severity flaws combine into an active breach route.
EPV addresses this gap by analyzing system components, including asset and patch states, endpoint protection policies, network reachability, identity privileges, and known exploit availability. The tool generates evidence-backed verdicts across four categories: Confirmed Exploitable, Blocked by a Control, Not Reachable, and Insufficient Evidence.
In addition to categorizing risk levels, EPV identifies chained attack paths, assesses whether existing security controls block specific technique classes, and drafts ready-to-use remediation instructions for ticketing platforms. The capability operates as an advisory feature, labeling all outputs as AI-generated, displaying underlying evidence, and routing results through Sophos analysts for manual review.
John Peterson, Chief Technology Officer at Sophos, stated that security teams frequently struggle to navigate vast volumes of security alerts. He highlighted that Exploit Path Verification was created to provide clarity on reachable attack vectors within an organization’s environment, backed by concrete evidence.
This release expands Sophos’ ongoing collaboration with OpenAI, following its entry into the OpenAI Daybreak Defense Network in June 2026. Under this architecture, OpenAI’s GPT cyber models handle underlying reasoning capabilities, while Sophos provides environment-specific data, product controls, and expert analyst oversight.
McCall McIntyre, Head of Global Cyber Partnerships at OpenAI, noted that the initiative applies frontier AI reasoning to practical defensive challenges while maintaining necessary deployment guardrails.
Sophos protects over 625,000 organizations globally, including 40,000 Managed Detection and Response customers. EPV is currently in development for enterprise and mid-market business customers using Sophos Managed Risk, with general availability timelines to be announced at a later date.
