Cognition、Devin を活用した脆弱性対策プログラムを発表
本文の状態
日本語全文を表示中
詳細モードで約3分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
Cognition Engineering
Cognition Engineering は、AI ソフトウェアエンジニア「Devin」をセキュリティチームに埋め込み、脆弱性の発見から修正まで自動化するプログラムを開始すると発表した。
AI深層分析を開く2026年8月4日 12:51
AI深層分析
キーポイント
2 つの柱によるアプローチ
既存の脆弱性バックログ解消と、従来のスキャナが見逃す論理欠陥などの継続的発見・修復を並行して行う体制を整える。
6 週間の標準プログラム構成
初期調査から優先順位付け、Devin の設定、大規模な修正実行、そして組織全体への展開計画策定までを約 6 ヶ月で完了させる。
既存ツールとの統合機能
Snyk や SonarQube など既存のスキャナからのレポートを取り込み、Devin が検証してプルリクエストを作成する仕組みを提供する。
アカウントチームによるプログラムのカスタマイズ
アカウントチームが対象者の資格を確認し、優先事項に合わせてプログラムを調整する。
問い合わせ先の提供
詳細については公式の連絡先ページを通じて問い合わせが可能である。
重要な引用
Attackers are using AI to discover, chain, and exploit vulnerabilities faster than traditional remediation programs can respond.
Cognition's forward-deployed engineering team embeds with yours and deploys Devin, the AI software engineer, to find, validate, and fix vulnerabilities.
Your account team can confirm eligibility and tailor the program to your priorities.
Get in touch
編集コメントを表示
編集コメント
AI エージェントがセキュリティ運用の現場に直接投入される事例は、実用化の速度を示す重要な指標である。企業側では、Devin の導入によりセキュリティチームとエンジニアリングチームのリソース配分がどう変化するかに注目する必要がある。
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
Cognition チーム 2026年7月2日
攻撃者は AI を活用し、従来の対策プログラムでは対応しきれないスピードで脆弱性を発見・連鎖させ、悪用しています。同時に、セキュリティチームが検出した問題の数は、エンジニアリングチームが安全に修正できる範囲を超えています。
「Devin セキュリティ脆弱性修復プログラム」は、組織が蓄積した脆弱性のバックログを解消し、継続的な修復体制を整えるためのものです。Cognition のフォワード・デプロイされたエンジニアリングチームが貴社のチームに常駐し、AI ソフトウェアエンジニアの Devin を導入して、脆弱性の発見、検証、修正を行います。
プログラムの仕組み
このプログラムは、2 つの柱を軸に構成されています。1 つ目は現在の脆弱性バックログの解消、2 つ目は継続的な発見と修復体制の確立です。
最初のフェーズでは、Devin が既知の脆弱性を大規模に解決します。スキャナからのレポートを取り込み、修正パッチをプルリクエストとして提出し、それぞれを検証します。2 番目のフェーズでは、「Devin Security Swarm」を導入し、従来のスキャナが見過ごしがちなロジック上の欠陥、不安全なパターン、連鎖する問題点を継続的に発見できるようにします。
これらは厳格な順序のフェーズではなく、柱です。優先事項に応じて並行して実行することも、段階的に進めることも可能です。多くの契約期間は約 6 週間程度です。
典型的なプログラムは以下のような構成になります。最初の 2 週間で、高リスクなアプリケーションの棚卸しを行い、対象範囲と優先順位を調整し、Devin の設定を行います。また、修正ワークフローのマッピングも完了させます。
3〜4 週間目には、最も優先度の高いリポジトリに対して大規模な修正を実施します。同時に、PR(プルリクエスト)の処理速度やマージ率、バックログ削減の効果などをモニタリングします。
5〜6 週間目に入ると、初期の結果を基に Devin の対応能力を見積もり、組織全体での広範な展開計画を最終確定させます。
期待できる効果
- 受動的から能動的なセキュリティへ。無数のアラートに対応するのではなく、最も重要な課題を継続的に発見し、検証して修正できるようになります。
- スキャナーの見落としを埋める。Devin は、ビジネスロジックの欠陥や文脈依存型の攻撃経路など、スキャナーが捉えきれない脅威を発見・検証・修正し、インシデント化する前に封じ込めます。
- エンジニアリングリソースの確保。本来ならプロダクトロードマップからエンジニアを奪うことになる修正作業を任せることで、セキュリティチームが自ら修正を主導できる体制を整えます。
Devin は、チームがすでに利用しているシステムにスムーズに組み込まれます。既存のスキャナー(Snyk、SonarQube、Checkmarx、Semgrep、Wiz、Veracode など)からレポートを取得し、それを検証した上で PR を作成します。
Devin Cloud を実規模で導入するエンタープライズ顧客で、プログラムの技術要件と参加条件を満たす場合は参加可能です。既存顧客でも条件に合致すれば登録できます。アカウントチームが資格確認を行い、貴社の優先事項に合わせてプログラムをカスタマイズいたします。
お問い合わせはこちらから
原文を表示
By The Cognition Team07.02.26
Attackers are using AI to discover, chain, and exploit vulnerabilities faster than traditional remediation programs can respond. At the same time, security teams already have more findings than engineering teams can safely fix.
The Devin Security Vulnerability Remediation Program helps organizations clear their vulnerability backlog and set up continuous remediation. Cognition's forward-deployed engineering team embeds with yours and deploys Devin, the AI software engineer, to find, validate, and fix vulnerabilities.
How the program works
The program is built around two pillars: clearing today's vulnerability backlog, then establishing ongoing discovery and remediation.
In the first phase, Devin resolves known vulnerabilities at scale—ingesting scanner reports, shipping fixes as PRs, and validating each one. In the second, we set up Devin Security Swarm to continuously discover the logic flaws, insecure patterns, and chainable issues traditional scanners miss.
These are pillars, not rigid phases—they can run in parallel or phased based on your priorities. Most engagements land around six weeks.
A typical program looks like this: in weeks one and two, we inventory high-risk applications, align on scope and priorities, configure Devin, and map remediation workflows. In weeks three and four, we execute remediation at scale on the highest-priority repositories and monitor PR velocity, merge rates, and backlog reduction. In weeks five and six, we use initial results to forecast Devin capacity and finalize a broad rollout plan across the org.
What you can expect
- Moving from reactive to proactive security. You can shift from triaging endless alerts to continuously finding, validating, and fixing the issues that matter most.
- Closing the gaps scanners miss. Devin helps uncover, validate, and remediate threats like business logic flaws and context-dependent exploit paths before they become breaches.
- Returning engineering capacity. You can delegate remediation work that would otherwise pull engineers away from the product roadmap, and empower your security teams to drive fixes themselves.
Devin fits into the systems your teams already use. It ingests reports from your existing scanners—Snyk, SonarQube, Checkmarx, Semgrep, Wiz, Veracode, and others—validates, and then creates PRs.
Enterprise customers deploying Devin Cloud at meaningful scale who meet the program's technical and engagement requirements can participate. Existing customers who meet the criteria can also enroll. Your account team can confirm eligibility and tailor the program to your priorities.
AI算出
主要ニュースainew評価高い
Cognition が AI コーディングエージェント「Devin」をセキュリティチームに組み込む新たなビジネスモデルと技術的アプローチ(バックログ解消と継続的発見の 2 つの柱)を発表しており、AI エージェントの実装事例として新規性が高い。ただし、日本企業固有の情報や日本語一次情報がないため、日本の文脈での関連性は限定的となる。
6つの評価軸を見る
- AI関連度
- 75
- 情報源の信頼性
- 100
- 新規性
- 75
- 調べる価値
- 75
- 重複の少なさ
- 100
- 日本での有用性
- 25
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み