{"data":{"id":"a4e3d06d-3130-4e4a-bcbe-501b1aeb1434","title":"Building your AI vulnerability harness, Part 1","summary":"This post describes a three-layer pipeline that narrows raw vulnerability scanner findings to a small, prioritized set with documented evidence of exploitability. It frames the approach as a test harness that constructs and runs tests for each candidate finding, using AI-augmented analysis to reason across files and deployment context where pattern-matching SAST tools fall short. The first layer uses multi-scanner agreement, and the source says confidence rises when two or more scanners converge on the same finding.","solution":"N/A -- no mitigation discussed in source.","labels":["industry","security"],"sourceUrl":"https://aws.amazon.com/blogs/security/building-your-ai-vulnerability-harness-part-1/","publishedAt":"2026-10-07T21:49:43.000Z","cveId":null,"cweIds":null,"cvssScore":null,"cvssSeverity":null,"severity":"info","attackType":[],"issueType":"news","affectedPackages":null,"affectedPackageNames":null,"affectedVendors":[],"affectedVendorsRaw":["AWS Cloud Development Kit (AWS CDK)","AWS CloudFormation"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":null,"epssScore":null,"epssCheckedAt":null,"kevDateAdded":null,"advisoryAliases":null,"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":null,"disclosureDate":"2026-10-07T21:49:43.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":null,"aiComponentTargeted":null,"llmSpecific":false,"classifierConfidence":0.7,"researchCategory":null,"atlasIds":null}}