Sophos has announced Exploit Path Verification (EPV), a new capability being developed for its Sophos Managed Risk service to help security teams determine which vulnerabilities are actually exploitable in their environments.
EPV will use OpenAI’s GPT cyber models through the OpenAI Daybreak Defense Network to assess factors including asset and patch status, endpoint protection policies, network reachability, identity and privilege information, and known exploit availability. It will classify findings as Confirmed Exploitable, Blocked by a Control, Not Reachable, or Insufficient Evidence.
The capability is also being designed to identify attack paths where multiple lower-severity vulnerabilities can be chained together, and provide remediation recommendations. Sophos said each verdict will include supporting evidence and will be reviewed by its security analysts.
“Exploit Path Verification is being built to make it clear what in their environment is reachable by an attacker, with the evidence to prove it, so they fix what counts first,” said John Peterson, chief technology officer, Sophos.
The capability builds on Sophos’ work with OpenAI through the Daybreak Defense Network, which the cybersecurity company joined in June 2026. Sophos said OpenAI’s GPT cyber models will provide the reasoning used to assess exploitability, while Sophos will supply environment-specific data and controls and have analysts review the results.
“Our goal through the OpenAI Daybreak Defense Network is to give defenders the advantage of frontier AI, safely,” said McCall McIntyre, head of global cyber partnerships, OpenAI. “Exploit Path Verification is a clear example of frontier reasoning applied to a real defensive problem, with the guardrails that responsible deployment demands.”
Sophos said EPV is currently in development for enterprise and mid-market customers of Sophos Managed Risk. Availability and early-access details will be announced later.