All posts

Proofpoint ships 35-second exploit protection for zero-days

Huma ShaziaAugust 3, 2026 at 3:32 AM4 min read
Proofpoint ships 35-second exploit protection for zero-days

Proofpoint launched Active Exploits Protection on July 28, a system that converts observed exploit activity into network-wide defenses in roughly 35 seconds, with full propagation in under 18 minutes. The product targets the shrinking window between vulnerability disclosure and active exploitation, a gap the company says has collapsed from years to hours as AI models accelerate exploit discovery.

Proofpoint ships 35-second exploit protection for zero-days
Source: TahawulTech.com

The core pitch: patching cannot keep pace with machine-speed threats. Active Exploits Protection sidesteps the patch cycle by layering detection and blocking across email and network paths, drawing from Proofpoint's telemetry across 3 million organizations and 14,000 large enterprises.

Advertisements

What does Active Exploits Protection actually do?

The product monitors Proofpoint's global sensor network, which spans over 5,000 endpoints and processes more than 2 billion emails daily. When that network detects exploit activity against a vulnerability, the system automatically generates and pushes protective rules to customers. Proofpoint claims 99.999% detection precision.

Four capabilities anchor the release. First, it prioritizes vulnerabilities based on observed attacker behavior rather than CVSS severity scores. Second, it translates exploit intelligence into protection in approximately 35 seconds. Third, it exposes that intelligence via APIs for integration with SOC tools and automation pipelines. Fourth, it provides a foundation for AI-driven security workflows that reduce manual triage.

12 vs 8
Proofpoint says it has identified 12 actively exploited 2026 CVEs year-to-date, compared to 8 currently listed in CISA's Known Exploited Vulnerabilities catalog.

Why the patch cycle no longer works

Proofpoint's argument rests on a timing mismatch. Frontier AI models can now discover software vulnerabilities autonomously, compressing the window between disclosure and weaponization. In some cases, attacks begin before public tracking frameworks like CISA's KEV catalog reflect the risk.

"The speed at which threats are evolving has fundamentally changed the risk equation," said CEO Sumit Dhawan. "It's no longer enough to identify vulnerabilities. Organisations need to understand what attackers are exploiting in real time and reduce their exposure immediately."

The company positions this as an escape from "vulnerability overload." Fewer than 6% of all disclosed vulnerabilities are ever observed being exploited in real-world attacks, yet security teams face thousands of critical-rated alerts. Active Exploits Protection filters that noise by grounding prioritization in actual attacker behavior.

Also Read
Nvidia forms 40-firm AI security alliance after agent breach

Industry context on how AI is reshaping security vendor strategies

Advertisements

The gap between claim and proof

Proofpoint's 35-second-to-protection claim is impressive if validated. The company has not released independent benchmarks or third-party audits of that latency. The 99.999% precision figure also lacks published methodology. Security teams evaluating the product should request customer references and false-positive data before committing.

Pricing and packaging were not disclosed. The product is available globally via integrated platform capabilities and API access, but whether it requires an existing Proofpoint subscription or sells standalone remains unclear.

Where this fits in the stack

Active Exploits Protection is not a replacement for vulnerability management or endpoint detection. It layers on top, feeding intelligence into existing SOC tools and automation pipelines like Zapier or n8n for teams building custom security workflows. The API access positions it as a data source for AI-driven security operations, not a standalone platform.

ℹ️

Disclosure

Some links in this post are affiliate links — Logicity earns a commission if you sign up, at no extra cost to you. We only link products we have used or actively recommend.

ℹ️

Logicity's Take

For AI product teams shipping agents that handle external inputs, Proofpoint's framing matters more than its product. If frontier AI models can discover vulnerabilities in hours, every team shipping code becomes a target. Active Exploits Protection is one vendor's answer, but the real question is whether your security posture assumes days-to-patch or hours-to-exploit. That assumption should inform every infrastructure decision.

The product is available now. Whether it delivers on the latency claims will depend on real-world deployment data that Proofpoint has not yet published.

ℹ️

Need Help Implementing This?

If you're evaluating security tooling for AI-driven infrastructure, reach out to our team at Logicity for architecture reviews and vendor comparisons.

Source: TahawulTech.com / Daniel Shepherd

H

Huma Shazia

Senior AI & Tech Writer

Produced with AI assistance and reviewed by the Logicity editorial team. Learn more in our Editorial Policy.