Can AI stop cyberattacks before developers patch the code?

Terra says its new Prevention feature creates and tests WAF and firewall rules for verified exploits, aiming to give security teams a temporary, targeted block while developers work on permanent fixes across web, cloud and app systems

Terra Security said Tuesday it launched Prevention, a new feature in its Terra Platform designed to help security teams block confirmed exploits while longer-term code fixes are still in progress.
The company said the tool generates specific web application firewall, or WAF, and firewall rules after Terra confirms that a vulnerability can be exploited. The rules are then tested against the exploit before being handed to security teams for implementation.
Terra co-founders Shahar Peled and Gal Malachi
Terra co-founders Shahar Peled and Gal Malachi
Terra co-founders Shahar Peled and Gal Malachi
(Photo: Tammy Montag for Mayko Studio)
Terra said the feature is meant to address a common gap in penetration testing, in which reports often end with broad mitigation recommendations that do not tell teams exactly what rule to write or whether it would stop the attack in question.
“Finding an exploitable risk is only half the job,” said Gal Malachi, co-founder and chief technology officer at Terra Security. “The hardest part is the stretch between proving it and fixing it, and adversaries can now exploit vulnerabilities in minutes. Traditional mitigation guidance from a pentest is generic and no one acts on it. Prevention is different.”
According to the company, Prevention first checks whether a customer’s existing controls can stop a specific attack path. If they cannot, Terra’s platform generates a targeted WAF or firewall rule and validates it against the confirmed exploit. Sensitive production changes remain subject to human oversight, Terra said.
The launch comes as companies face pressure to respond faster to vulnerabilities, even as permanent fixes often depend on development cycles, release schedules and change-management approvals.
Terra describes its platform as an AI-native offensive security system that uses trained AI agents, with human supervision, to find, validate and support remediation of exploitable vulnerabilities across websites, AI systems, internal applications, APIs, mobile systems, networks and cloud environments.
The company said its customers include Fortune 500 organizations. It did not disclose financial details related to the new feature.
Comments
The commenter agrees to the privacy policy of Ynet News and agrees not to submit comments that violate the terms of use, including incitement, libel and expressions that exceed the accepted norms of freedom of speech.
""