Vega 推出了 Vega II,这是其从隐身状态亮相以来最大的平台发布。此次更新将面向安全运营的前沿人工智能引入 SOC(安全运营中心),为团队提供持久的学习记录,并消除了阻碍关键信息获取的传统 SIEM(安全信息和事件管理)和数据管道壁垒。
借助 Vega II,每个安全团队都拥有了网络防御的“ harness”(核心框架):这是一个 AI 自主执行检测、分类和调查的系统,由团队中最优秀的防御人员的判断力引导,并覆盖所有此前被迫排除在 SIEM 之外的数据源。
“人工智能让攻击者抢占了先机。但这并不意味着他们必须赢得未来。”Vega CEO Shay Sandler 表示,“两年前,我们创立 Vega 基于一个坚定的信念:SOC(安全运营中心)迎来了新的操作员——AI 智能体,它们需要你的所有数据、你最优秀防御人员的知识与判断力,以及一个经过后训练以适用于代理式网络防御的模型。通过 Vega II,每个团队终于拥有了赢得这场战斗所需的框架、模型和速度。”
为何是现在
敌对势力在前沿模型发布的当周就会采用。而防御者却只能依靠从未针对网络防御进行过优化的推理能力、案件关闭时丢失的事实,以及被连接器(connectors)和数据管道项目所阻挡的数据。通用人工智能速度缓慢:它在每个警报上都从头开始推理,而攻击者却在不断移动。智能体无法运用其从未具备的专业知识进行推理,无法应用其从未学到的内容,也无法调查其无法触及的目标。打破阻碍前沿人工智能成为卓越网络防御的壁垒,下一个时代将属于防御者。
为战斗而构建的框架与模型
代理式网络防御(Agentic Cyber Defense)需要专为特定目的构建的模型、对环境的持久记忆以及对所有存储数据的访问权限。借助 Vega II,团队可以:
将专门的 AI 推理能力带入战斗:Vega 的首个模型经过后训练以适用于代理式网络防御,与前沿情报在平台中并行运行。为了速度而构建:当通用人工智能仍在思考时,它已得出判决,因此每个警报都能获得专家级的解读,其规模是任何团队依靠人力都无法实现的。
让每堂课的经验持久留存:Vega Memory 捕获环境的真实情况和已采取的行动,使每次判决都从团队已有的知识出发。工程师可以检查、追踪并控制哪些内容被保存。
访问所有数据:Vega Gateway 通过 OpenTelemetry、Webhook 或 API 将任何数据源流式传输至低成本的对象存储中,无需复杂的管道或传统连接器。它将 Vega 的即时分析能力扩展到那些无处安放的数据源,只需几分钟即可上线,使调查能够跟随攻击者的足迹,到达 SIEM 从未触及的地方。
Vega has introduced Vega II, its biggest platform release since emerging from stealth. The update brings frontier AI trained for security operations into the SOC , gives teams a lasting record of what they have learned, and removes the legacy SIEM and data pipeline barriers that have kept vital information out of reach.
With Vega II, every security team has the harness for cyber defense: the system where AI runs detection, triage, and investigation as an autonomous loop, directed by the judgment of their best defenders, and spanning every source they were forced to keep out of the SIEM.
“AI gave attackers a head start. It doesn’t have to give them the future,” said Shay Sandler , CEO of Vega. “Two years ago, we founded Vega on one conviction: the SOC has a new operator, AI agents, and they need all your data, the knowledge and judgment of your best defenders, and a model post-trained for agentic cyber defense. With Vega II, every team finally has the harness, the model, and the speed to win the fight.”
Why now
Adversaries adopt frontier models the week they ship. Defenders answer with reasoning never tuned for cyber defense, facts lost when the case closes, and data held behind connectors and pipeline projects. And generic AI is slow: it reasons from scratch on every alert while the attacker keeps moving. An agent can’t reason with expertise it never had, apply what it never learned, or investigate what it can’t reach. Break the barriers keeping frontier AI from becoming extraordinary cyber defense, and the next era belongs to the defenders.
The harness and the model, built for the fight
Agentic Cyber Defense demands a purpose-built model, lasting memory of the environment, and access to all data wherever it is stored. With Vega II, teams can:
Bring specialized AI reasoning to the fight: Vega’s first model, post-trained for agentic cyber defense, runs beside frontier intelligence in the platform. Built for speed: it reaches the verdict while generic AI is still thinking, so every alert gets an expert’s read at a scale no team can staff.
Make every lesson last: Vega Memory captures the environment’s ground truth and actions taken, so each verdict starts from what the team already knows. Engineers inspect, trace, and control what gets saved.
Access all data: Vega Gateway streams any source into low-cost object storage over OpenTelemetry, webhook, or API, without complex pipelines or legacy connectors. It extends Vega’s in-place analytics to the sources with nowhere to live, onboarded in minutes, so investigations follow attackers where the SIEM never looked.
首次收录 · 2026-09-30 · 7.48 分