Closing the AI Vulnerability Remediation Gap With Cobalt
The Business of CybersecurityJuly 25, 2026
39
00:27:5525.56 MB

Closing the AI Vulnerability Remediation Gap With Cobalt

In this episode of Business of Cybersecurity, I speak with Gunter Ollmann, CTO at Cobalt, about AI-powered vulnerability discovery, the widening remediation gap, continuous pentesting, legacy application risk, and the future of cybersecurity careers.

Advanced security models such as Mythos can gather and apply techniques published across security research, Black Hat, DEF CON, and other industry sources. Gunter says this makes them particularly effective at reviewing large code bases and trying known attack methods against potential targets.

The result is faster vulnerability discovery, but finding additional weaknesses does not automatically make a company safer. Cobalt’s 2026 State of Pentesting Report found AI and LLM tests produced high risk findings at 2.7 times the rate of its wider data set. According to Cobalt, 32% of AI and LLM findings were rated High Risk, while only 38% were resolved.

Gunter sees two reasons for the gap. Companies are adding AI features to existing applications without fully understanding how the new components affect security. He compares this with the arrival of internet connectivity inside physical equipment, when engineering teams added network stacks without years of experience securing them.

Supplier dependency creates another problem. When a company adds a third party model or AI service to its product, it may lack the ability to correct a weakness directly. Remediation then depends on the supplier’s development priorities and release schedule.

Gunter recommends moving security testing closer to development. The traditional annual penetration test created for compliance is being replaced by a continuous cycle of monthly or quarterly human testing, daily or weekly automated scanning, and remediation connected with development pipelines.

Human participation remains important, but its role is changing. Automation, machine learning, and AI have already removed many Tier 1 positions from security operations centers. The same pattern is appearing in offensive security, where junior pentesters once learned by working alongside experienced practitioners.

Gunter does not see strong evidence that giving a junior analyst an AI tool automatically turns that person into a Tier 2 practitioner. Instead, some organizations are recruiting experienced professionals from IT, product management, or program management and using AI to help them acquire cybersecurity knowledge.

This creates a long term talent problem. Businesses continue competing for senior practitioners while removing the junior roles that historically produced them. The industry therefore needs new ways for inexperienced candidates to learn, practice, receive feedback, and assume responsibility safely.

We also discuss whether faster discovery could overwhelm senior practitioners. Gunter points out that many weaknesses being discovered by AI have existed for years. The technology is improving the industry’s ability to locate and exploit them. Defensive tools are also becoming faster at finding causes, creating fixes, and deploying updates.

The remaining problem is time. If an AI system can find a vulnerability and create an exploit almost simultaneously, companies may have hours rather than weeks to respond. When an immediate code fix is unavailable, detection and blocking technologies may need to provide temporary protection.

His final message is directed at CISOs. AI cannot be treated as a system that receives a problem and operates without supervision. Security leaders need to understand how the technology works, where humans belong in the process, and when human review becomes a delay that attackers can exploit.

Can security teams increase testing and remediation speed while still developing the practitioners they will need in the future? Listen to the episode and share your thoughts with me.

Useful Links

[00:00:00] Your agents aren't producing accurate answers because they don't have a complete semantic understanding of your data. And Denodo is solving this and solving it through semantic consistency. Through semantic consistency, your agents can start making accurate predictions in real time. So see what else Denodo can do by visiting denodo.com to learn more. But now let me introduce you to today's guest.

[00:00:35] What happens when AI can find and exploit vulnerabilities faster than your security teams can fix them? Well, the good news is that defenders never had better tools at their disposal. But the bad news is attackers have access to many of them too. But my guest today is the CTO at Cobalt.

[00:00:58] And he's going to join me to explain why yesterday's medium risk vulnerability could become tomorrow's emergency. And together, we'll explore why AI is quietly removing the first rung from the cybersecurity career ladder. And discuss why every CISO now needs to understand AI well enough to command it rather than simply delegate it. We've got a lot to get through on this episode of Business of Cybersecurity.

[00:01:29] We've got a few surprises in there as well. But enough scene setting for me. Let me introduce you to my guest right now. So thank you for joining me on the show today. Can you tell everyone listening a little about who you are and what you do? So my name is Gunter Oldman. Look, I've been in the cybersecurity space for a long time. It's really hard to describe. But I sort of classed it. I spent most of my career trying to figure out how to be better at the bad guy stuff than the bad guys.

[00:01:59] And in between, I have to sort of figure out how to stop, detect, and stop people like myself. So there's a brief summary. But, you know, I've worn many hats. You know, today I wear a CTO hat. You know, I've worn a CISO hat. And I've worn the hat of having to apologize for many, many events where consultants have got things wrong. Well, I would imagine that that challenge between beating the bad guys, that good guys versus bad guys battle, is even harder now.

[00:02:26] Because recently, of course, Mythos and other advanced AI security models, we quickly learned that they can discover vulnerabilities at extraordinary speed. Speed that neither of us have seen in our lifetime. But what are these systems genuinely good at today? And where do they still fall short compared to experienced security professionals like yourself? Well, I mean, if you take something like Mythos, these frontier models, as they sort of call them, right?

[00:02:53] You know, in many ways, they are very good at distilling, you know, that the entire Internet's worth of knowledge down to something, right? And so what we've been seeing is that these frontier models like Mythos are super efficient at, you know, applying all that security knowledge, all those, you know, mythical techniques, you know, everything that's being published at Black Hat or DEFCON or a major security conference,

[00:03:21] and then effectively trying out all those techniques against these targets. And so what we've seen is that, you know, these tools, which are based on large language models, are really good at things like source code reviews. And so, you know, we've seen this explosion in, you know, discovery of vulnerabilities in large code bases. And that's going to continue for quite some time.

[00:03:47] Problem, though, as I think we're still trying to figure out as an industry how much it costs and, you know, how much is a vulnerability actually worth, you know, investing into to go find it. And one of the reasons I was excited to get you on the podcast today is when your state of the pen testing report set off my tech spidey sensors, when I learned that it had found AI and LLM tests surfaced high-risk findings

[00:04:14] at 2.7 times the rate of the wider data set. But only 38% were resolved. So why is remediation failing to keep pace with vulnerability discovery? It's got to be my first question. And on behalf of every security leader listening to us today, what should they be doing about this? Sure. I mean, I think the numbers reflect two things, right?

[00:04:37] So one, it reflects that these technologies are being bolted on and included in the software, the applications, the products that these companies have been producing for quite some time, and they're still figuring it out. In some ways, it reminds me very much of, you know, 15, 20 years ago, where everyone started, you know, patching on a TCP IP stack onto their physical device.

[00:05:06] And, you know, now we end up with, you know, the IoT and OT type technologies. At that time, you had, you know, engineers, electrical engineers and mechanical engineers strapping on a TCP IP stack and attaching to the internet and trying to figure out, you know, all those vulnerabilities. And so we're seeing the same thing now, right? Where they're dropping in these, you know, NLMs. It does all these fantastic AI features, but they haven't really figured out how the integration really works,

[00:05:34] and it's exposing vulnerabilities and problems that they always had. So that's one side. The second side is because they're bolting on someone else's private technology, when a vulnerability is found, they are dependent on that third party to go fix and resolve these things, right? And so it means that, you know, they are, the timeline for remediating is now dependent on their supplier.

[00:06:02] And, you know, these largest models that they're integrating on and connecting, they're very big and very sophisticated. And perhaps your vulnerability in your application, the way that you've implemented, is a little further down the stack for remediation, you know, or even addressing by those third parties. So there's a lot, you know, to unpack in that space. You know, it will get better, but I think it's probably going to get worse before it gets better because of the volume of these things.

[00:06:29] But, you know, to your second part of the question, you know, what should, you know, the CISOs really be working on? I think there's a couple of areas. So one area is really building out the processes internally for continuous testing and evaluation of these technologies. And, you know, what we're seeing, you know, successful organizations do is that they are building in their penetration testing

[00:06:57] and their remediation of those vulnerabilities into their development pipelines. And instead of, you know, as an industry, we're moving away from this, you know, once a year annual pen test report that's, you know, you flash around for compliance into a continuous cycle of, you know, monthly, quarterly testing and, you know, daily or weekly, you know, automated scanning and remediation.

[00:07:25] I think that's the biggest trends that we've seen, you know, in resolving this. And the third part of that is we're seeing more organizations now flip to having more humans actually involved in the loop. So this, you know, human in the loop has come back, you know, come back stronger than ever. And there's more eyes on glass, as it were, to use, you know, an older term there, to actually inspect the pipelines,

[00:07:52] inspect and evaluate the code that's being written in the integrations. So they're catching these things earlier. And I think there has been a concern that leaders could be tempted to use AI to eliminate entry-level cybersecurity roles. But the flip side of that, thankfully, many are arguing that this could damage the industry's talent pipeline and those entry-level roles there.

[00:08:15] So what are companies misunderstanding about the role that analysts and pen testers of varying levels should play alongside AI? It feels like quite a balance and quite complex on the right thing to do. But how do you see this conundrum? Well, it's actually been a deep concern of mine for over decades. You know, the AI systems that we're talking about today, this trend has been going on for longer than that.

[00:08:40] Whether it was machine learning and classifier systems and all the smart automation, what we've seen is, you know, in this classic term of, you know, three-tier architecture of humans, you know, tier three being your super experienced and tier one, your entry level. You know, for the last 10 years, we've seen, you know, the tier one analysts disappear from security operations centers,

[00:09:04] you know, not because of latest generation of AI, but because of automation, smart automation, and then, you know, machine learning, and now AI is accelerating it. Honestly, I worry very much about what that new career path really looks like. I think the biggest things that we've been seeing have been this trend over the last decade that, you know, every organization now needs to have a CISO.

[00:09:30] The first thing on every CISO's hit list is they need to have a SOC, you know, Security Operations Center. And to make a SOC work, you actually, even to start it up, you need to have senior experienced people on there. And so there is a drawer around the world for that top talent. Meanwhile, you know, that first tier, that evolution of the first tier has gone away. I'm seeing exactly the same thing happening in the offensive security space as well, right?

[00:09:59] So those, you know, junior pen testers, the folks that, you know, if you were doing a pen test, you had a team of five people and you had a couple of, you know, juniors sort of learn the trade. The automated tooling, you know, the latest tools that you run from your laptop or doing your pen test have replaced the need for those folks. Right. And so what does that mean?

[00:10:24] So one angle is that that traditional career path of starting from that junior position and rotating up just honestly does not exist anymore. Right. The technologies around saying that I can have a junior person and I give them access to AI and that elevates them to a tier two. We're not actually seeing that in reality.

[00:10:47] I think it's, it's a story and something that we would like to see, but we're not seeing that. What we're actually seeing is that as those tier threes are becoming rarefied, organizations are looking for other senior and experienced people in other fields. And then giving them those tools, the AI tools to augment them. So they learn the cybersecurity piece instead.

[00:11:16] So we're seeing, you know, professional IT people or product managers or program managers, you know, make that transition to cybersecurity to fill in that gap by augmenting them with the AI systems. So it's, it's very interesting. It honestly worries me a lot. You know, I speak to a lot of CISOs in this space. You know, I think we're all committed to figuring out how we can get more, you know, juniors and help them on that path.

[00:11:45] But that traditional matter, you know, of moving from tier one to tier two to tier three, it feels like that is permanently gone. We have to look for another route in the space. Well, I'm curious if AI does continue to dramatically increase the number of vulnerabilities being discovered. Do you think or could security teams end up less secure because those senior practitioners become overwhelmed with alerts, validation and remediation?

[00:12:12] We already hear stories of burnout in the industry. But what do you see here? Well, certainly burnout is a high factor. What we're seeing in this space. A couple of things there. One is it's not like those vulnerabilities are brand new. Those vulnerabilities have been there from time. We've just become better and better at uncovering the vulnerabilities. And year on year finding newer new techniques of how to locate and actually exploit those vulnerabilities.

[00:12:43] So I think, you know, AI is making that job a lot easier, a lot more efficient. But on the flip side, you know, the ability for in-house security teams and engineering teams to locate the cause of the vulnerability and actually go fix the vulnerability has increased exponentially in pace with that. And so our ability to resolve, you know, fix and roll out fixes has never been better. Right.

[00:13:11] There's still a gap where, you know, the adversarial side plays a key part in there. But I am expecting, you know, and seeing evolution in two ways. Right. So one way is that, you know, if it's in with inside your organization's power to fix, patch or, you know, to again use an old term, you know, virtually patch something.

[00:13:35] Then, you know, the tools are evolving rapidly, you know, and are going to be very, very good in that space. Right. But it brings that to your earlier question. Right. You're dependent on, you know, third party development of third party tools. And so you're dependent on their cycles for remediation and fixing these things. And there, that is a gap still today in the remediation space.

[00:13:58] And so I'm working with a lot of, if you like, some of the traditional players, you know, the IDS, the IPS, the EDR, all these three letter, you know, detect, respond type technologies where they are now becoming, you know, at the forefront of prevention. Right.

[00:14:26] And so, you know, it's now, you know, if these tools are not only finding a vulnerability, but also creating the exploit for that vulnerability at the same time. That, you know, zero day is now today. And so the need to remediate and to, you know, and if you can't remediate, but the ability to block it has now become, you know, prerequisite for success.

[00:14:50] And so that space between exploit availability, you know, and you have to, you know, move from detecting it to blocking it is now shrinking down to, you know, today it's shrinking down to 24 hours, you know, is the ideal space. So a lot of exciting times, a lot of new technologies that have to be built, but workflows are changing.

[00:15:12] And perhaps that brings it back to that question about, you know, the tier one analyst, you know, human in the loop is great for checking and making sure that the processes work, but they're also the speed bump and responding against these threats. Right. And so finding that balance, I think is going to be a continuous yin yang situation. Yeah. As it always has been, I guess. Yeah. I love that analogy of a speed bump of sorts as well. A hundred percent with you there.

[00:15:42] And you are someone with decades of experience reviewing source code. Like right here. It's like, yeah, I'd also found that older, larger applications often contain the most unpleasant security vulnerabilities. What I'm trying to say is this is not your first rodeo. So as companies race to add AI features to those legacy systems, what risks are they unwittingly creating that many security teams could be overlooking?

[00:16:09] You must have a few war stories until you're about throughout your career. Definitely a few war stories. But yes, I mean, the larger the code base, the longer it's taken to develop that tool and technology. It's a bit like, you know, you've inherited a hundred year house. You know, how often do you go into the basement to check the boiler and things like that? Right. There's a lot of things in those sort of cobwebs. And yes, you use that house knowledge.

[00:16:37] You can, you know, update all the windows and all those things. But, you know, the foundations are where a lot of the, you know, with a lot of the changes in the reality is. And I think two things I'll sort of call out. So one is, you know, the larger and the older the applications, the more vulnerabilities there are. And these are not new vulnerabilities. These are vulnerabilities that have always been there.

[00:17:03] In many cases, it's just been difficult to figure out how to exploit them. Right. And, you know, we touched a little bit about, you know, the foundational, you know, the frontier models where they excel is actually figuring out how to chain together lots of vulnerabilities and to navigate that kill chain for exploitation.

[00:17:25] And so what we're seeing in this space, many of those old vulnerabilities may have been classed as low or medium risk because they were no one knew how to exploit them. Now what we're seeing with these models is that I can take three or four of these medium and low risk vulnerabilities, figure out how to chain them to get the full control of the system. So we're seeing that, you know, sort of really sort of grow in this space.

[00:17:51] The flip side of this, though, is, you know, I see it myself, right? So in my company is, you know, 13 years old and the platform has a decade worth of developments. Right. You know, in traditional senses, you would have been talking about, you know, to redevelop that is, you know, a two year mission for 50 engineers, et cetera, et cetera.

[00:18:13] Today, though, you know, I can access that source code that I've written over the last 10 years, get an LLM, you know, a frontier model to understand it, you know, and then draw out what the changes need to be and actually refactor and rebuild the code within weeks. Right. That's not to say, you know, go build a brand new product, but to, you know, you know, instead of me trying to read every line of code, understand why the hell someone made a decision like this, you know, and what this thing connects to.

[00:18:40] So the AI systems are fantastic at that today. Right. And to be able to then pass that through to a smart engineering team, you know, and give them access to those same AI tools means that we're more able to get down to the basement, uncover these things, you know, and start fixing these things than we ever were before. And we're talking about what the good guys are doing here. But on the flip side, attackers are also using AI to find vulnerabilities and operate faster.

[00:19:09] And that's something we're all seeing now. But what practical changes should listeners, especially in companies, what should they be making to their pen testing, their vulnerability management and remediation programs to better keep speed or keep pace with machine speed discovery? Because that's the challenge now, right? Correct.

[00:19:28] I mean, to be clear, you know, the all the pen testing tools that you can get a hold of today, you know, the best ones all have AI in them of some flavor or whatever. And so this is not something new. Right. And that doesn't mean that, you know, today's pen test compared to three years ago, pen test like for like a much better, higher quality and findings because of the tools, you know, and the evolution of folks there.

[00:19:55] So I think the change that we're seeing on the adversarial side, though, is that, you know, these advanced models are very good at finding stuff. But they are very expensive. Right. Right. So when you saw, you know, things like the mythos releases, you know, glass wing programs in this, you're sort of seeing that maybe per vulnerability is maybe $25,000 per vulnerability to go discover. Right.

[00:20:24] You know, on average, and that ignores all the ones that are tried but didn't was unsuccessful. And so the realm for the elite space has become a dollar amount. Right. And so in this space, you know, as an organization, your ability to find the vulnerabilities that your traditional adversary can find is on par. Right. So nothing has really changed on these. Maybe the timing around this has changed.

[00:20:50] But your ability for your adversary with a lot of money to go find the vulnerabilities that you can't find because they have the money to actually find these things has flipped into the adversary sides. Right. But this is organized crime, state actors, you know, and state players that now have access to these types of tools that are better than what the tools that are available for many organizations.

[00:21:17] On the defensive side, you know, I think the key one I called out is that that time between discovery and remediation, you know, and if not remediation to preemptively block has shrunk down to real time. Right. And so organizations need to be thinking about how they move from.

[00:21:41] I think we've spent 20 plus years talking about, you know, we talk about risk and high, medium and low and critical. And we've translated these things one way or the other to say that, you know, a critical vulnerability is you got 24 hours to go fix it, a high risk you have three days, a medium you've got about a month and low risk, yeah, whatever, once a year types. And we've built that into our sort of informal thinking. Now, what we have, though, is that, frankly, anything that's medium and above may be exploited within the next hour.

[00:22:11] Right. As soon as you've learned about this, it may, you know, the tools may be able to exploit. And so that process for understanding, reverse engineering, the vulnerability, reverse engineering, the exploits, building the signature, the detection that has to be rolled out to your multi-land defense now has to become automated and has to be resolved and, you know, in record speed.

[00:22:41] I think that's the part that's changing for media organizations. The other side about, you know, it's a vulnerability in your own codes that could be found. Honestly, it's a little different. You know, those big adversaries with these tools are probably less, they care less about finding vulnerabilities in your specific code because it may only apply to you as opposed to if I'm going to spend that money, I'll find a vulnerability in something that affects many thousands of people. Right.

[00:23:06] And so those vulnerabilities in your codes, you know, you are in more control and you should be still automating your CICD pipelines and rollouts and making those more efficient. But actually, you've got a little bit more time compared to those bigger, broader vulnerabilities in third party software.

[00:23:23] So, and if we do have a CISO listening today who wants to better leverage AI, but do so in a way without weakening their security team or cutting off their future talent pipeline, any actions that you'd advise that they can take now after this podcast and improve security outcomes without, while also developing the next generation of practitioners too? I think one key takeaway is human in the loop is really important. Yeah.

[00:23:53] Right. You've still got a little bit of balance, you know, when does the human loop become their speed bump? Right. But what we're seeing is that, you know, AI is not a point to shoot technology. You can't just say, you know, here's my problem and go figure it out and let it go to this part. Right. The more interaction, the more you learn with your AI systems, the better, more powerful it becomes.

[00:24:16] And, you know, in one way, you know, I think a responsibility to the CISOs is that with all the AI technology, unlike other technologies, the CISO actually has to become a master of this technology, has to truly understand it, and has to be as capable, if not more capable than the tiers below them, which is very different from the past.

[00:24:55] And I think that's a powerful moment to end on. And for anybody listening there wanting to find out about Cobalt, it's quite clear that you are focused on combining talent and technology with speed, scalability and expertise. We covered a lot today, including that report as well.

[00:25:22] For anyone listening wanting to find out more about anything we talked about, where would you like me to point? Well, two ways. So the Cobalt.io website, you know, lots of blogs, lots of releases and things there. And, you know, I'm also broadcasting. So if everyone wants to find me on LinkedIn, then you'll see me pointing to the latest, coolest things that are going out there. Things to worry about, things to, you know, take comfort in and the latest security knowledge. Fantastic.

[00:25:52] I'll include links to everything, including some of your broadcasts as well. I'm going to be checking those out. I'd encourage everyone listening to carry on this conversation. I think it's something that impacts every organization around the world. But thank you for sitting down with me today, bringing it all to life in a language everyone can understand. Really appreciate your time. Thank you for giving me the opportunity, Neil. I think my guest highlighted one of the biggest challenges facing cybersecurity leaders today.

[00:26:17] Yes, AI is helping defenders find vulnerabilities, understand old code and fix problems faster. But it's also giving well-funded attackers the ability to discover and chain weaknesses at machine speed. And I think he also raised an uncomfortable question that the industry cannot afford to ignore. If automation removes junior roles, where will the next generation of experienced security leaders come from?

[00:26:47] And my other big takeaway was his advice for CISOs. AI is no longer something leaders can simply hand to a technical team and hope they do their best. They need to understand it. They need to use it and question it and know when the human in the loop becomes either the last line of defense or just the first line, the speed bump that slows everything down. But I'd love to hear your thoughts. Is AI making your cybersecurity team stronger?

[00:27:15] Or are we creating new risks by automating away the people who would be tomorrow's experts? Let me know. TechTalksNetwork.com. Lots for you to look at there. Meet me on the road at an event or send me an audio message. But thank you for listening today. And I'll be back again real soon on the Business of Cybersecurity podcast.