Closing the AI Vulnerability Remediation Gap With Cobalt
The Business of CybersecurityJuly 25, 2026
39
00:27:5525.56 MB

Closing the AI Vulnerability Remediation Gap With Cobalt

In this episode of Business of Cybersecurity, I speak with Gunter Ollmann, CTO at Cobalt, about AI powered vulnerability discovery, the widening remediation gap, continuous pentesting, legacy application risk, and the future of cybersecurity careers.

Advanced security models such as Mythos can gather and apply techniques published across security research, Black Hat, DEF CON, and other industry sources. Gunter says this makes them particularly effective at reviewing large code bases and trying known attack methods against potential targets.

The result is faster vulnerability discovery, but finding additional weaknesses does not automatically make a company safer. Cobalt’s 2026 State of Pentesting Report found AI and LLM tests produced high risk findings at 2.7 times the rate of its wider data set. According to Cobalt, 32% of AI and LLM findings were rated High Risk, while only 38% were resolved.

Gunter sees two reasons for the gap. Companies are adding AI features to existing applications without fully understanding how the new components affect security. He compares this with the arrival of internet connectivity inside physical equipment, when engineering teams added network stacks without years of experience securing them.

Supplier dependency creates another problem. When a company adds a third party model or AI service to its product, it may lack the ability to correct a weakness directly. Remediation then depends on the supplier’s development priorities and release schedule.

Gunter recommends moving security testing closer to development. The traditional annual penetration test created for compliance is being replaced by a continuous cycle of monthly or quarterly human testing, daily or weekly automated scanning, and remediation connected with development pipelines.

Human participation remains important, but its role is changing. Automation, machine learning, and AI have already removed many Tier 1 positions from security operations centers. The same pattern is appearing in offensive security, where junior pentesters once learned by working alongside experienced practitioners.

Gunter does not see strong evidence that giving a junior analyst an AI tool automatically turns that person into a Tier 2 practitioner. Instead, some organizations are recruiting experienced professionals from IT, product management, or program management and using AI to help them acquire cybersecurity knowledge.

This creates a long term talent problem. Businesses continue competing for senior practitioners while removing the junior roles that historically produced them. The industry therefore needs new ways for inexperienced candidates to learn, practice, receive feedback, and assume responsibility safely.

We also discuss whether faster discovery could overwhelm senior practitioners. Gunter points out that many weaknesses being discovered by AI have existed for years. The technology is improving the industry’s ability to locate and exploit them. Defensive tools are also becoming faster at finding causes, creating fixes, and deploying updates.

The remaining problem is time. If an AI system can find a vulnerability and create an exploit almost simultaneously, companies may have hours rather than weeks to respond. When an immediate code fix is unavailable, detection and blocking technologies may need to provide temporary protection.

His final message is directed at CISOs. AI cannot be treated as a system that receives a problem and operates without supervision. Security leaders need to understand how the technology works, where humans belong in the process, and when human review becomes a delay that attackers can exploit.

Can security teams increase testing and remediation speed while still developing the practitioners they will need in the future? Listen to the episode and share your thoughts with me.