From Findings to Fixes: AI Alone Isn’t Enough
At Black Hat USA 2026, Scott Kuffer, CPO and Co-founder at Nucleus Security, explores one of the most pressing questions facing cybersecurity teams today: How will AI actually change vulnerability management, and where are organizations getting it wrong?
While much of the industry focuses on “fighting AI with AI,” Scott argues that the real challenge isn’t simply finding more vulnerabilities or deploying autonomous remediation agents. Instead, organizations must address the operational bottlenecks that prevent vulnerabilities from being fixed at scale.
Key Points in the Speaking Session
In his session, Scott examines how the vulnerability management landscape is evolving as AI accelerates software development, increases the volume of internally developed applications, and shifts the industry away from a world dominated by publicly disclosed CVEs.
He explains why traditional vulnerability discovery approaches are becoming less effective, how organizations can adapt to an environment with growing numbers of unique, privately created vulnerabilities, and why remediation workflows deserve far more attention than they currently receive.
Key discussion topics include:
- Why the “AI vulnerability explosion” narrative misses the larger operational challenge
- How shrinking exploit windows are impacting vulnerability programs
- The growing importance of managing vulnerabilities in custom-built and AI-generated software
- Why vulnerability discovery without remediation delivers little security value
- Building scalable vulnerability management pipelines through automation and orchestration
- Where AI can provide meaningful value in remediation workflows and where traditional automation remains the better choice
- How security teams can align with engineering and executive stakeholders to drive measurable risk reduction
Rather than advocating for an AI-first approach, Scott presents a practical framework for combining AI capabilities with proven automation techniques to improve vulnerability response, reduce mean time to remediation (MTTR), and deliver outcomes that security leaders, engineering teams, and boards can understand.
Watch this session to learn how leading organizations can move beyond vulnerability discovery and build remediation programs that scale in the age of AI.