AI-powered vulnerability scanners can now find tens of thousands of flaws in a matter of weeks. That sounds like a breakthrough until you look at the other number: the patch rate is under one percent. So are these frontier models a genuine game changer, or just the latest round of marketing built on fear, uncertainty, and doubt?
In this episode, Jeffrey Wheatman, Bob Maley, and Ferhat Dikbiyik pressure-test the hype around tools like Project Glasswing and the new class of AI scanners. They dig into why discovery has raced ahead of remediation, why throwing AI at the end of the process may be solving the wrong problem, and where these tools actually earn their keep today versus where the marketing gets ahead of reality. Along the way they get into prioritization, explainability, and the uncomfortable question of what happens when you can find far more than you could ever fix.
In this episode, you will learn:
- Why the real story is the gap between vulnerabilities discovered and vulnerabilities patched
- Where AI genuinely helps today, from discovery and attack chaining to triage
- Why shifting these tools earlier in the development cycle may matter more than faster remediation
- How to cut through vendor AI claims using explainability as your filter
- Why prioritization, not patching everything, is the only way out of the deluge
- What security leaders should expect from these tools over the next year
If you have ever wondered whether the AI vulnerability hype is signal or noise, this conversation gives you a framework to tell the difference.