Full Metal Packet Cybersecurity Podcast

Why Top Security Teams Deliberately Leave Vulnerabilities Unpatched | Paul Bleicher


Listen Later

Paul Bleicher is Co-Founder and Chief Product Officer at Convo, building agentic vulnerability triage for security teams drowning in scanner noise.

After a decade as an early employee across security and dev-tool startups, Paul and his co-founders spent two months interviewing 100+ security leaders before landing on the problem: most CVEs flagged by scanners are never actually exploitable.

What we cover in this EP:

◼ Why 70-90% of vulnerabilities flagged by scanners are false positives, and how reachability vs. exploitability analysis separates real risk from noise

◼ How agentic AI systems investigate CVEs like a security analyst — building exploitability checklists, orchestrating deterministic tools, and guarding against prompt injection

◼ Why large enterprises' compliance processes can slow AI adoption at the exact moment attackers are moving faster than ever

◼ The audit/compliance angle: how AI-generated exploitability reports help satisfy regulators when vulnerabilities go unpatched

◼ Paul's advice to every security leader: use an LLM 5-10 times a day or risk falling behind entirely

(00:00) – Meet Paul Bleicher, Co-Founder & CPO of Convo

(00:56) – Why Paul started his own company after 12 years as an early employee

(01:54) – The pivot: from ownership mapping to vulnerability triage

(03:42) – Reachability vs. exploitability explained

(08:21) – False positives on false positives: the limits of reachability

(10:16) – The CVE arms race and thousands of vulnerabilities per day

(13:29) – What “agentic” actually means vs. AI marketing buzzwords

(15:22) – Prompt injection risk: securing an AI system that reads your codebase

(19:13) – Noise vs. context: solving triage in the right order

(20:11) – “Don’t worry about it, bro” — the reality of unfixed critical vulnerabilities

(23:33) – Convo’s real numbers: how many alerts are actually exploitable

(26:27) – AI writes the code, AI finds the bugs, AI has to fix them

(28:45) – Startups vs. enterprises: who’s better equipped to survive?

(33:21) – The gap between security leaders who use AI daily and those who don’t

(37:09) – What to tell boardrooms still afraid of AI in 2026

(41:18) – What CISOs should stop doing today

(42:17) – What CISOs should start doing tomorrow

(44:41) – Closing thoughts and where this is all heading

Guest ⬇️

Paul Bleicher: https://www.linkedin.com/in/paulbleicher/

Hosts ⬇️

Yegor Sak: https://www.linkedin.com/in/yegor-sak-725330b2/

Alex Paguis: https://www.linkedin.com/in/alex-paguis-53a21815/

Powered by Control D

...more
View all episodesView all episodes
Download on the App Store

Full Metal Packet Cybersecurity PodcastBy Control D