
Sign up to save your podcasts
Or


Paul Bleicher is Co-Founder and Chief Product Officer at Convo, building agentic vulnerability triage for security teams drowning in scanner noise.
After a decade as an early employee across security and dev-tool startups, Paul and his co-founders spent two months interviewing 100+ security leaders before landing on the problem: most CVEs flagged by scanners are never actually exploitable.
What we cover in this EP:
◼ Why 70-90% of vulnerabilities flagged by scanners are false positives, and how reachability vs. exploitability analysis separates real risk from noise
◼ How agentic AI systems investigate CVEs like a security analyst — building exploitability checklists, orchestrating deterministic tools, and guarding against prompt injection
◼ Why large enterprises' compliance processes can slow AI adoption at the exact moment attackers are moving faster than ever
◼ The audit/compliance angle: how AI-generated exploitability reports help satisfy regulators when vulnerabilities go unpatched
◼ Paul's advice to every security leader: use an LLM 5-10 times a day or risk falling behind entirely
(00:00) – Meet Paul Bleicher, Co-Founder & CPO of Convo
(00:56) – Why Paul started his own company after 12 years as an early employee
(01:54) – The pivot: from ownership mapping to vulnerability triage
(03:42) – Reachability vs. exploitability explained
(08:21) – False positives on false positives: the limits of reachability
(10:16) – The CVE arms race and thousands of vulnerabilities per day
(13:29) – What “agentic” actually means vs. AI marketing buzzwords
(15:22) – Prompt injection risk: securing an AI system that reads your codebase
(19:13) – Noise vs. context: solving triage in the right order
(20:11) – “Don’t worry about it, bro” — the reality of unfixed critical vulnerabilities
(23:33) – Convo’s real numbers: how many alerts are actually exploitable
(26:27) – AI writes the code, AI finds the bugs, AI has to fix them
(28:45) – Startups vs. enterprises: who’s better equipped to survive?
(33:21) – The gap between security leaders who use AI daily and those who don’t
(37:09) – What to tell boardrooms still afraid of AI in 2026
(41:18) – What CISOs should stop doing today
(42:17) – What CISOs should start doing tomorrow
(44:41) – Closing thoughts and where this is all heading
Guest ⬇️
Paul Bleicher: https://www.linkedin.com/in/paulbleicher/
Hosts ⬇️
Yegor Sak: https://www.linkedin.com/in/yegor-sak-725330b2/
Alex Paguis: https://www.linkedin.com/in/alex-paguis-53a21815/
Powered by Control D
By Control DPaul Bleicher is Co-Founder and Chief Product Officer at Convo, building agentic vulnerability triage for security teams drowning in scanner noise.
After a decade as an early employee across security and dev-tool startups, Paul and his co-founders spent two months interviewing 100+ security leaders before landing on the problem: most CVEs flagged by scanners are never actually exploitable.
What we cover in this EP:
◼ Why 70-90% of vulnerabilities flagged by scanners are false positives, and how reachability vs. exploitability analysis separates real risk from noise
◼ How agentic AI systems investigate CVEs like a security analyst — building exploitability checklists, orchestrating deterministic tools, and guarding against prompt injection
◼ Why large enterprises' compliance processes can slow AI adoption at the exact moment attackers are moving faster than ever
◼ The audit/compliance angle: how AI-generated exploitability reports help satisfy regulators when vulnerabilities go unpatched
◼ Paul's advice to every security leader: use an LLM 5-10 times a day or risk falling behind entirely
(00:00) – Meet Paul Bleicher, Co-Founder & CPO of Convo
(00:56) – Why Paul started his own company after 12 years as an early employee
(01:54) – The pivot: from ownership mapping to vulnerability triage
(03:42) – Reachability vs. exploitability explained
(08:21) – False positives on false positives: the limits of reachability
(10:16) – The CVE arms race and thousands of vulnerabilities per day
(13:29) – What “agentic” actually means vs. AI marketing buzzwords
(15:22) – Prompt injection risk: securing an AI system that reads your codebase
(19:13) – Noise vs. context: solving triage in the right order
(20:11) – “Don’t worry about it, bro” — the reality of unfixed critical vulnerabilities
(23:33) – Convo’s real numbers: how many alerts are actually exploitable
(26:27) – AI writes the code, AI finds the bugs, AI has to fix them
(28:45) – Startups vs. enterprises: who’s better equipped to survive?
(33:21) – The gap between security leaders who use AI daily and those who don’t
(37:09) – What to tell boardrooms still afraid of AI in 2026
(41:18) – What CISOs should stop doing today
(42:17) – What CISOs should start doing tomorrow
(44:41) – Closing thoughts and where this is all heading
Guest ⬇️
Paul Bleicher: https://www.linkedin.com/in/paulbleicher/
Hosts ⬇️
Yegor Sak: https://www.linkedin.com/in/yegor-sak-725330b2/
Alex Paguis: https://www.linkedin.com/in/alex-paguis-53a21815/
Powered by Control D