{"id":26200,"date":"2026-09-21T15:15:13","date_gmt":"2026-09-21T23:15:13","guid":{"rendered":"https:\/\/www.palada.net\/index.php\/2026\/09\/21\/can-ai-beat-ai-3-challenges-with-vulnops-adoption\/"},"modified":"2026-09-21T15:15:13","modified_gmt":"2026-09-21T23:15:13","slug":"can-ai-beat-ai-3-challenges-with-vulnops-adoption","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2026\/09\/21\/can-ai-beat-ai-3-challenges-with-vulnops-adoption\/","title":{"rendered":"Can AI beat AI? 3 challenges with VulnOps adoption"},"content":{"rendered":"<div class=\"rich-text_richText__UyrDZ\" data-anchor-headings=\"true\" data-component=\"rich-text\" data-reader-view=\"false\">\n<div class=\"payload-richtext\">\n<p>Emerging AI frontier models could be the impetus that gets security professionals to finally tackle the tough job of fixing <a href=\"https:\/\/www.reversinglabs.com\/blog\/noise-to-signal-malware-matters\">broken vulnerability management practices<\/a>. Security strategists see Mythos and its ilk as engines for dangerously increasing exploitation risks \u2014 but\u00a0 also as the tools that will make it possible to bring to fruition all of those elusive VM improvements that have been out of reach for so long.\u00a0<\/p>\n<p>Take the push for continuous threat exposure management (CTEM), which emphasizes doing continuous assessment and basing prioritization on exploit and business context. While the security world has spent buckets of money to uplift VM with CTEM tooling and frameworks, it hasn&#8217;t managed to operationalize CTEM to effectively automate the remediation of flaws, <a href=\"https:\/\/www.resilientcyber.io\/p\/why-vulnerability-management-has\" rel=\"noopener noreferrer\" target=\"_blank\"><span style=\"text-decoration:underline\">said Chris Hughes of Resilient Cyber<\/span><\/a>.\u00a0<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cThat\u2019s where most organizations stall. They struggle to execute it at the speed the threat environment demands because their workflows still depend on human analysts to interpret findings, human operators to implement remediations, and human decision-makers to approve changes.\u201d<\/em><br \/>\u2014<a href=\"https:\/\/www.linkedin.com\/in\/resilientcyber\"><span style=\"text-decoration:underline\">Chris Hughes<\/span><\/a>\u00a0<\/p>\n<p>But looping agentic swarms into workflows has the potential to drive what security pros are now calling VulnOps. This is the latest shorthand for that mash-up of not only continuous assessment and really meaningful prioritization, but also autonomous triage and remediation. Ideally, it will also help finally bring VM out of its isolation from the rest of SecOps, said Nico Popp, operating partner for Crosspoint Capital Partners.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cI think SecOps needs to swallow VM, at very least for the zero days.\u201d<\/em><br \/>\u2014<a href=\"https:\/\/www.linkedin.com\/in\/nicopopp\"><span style=\"text-decoration:underline\">Nico Popp<\/span><\/a>\u00a0<\/p>\n<p>Popp said he believes that VulnOps will converge VM activities such as threat-driven remediation with higher-tier SOC functions such as threat hunting and control optimization. An effective VulnOps program will revolve around what <a href=\"https:\/\/www.linkedin.com\/posts\/nicopopp_vulnops-vm-ctem-share-7468206952788062208-TxRd\/\" rel=\"noopener noreferrer\" target=\"_blank\"><span style=\"text-decoration:underline\">he calls the seven samurai of VulnOps<\/span><\/a>: shift left, continuous scanning, validation, prioritization, agentic patching, adaptive remediation, and detection and containment.\u00a0<\/p>\n<p><em>\u201c<\/em>AI beats AI\u201d is a great vision, but a lot of practical AI work has to happen before security teams can reach the autonomous VulnOps nirvana. Here are the biggest challenges that need to be tackled to make VulnOps a reality.\u00a0\u00a0<\/p>\n<p><strong>[ See webinar:\u00a0<\/strong><a href=\"https:\/\/www.reversinglabs.com\/webinar\/building-high-fidelity-threat-intel-feeds-for-agentic-ai\"><strong>How to Build High-Fidelity Threat Intel Feeds for Agentic AI<\/strong><\/a><strong>\u00a0]<\/strong><\/p>\n<h2 id=\"1-managing-ai-token-costs-is-essential\">1. Managing AI token costs is essential<\/h2>\n<p>IT budgets are always an issue, and AI tokens don\u2019t come cheap.\u00a0<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cTokenomics will be a big challenge. If the costs are out of control, it could get to the point where some people will say, \u2018If the AI is more expensive than humans, maybe we don\u2019t need the AI.\u2019\u201d<\/em><br \/>\u2014Nico Popp<\/p>\n<p>In the AI euphoria of just a couple of months ago, companies were encouraging \u201ctokenmaxxing,\u201d or trying to do more with AI by maxing out the number of tokens consumed. But now the bills are coming due, <a href=\"https:\/\/techcrunch.com\/2026\/06\/05\/the-token-bill-comes-due-inside-the-industry-scramble-to-manage-ais-runaway-costs\/\" rel=\"noopener noreferrer\" target=\"_blank\"><span style=\"text-decoration:underline\">budgets are borked<\/span><\/a>, and the bean counters want to walk back those policies and start real AI cost management. <\/p>\n<p>Tokenomics is a big enough issue that the Linux Foundation has launched the <a href=\"https:\/\/www.tokeneconomics.com\/\" rel=\"noopener noreferrer\" target=\"_blank\"><span style=\"text-decoration:underline\">Tokenomics Foundation<\/span><\/a> to define efficient token consumption that doesn\u2019t hold up AI advancement.\u00a0For CISOs and SOC leaders, the big challenge will be finding a good balance between agentic AI gains and budgetary realities.<\/p>\n<h2 id=\"2-choosing-the-right-llm-is-key\">2. Choosing the right LLM is key<\/h2>\n<p>Another issue tied to cost is deciding on which large language model (LLM) to use and defining the surrounding infrastructure, code, and orchestration logic that will turn that model into a working, autonomous agent \u2014 the harness. Models are not one-size-fits-all. Right-sizing the model to whatever problem the AI is supposed to analyze or automate will keep expenses down, Popp said. It\u2019s also crucial for managing the effectiveness of the AI in specific use cases.\u00a0<\/p>\n<p>Frontier models are currently getting the most attention, but <a href=\"https:\/\/www.linkedin.com\/in\/stanislav-fort\/\"><span style=\"text-decoration:underline\">Stanislav Fort<\/span><\/a>, chief scientist and founder of AISLE, <a href=\"https:\/\/aisle.com\/blog\/ai-cybersecurity-after-mythos-the-jagged-frontier\" rel=\"noopener noreferrer\" target=\"_blank\">wrote recently<\/a> that security researchers are showing that \u201csmall, cheap models outperform large frontier ones\u201d in a lot of cases.\u00a0<\/p>\n<p>Many of the open-source models from China and elsewhere are \u201cgood enough at cyber investigations,\u201d said longtime security pro and agentic AI startup founder Jimmy Astle. Kimi K2, from China\u2019s Moonshot AI, for example, costs just one-tenth of more advanced closed-source models but is\u00a0 effective for many tasks.\u00a0<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cIt\u2019s not as good at the critical thinking stuff, but it\u2019s really good at agentic tool calling and task solving. These open-source models will force the tokenomics down, which will then enable these [autonomous] investigations to proliferate.\u201d<\/em><br \/>\u2014Jimmy Astle<\/p>\n<h2 id=\"3-be-the-master-of-your-agentic-governance\">3. Be the master of your agentic governance<\/h2>\n<p>If agentic AI needs free rein to be effective at VulnOps, how do you make overall risk go down and not up? If human oversight of vulnerability remediation is limited, you need to boost threat modeling and controls such as identity and permission structures around the agents. Because they hold write access, they are targets. The architecture has got to be designed deliberately so that the security holds up without slowing down the autonomous action when it needs to be made, <a href=\"https:\/\/www.rockcybermusings.com\/p\/aiuc-1-after-mythos-machine-speed-defense\" rel=\"noopener noreferrer\" target=\"_blank\"><span style=\"text-decoration:underline\">wrote AI security consultant Rock Lambros<\/span><\/a>.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cMachine-speed remediation needs pre-approved business-impact authority with bounded autonomy, so the response fires inside agreed limits without a 2 a.m. approval chain.\u201d<\/em><br \/>\u2014<a href=\"https:\/\/www.linkedin.com\/in\/rocklambros\/\"><span style=\"text-decoration:underline\">Rock Lambros<\/span><\/a><\/p>\n<p>Keeping agents hardened from attack is important, but even more crucial is building in the governance and controls that make sure they behave as intended, Popp said.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cYou need to control what those swarms of agents are doing. People are going to be even more concerned about the agent going off of the reservation than malicious actors trying to take advantage of vulnerability in the agent.\u201d<\/em><br \/>\u2014Nico Popp<\/p>\n<p>The biggest concern, Popp said, is action governance rollback. He believes that this is going to be where the human in the loop resides, as security teams phase out of the work of remediating the vulnerabilities and running triage and transition into guiding agents, auditing them, and managing the policies that tell them how to carry out VulnOps and all of the security work around it.<\/p>\n<h2 id=\"the-agentic-soc-is-key--and-takes-hard-work\">The agentic SOC is key \u2014 and takes hard work<\/h2>\n<p>Popp said that for VulnOps to become a reality, getting to to an agentic SOC is going to be the most important piece of the puzzle.<\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cWhen you have enemies that can weaponize new vulnerabilities in minutes and it still takes 15 weeks to patch, they have the speed advantage. I tell people, \u2018You don\u2019t bring a knife to a gunfight. You have to bring AI to this problem.\u201d<\/em><br \/>\u2014Nico Popp<\/p>\n<p>Working with agentic AI has its own challenges. Shimon Tolts, co-founder and CEO of Copperhelm, said the core work of SecOps will shift from execution to verification, adding that analysts who continue to spend their days manually triaging alerts will be automated out of relevance because agents are stuff faster and cheaper. <\/p>\n<p style=\"padding-inline-start:40px\"><em>\u201cThe durable skill is supervising a fleet of agents and knowing when their conclusions are wrong. That is a judgment skill, not a tooling skill, and most current training still teaches button clicking.\u201d<\/em><br \/>\u2014<a href=\"https:\/\/www.linkedin.com\/in\/tolts\/\">Shimon Tolts<\/a><\/p>\n<p><em>Learn more in the recent post, <\/em><a href=\"https:\/\/www.reversinglabs.com\/blog\/agentic-secops-survival-guide\"><em>&#8220;Working with agentic AI: A SecOps survival guide.&#8221;<\/em><\/a><\/p>\n<\/div>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Emerging AI frontier models could be the impetus that gets security professionals to finally tackle the tough job of fixingbroken vulnerability management practices. Security strategists see Mythos and its ilk as engines for dangerously increasing exploitation risks \u2014 but\u00a0 also as the tools that will make it possible to bring to fruition all of those elusive VM improvements that have been out of reach for so long.Take the push for continuous threat exposure management (CTEM), which emphasizes do<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[32775],"tags":[],"class_list":["post-26200","post","type-post","status-publish","format-standard","hentry","category-reversinglabs"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26200","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=26200"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/26200\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=26200"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=26200"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=26200"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}