EPISODE · Jul 29, 2026 · 46 MIN
Why Top Security Teams Deliberately Leave Vulnerabilities Unpatched | Paul Bleicher
from Full Metal Packet
Paul Bleicher is Co-Founder and Chief Product Officer at Convo, building agentic vulnerability triage for security teams drowning in scanner noise.After a decade as an early employee across security and dev-tool startups, Paul and his co-founders spent two months interviewing 100+ security leaders before landing on the problem: most CVEs flagged by scanners are never actually exploitable.What we cover in this EP:◼ Why 70-90% of vulnerabilities flagged by scanners are false positives, and how reachability vs. exploitability analysis separates real risk from noise◼ How agentic AI systems investigate CVEs like a security analyst — building exploitability checklists, orchestrating deterministic tools, and guarding against prompt injection◼ Why large enterprises' compliance processes can slow AI adoption at the exact moment attackers are moving faster than ever◼ The audit/compliance angle: how AI-generated exploitability reports help satisfy regulators when vulnerabilities go unpatched◼ Paul's advice to every security leader: use an LLM 5-10 times a day or risk falling behind entirely(00:00) – Meet Paul Bleicher, Co-Founder & CPO of Convo(00:56) – Why Paul started his own company after 12 years as an early employee(01:54) – The pivot: from ownership mapping to vulnerability triage(03:42) – Reachability vs. exploitability explained(08:21) – False positives on false positives: the limits of reachability(10:16) – The CVE arms race and thousands of vulnerabilities per day(13:29) – What “agentic” actually means vs. AI marketing buzzwords(15:22) – Prompt injection risk: securing an AI system that reads your codebase(19:13) – Noise vs. context: solving triage in the right order(20:11) – “Don’t worry about it, bro” — the reality of unfixed critical vulnerabilities(23:33) – Convo’s real numbers: how many alerts are actually exploitable(26:27) – AI writes the code, AI finds the bugs, AI has to fix them(28:45) – Startups vs. enterprises: who’s better equipped to survive?(33:21) – The gap between security leaders who use AI daily and those who don’t(37:09) – What to tell boardrooms still afraid of AI in 2026(41:18) – What CISOs should stop doing today(42:17) – What CISOs should start doing tomorrow(44:41) – Closing thoughts and where this is all headingGuest ⬇️Paul Bleicher: https://www.linkedin.com/in/paulbleicher/Hosts ⬇️Yegor Sak: https://www.linkedin.com/in/yegor-sak-725330b2/Alex Paguis: https://www.linkedin.com/in/alex-paguis-53a21815/Powered by Control D
Embed this episode
Ready to play
Why Top Security Teams Deliberately Leave Vulnerabilities Unpatched | Paul Bleicher
No transcript for this episode yet
Similar Episodes
No similar episodes found.