Sarasota, FL, USA
2018
  |  By Scott Kuffer
If you've been following the cybersecurity conversation over the last several weeks, you've heard some version of the phrase “Claude Mythos changes everything.” It’s dominated the industry news cycles since early April. While the capabilities these stories tout are very much real, I have an issue with the framing being wrong when it comes to vulnerability management. There’s a narrative that Mythos and other frontier models will find too many vulnerabilities to deal with.
  |  By Doug Drew
In the span of six weeks this summer, the United States government issued three separate security directives that, on the surface, appear to address completely different problems. One tightens how federal agencies patch software vulnerabilities. Another creates a government-industry clearinghouse to triage AI-discovered bugs. The third restructures how defense contractors source the raw materials that go into missiles, aircraft, and military electronics. Different agencies. Different languages.
  |  By Will Gorman
When Anthropic revealed Claude Mythos and Project Glasswing, the industry did what the industry always does with a frontier-AI story: it reached for the alarm. The headlines, Reddit threads, and back-channel conversations all focused on the same things: All of that is real, and none of it is the part that should keep a security leader up at night. Here is the part that should.
  |  By Tony Ramirez
If you've ever pulled an asset count from one tool and compared it to another, you've probably noticed they don't match. The discrepancy isn’t minor, either. The difference is likely to be substantial. One scanner says you have 4,200 assets. Your CMDB says 3,800. Your cloud inventory says 1,100. None of them agree, and none of them are right. That's not a data hygiene problem you can solve with a spreadsheet cleanup.
  |  By Jeff Gouge
At the executive level, vulnerability management stops being a technical exercise and becomes a question of risk ownership, operational tradeoffs, and organizational accountability. When a vulnerability leads to a breach, it has a personal effect on security leaders along with its broader organizational impact. According to Proofpoint’s Voice of the CISO Report, a majority of CISOs claim they are personally blamed ‘always or often’ when a breach occurs, even when defenses were in place.
  |  By Tally Netzer
CISA Binding Operational Directive 26-04: Prioritizing Security Updates Based on Risk requires Federal Civilian Executive Branch (FCEB) agencies to prioritize security updates based on operational risk, not just severity. It builds on earlier Cybersecurity and Infrastructure Security Agency (CISA) directives by combining exposure, exploitation, impact, and prioritization logic into a more actionable remediation model.
  |  By Aaron Attarzadeh
Most vulnerability management programs don’t struggle because they lack visibility. They struggle because they generate more security decisions than humans can realistically process at scale. Modern security teams already have most of the tools they need to find and assess vulnerabilities. Their real operational challenge is determining which vulnerabilities matter, which teams own them, which findings deserve escalation, and which can safely wait.
  |  By Ryan Cribelar
Every year, the Verizon Data Breach Investigations Report (DBIR) gives the security industry a chance to step back from the noise and look at what happened. Not what vendors predicted. Not what attackers threatened. Not what defenders feared. What happened. This year’s report makes one point hard to ignore: vulnerability exploitation became attackers’ initial leading access vector.
  |  By Tally Netzer
Don't wait for KEV listing Waiting for CISA KEV may be too late. Across six months of Nucleus research, public PoCs gave defenders a median 5.5 days of runway before KEV listing, every single time.
  |  By Tally Netzer
EPSS: Early warning or not? EPSS is a predictive scoring model, and security teams assume it is an early warning signal. Nucleus research across 18% of CISA KEV-listed CVEs over 6 months found it isn’t.
  |  By Nucleus Security
During our recent webinar, Co-founder and CPO Scott Kuffer explains how a text from an unexpected source brought home how AI and Claude Mythos have elevated the visibility of the vulnerability problem in the public sphere.
  |  By Nucleus Security
In our recent webinar on how Claude Mythos will affect vulnerability and exposure management, guest speaker Jerry Hoff talks about what the ramifications are for discovering masses of new vulnerabilities in your environment.
  |  By Nucleus Security
Artificial intelligence is transforming cybersecurity at an unprecedented pace, but is it making organizations safer or simply exposing more vulnerabilities?
  |  By Nucleus Security
In this webinar, Nucleus Security CEO Steve Carter and Product Marketing Lead Tally Netzer break down the growing “exploitability intelligence gap” and what it means for modern vulnerability and exposure management programs. Drawing from six months of research and real-world vulnerability data, they explore how attacker timelines have compressed, why traditional reactive workflows are struggling to keep pace, and where organizations are missing critical signals before exploitation begins.
  |  By Nucleus Security
AI is becoming table stakes in vulnerability and exposure management. In this candid webinar conversation, Chris Ray, Field CTO at GigaOm, and Will Gorman, CTO and leader of AI initiatives at Nucleus Security, challenge the assumption that more AI automatically leads to better outcomes.
  |  By Nucleus Security
Nucleus R&D Engineer Ryan Cribelar assesses where internet exposure ranks amongst all of the factors involved when prioritizing vulnerabilities.
  |  By Nucleus Security
R&D Engineer Ryan Cribelar explains how internet exposure is a factor in risk management related to vulnerabilities and exposures.
  |  By Nucleus Security
Nucleus Security's Adam Dudley talks about the platform's place in a highly functioning CTEM approach during a joint webinar with Cycode and HackerOne.
  |  By Nucleus Security
In this conversation, Ryan Cribelar, R&D Engineer at Nucleus Security, breaks down why internet exposure is one of the most important layers of context in vulnerability and exposure management. Security teams are flooded with vulnerability data, but not every finding carries the same level of risk. As Ryan explains, whether a vulnerability is reachable from the internet can dramatically change how urgent it really is. Internet exposure shortens the path from discovery to exploitation and often determines whether a vulnerability is theoretical or immediately actionable.
  |  By Nucleus Security
In a joint webinar with leaders from Nucleus, Cycode, and HackerOne, HackerOne product manager Kyle Mativier explains how advancing AI capabilities are collapsing how long it takes attackers to exploit seemingly low to medium severity vulnerabilities.
  |  By Nucleus
There are hundreds of statistics you could collect and monitor to use as guiding metrics, but that doesn't mean it's a good idea to do so. Learn the four most critical metrics to track in vulnerability management, and what they tell us about the health of your program.
  |  By Nucleus
Many organizations are using outdated, highly inefficient, and time consuming VM processes that leave security personnel struggling to keep up. As the vulnerability landscape continues to evolve rapidly, the processes used to discover, track, and remediate them has failed to evolve with it.
  |  By Nucleus
Vulnerability exploitation is involved in over half of breaches, making it a huge risk to organizations. And the problem only continues to balloon year over year... both in the speed at which attackers are capitalizing on exploited vulnerabilities, and in the way that technology and assets outgrow most organization's current vulnerability management programs. In this series, we're going to be breaking down how vulnerability management has grown and evolved over time, plus how to modernize your program using things like risk-based vulnerability management.

Nucleus is a Risk Based Vulnerability Management (RBVM) solution that automates vulnerability management processes and workflows, enabling organizations to mitigate vulnerabilities 10 times faster, using a fraction of the resources that it takes to perform these tasks today.

The only Risk-Based Vulnerability Management Platform purpose-built for the world’s most complex enterprises:

  • Vulnerability Management: Mitigate vulnerabilities 10X faster, using a fraction of resources.
  • Application Security: Accelerate AppSec to the Speed of Operations & ship secure code faster.
  • Government: Ensure compliance and control access to data any way you choose.
  • MSSPs: Manage all clients from a single platform with true multi-tenancy.

Unified Vulnerability Management.