Furl Targets the Cybersecurity Remediation Gap
Furl Focuses on the Remediation Problem
Alan Shimel speaks with Derek Abdine, co-founder and CEO of Furl, during Techstrong TV’s Black Hat 2026 coverage. The conversation focuses on cybersecurity remediation and why fixing issues remains one of the hardest parts of enterprise security. Abdine explains that the industry has spent years getting better at finding problems. Fixing those problems is still too slow, too manual and too complex.
Furl is built to address that gap. Abdine says security teams often face a long decision tree after a vulnerability or configuration issue is found. They need to understand the asset, the owner, the right tool and the safest path to a fix. That process can create major delays. It also makes remediation backlogs harder to control.
Detection Alone Does Not Reduce Risk
Abdine brings more than 20 years of cybersecurity experience to the discussion. His background includes work at Rapid7, Censys and other security organizations. He has worked on internet scanning, honeypots, threat intelligence and vulnerability management. Those roles shaped his view that detection is only part of the job.
The real challenge begins after a finding appears. Security teams must decide what needs to change, who should approve it and which tool should make the fix. If no tool can do the job, someone may need to write a script or handle the work manually. Cybersecurity remediation becomes even harder when fixes do not stick or cannot be validated.
AI Changes the Speed of Security Work
Alan and Abdine also discuss the impact of AI on security operations. Abdine notes that AI-generated code can create new vulnerabilities. At the same time, AI can also help defenders move faster. That shift raises the stakes for teams that already struggle with remediation speed.
Furl uses an agent-based approach to support remediation work across endpoints. Abdine describes a system that can gather information, perform analysis, create remediation artifacts and help build a recurring detection. The goal is not to add another dashboard. The goal is to help teams move from finding issues to closing them.
Endpoint Teams Need Action, Not More Noise
The discussion also looks at process, culture and ownership. Abdine explains that endpoint remediation often involves IT, security and asset owners. Those teams need better coordination. They also need technology that can support action without removing needed control.
For security leaders, the takeaway is clear. Faster detection is useful, but it does not reduce risk unless teams can fix what they find. Furl is focused on making cybersecurity remediation more practical, more repeatable and better aligned with how modern endpoint teams work.
Transcript
Hey everyone. Welcome to our Black Hat coverage for 2026. I'm Alan Shimel, and we are out here at the Mandalay Bay.
We found a little quiet corridor that's the perfect place for us to do some videos. ai, and he's our first guest today. Hey, Derek, welcome to Techstrong TV, man.
Thank you. Thank you for having me. Our pleasure.
So Derek, we're going to talk about Furl, but before we do, I wanted to just take a quick moment to let folks know who you are, what do you do at Furl, and how'd you get here? Yeah. So who I am, I have been in cybersecurity for over 20 years.
And, if you look back at my early days, kind of like in a dark room, nerding out with and teaching myself the level of programming languages, how to write operating systems. It goes back around 30 years, first engineering hardware and software. I took that into a video game, actually.
Really? And I reverse engineered "Grand Theft Auto," yeah. And so that's one of my early claims to fame, is I reverse engineered that game to add multiplayer support to it, and then open sourced it so people could play online with each other.
And it was pretty wildly successful. Still played by thousands of players to this day, which is kind of crazy for a 23-year-old model. What a great feel.
Yeah, it's pretty amazing. But that started off my journey into professional cybersecurity industry, where I was noticed by some of the founders of Rapid7. So I was one of the early engineers at Rapid7, which is a well-known security company.
Was that when Alan Matthews was still there? Alan Matthews was there, yeah. Sure.
Alan Chadloader, Toss Jackmonoki. Yeah, I knew all those guys. Yeah, they're great guys.
So I reported actually into Toss for quite a while as well. Really? Yeah.
Yeah, I knew Toss. So I had started a company called Still Secure. Okay.
Sounds familiar. And we had a VAM, a vulnerability. We used to compete with Rapid7, and we also had IDS and NAC.
Okay. But I knew Alan pretty well. It's funny you talk about how you got into it.
A little different than what you hear from most people today. They took cybersecurity in school. Yeah.
And back when you were doing it and I got into it, there was no cybersecurity in school. You broke stuff. Yeah, exactly.
And then you fixed it, or you put it back together anyway. And some of the best security people come from that. Yep.
So take us from Rapid7. How'd you get to Furl? Well, again, yeah, at Rapid7, I did a lot of stuff from scanning the internet to doing global honeypots, do threat intelligence.
By the time I left then, it was threat intelligence data science. I had gone to do the 2019 economic report to the president. That was great security research that the entire Rapid7 team did.
I was doing a ton of stuff. Went to Census as CTO there for a year. Uh-huh.
And I really wanted to look back on remediation, was something that was kind of frustrating to me because I had been on the vendor side of detection problem and vulnerability management for quite a while. But, it's one thing to detect, and everyone's focusing on detecting. And just let's just be blunt.
There's a lot of romanticizing around detection with all the marketing security pages that we see coming out and all this flashy security research. " And we don't talk enough about that. And it's a real problem for defenders.
Talk to any defender that's had a security report come out on a Friday on Twitter, and then they have to go and deal with that. Welcome to Saturday. Yeah.
Mm-hmm. And then you work on the weekend. Yeah.
And so we wanted to do something about it, so we started the company, after looking at what exists on the market today, and saw that there was insufficient tooling to really help on the defensive side on the remediation end. So referral started to really be the answer to that remediation problem on the endpoint. And by the way, while that was starting, we started seeing models coming out.
So I had been playing with models since 2022 when GPT-3 was out before ChatGPT came out, and they hallucinated a lot, right? And they weren't really great. But now you fast-forward, and people are bicoding applications, just asking the model to write code.
That'll have vulnerabilities because guess what? It's trained on human-generated- Bad in and bad out ... bad out.
Bad in, exactly right. But they're also good at understanding how to identify vulnerabilities and then exploit them. And so again, the compression of time now from where we used to be versus today is much greater.
We need to be able to deal with these issues much faster than we've historically been able to. So what we're doing with Furl is really rethinking the last 30 years of how remediation was done and how security's been working, and just really asking ourselves how should it work, and then redefining a security stack for the future, and how we should align ourselves culturally in the future there. Love it.
I got to ask you a serious question. You and I, I also spent 30 years in cyber, right? From the people who at Rapid7, I remember when Rapid7 first came out, it was butt ugly.
Worst interface I ever saw. We're like a software company. I told my co-founders, I said, "I wouldn't worry about these guys.
" Oh, whatever. But, why haven't we solved the remediation? You're in this long.
You remember Citadel Hercules probably back in the day? Yeah. Coordinated patching and everything.
DISA put money into them and everything, but it never really caught on. For as long as I know, we've never done the remediation piece. No matter whether we're talking about humans finding vulnerabilities or now Mythos and these things finding vulnerabilities.
We've always been on a deficit when it comes to fixing them. Mm-hmm. Why?
Process and technology. So process-wise, it's hard to remediate anything. You think about there's a big decision tree that you have to go down whenever you find an issue.
So a vulnerability scan, and vulnerability is just one type of thing you can remediate, by the way. Right. It's configuration, compliance, hygiene issues, all that stuff that come down to it when you're talking about endpoints.
But a vulnerability is like a signal that something needs to be changed on a device. Now, how does that change happen? Well, there's a cultural part of the process, like, okay, centralized IT organization can't just automatically fix everything in the environment.
Sometimes the asset owner or the mediator is somebody completely different. So that's something. We still see that today, although the teams are starting to shift and change.
But then you have to go down to this tree of do I have a tool that can actually fix it, like a patch management tool? If I do, I need to see if I can configure that tool to fix it. If not, then I need to customize that tool to be able to fix it.
And if I can't use that tool, then I have to write a script. If I can't do that, then I have to instruct somebody on how to do it. And what you find is that the effort that it takes to go through all that is so significant that it causes a lot, it just takes too long to churn through the backlog of remediations.
So that's the process side of it. Then the technical side is, with all the patch tools that exist and all the scripts that need to be crafted, you have to have the domain expertise, the system administration expertise to script anything. And then the tools that exist on the market, for one, I'm talking about patch tools mainly right now, sometimes the fixes don't stick.
So the first is like you might apply a patch, but it doesn't actually stick correctly, and you have no way to kind of validate and vet that. And some improvements have been made there, but it's very you throw a script at it and you hope it gets fixed, and that doesn't always work. And the second is that none of these systems that exist today are taking into account the ability to look at context from the endpoint and understand what's going on there.
And so it turns out now that with models, we have the ability to reason through them and reason about the endpoint a little bit more clearly, and then use that reasoning to drive better remediation. So process and technology are the main two. So look, my question is why endpoints?
Because I come from a world where we used to have something called antivirus, right? Symantec and McAfee, those- Right ... they were pigs of a program.
It would kill your resources. But we've evolved to endpoint security solutions, SentinelOne, these kinds of things. Why haven't they licked this problem?
It's hard. Nobody wants to do it. It's like one of the hardest problems you can try.
" Right. Let's just let it burn. That's part of it.
This is one of the hardest problems, and that's why it's been mostly avoided, and most of the solutions that exist can only do very narrow slices of it. The other thing is that most of what we've built over the last 30 years in security and IT are disconnected from each other. And so patch management tools are born out of IT, and security tools are born from a security perspective.
The incentive on the security side is finding more, and the security on the IT side is maintenance and operations and stuff like that. And so there's nobody's really thought about bringing those two together, understanding where the gaps are between those two products, and then automating or remediating all the way through. Get it.
So let's get specific on Furl now, right? ai in the name You're probably using AI to help with this. How exactly does Furl work?
So the first is, there's a kind of foundational layers I'll walk you through, and there's two kind of components to it. At a high level, the two components are proactive remediation, so doing it while you're sleeping, and the second is reactive remediation. I'll describe what both those mean.
But to get to there, you need a foundation layer, which is understanding a source of signal. And this mirrors what we're talking about on the process side. So today, if you're running a vulnerability, let's talk about vulnerability, just being specific on that.
You're going to get a vulnerability remediation report that tells you the things that need to be fixed in the environment. You're going to create tickets, prioritize them, assign them to people, and then work on them. That's the state of the art before Furl.
So the first thing we need to do is understand the source of signal, and that means integrating with sources of vulnerability data on the endpoint. As an example, our compliance configuration, hygiene, all that information. But then, a lot of what we have to do as defenders is look at that information and tell what is the actual thing that needs to be fixed on the endpoint.
So if it says we got 100 vulnerabilities on Firefox, and Firefox is now the thing that needs to be solved. Where is Firefox installed? Did the user install it by themselves or installed in a global directory?
On Windows, this happens a lot. Which version is it? What's the latest version that it needs to be upgraded to?
So the gap of operationalizing that is already massive for every issue that's found. So the first part we do is we take that data, we clean it up, and we identify something called a target or mediation target. And then once we inventory that, now we can basically build the next two components that I mentioned earlier.
The continuous autonomous remediation works with a three-tiered guardrail system, where essentially people can define what are the criteria, how wide or narrow do they actually want to remediate in their environment. So they just basically tell us, okay, types of software, types of endpoints by operating system, by asset owner, by tag, maybe by vulnerability score. And after they define that criteria, the product then goes in and matches those targets to, and then starts to process remediation.
And this is kind of full stop there. That's different than what the rest of the security industry's doing. Right.
Because the industry security industry right now is primarily focused on ticketing and priority. So, like, to remediate, the answer has historically been ticketing and priority, primarily because we haven't been able to fix a lot fast enough. And so the first part, with us, is really focusing on bringing the guardrail to allow people to really hone in on the fix.
The second part is how you go around each fix. So as you think about fixing something as an operator, if you're on the IT side, what are you going to do? You're going to validate it.
You scan on a Friday, announce a Wednesday. Is that thing still valid and should be remediated? Because you don't want to make an operational change on a system that you don't need to.
So that's one example. But now utilizing artificial intelligence to basically interact with the endpoint and determine whether or not a target is valid, whether the endpoint's ready to receive the change. Does it have enough disk space?
Is it ready to receive this change? It's not going to fail when you go to deploy it. Deploying the fix.
Then the last one's verification, making sure that the application still works, making sure that the risk has been actually removed. And doing that over and over and over again for every specific thing that you're going to fix, rather than maybe doing an end-to-end test when you've already fixed a bunch of things and you have too many variables now that you don't know what failed and why. So the proactive part is just walking through with an operator's mindset, utilizing a model to reason through what's being fixed and why till you get to that remediation side.
The second part is autonomous response. And so that one, the first part that I just discussed right now, that's you're letting the product go figure it out. You're telling it, giving it guardrails on how to actually remediate.
The second one is a little bit different because the key use case for the autonomous response side is, let's talk about supply chain attacks. There's a new one with just today, actually, that was announced with KV and Cachable. Their NPM library is downloaded by lots of developers, 125, I think.
So another NPM library? Another one. There was Axios in March, was another example.
There's been plenty in between, but there's one just dropped today. And you have KV and Cachable download 125 million times a week by developers, and somebody compromised the package, uploaded a malicious version. There's a remote access toolkit on it now, and then people that are downloading that, it runs a post-install script, and basically their machine is owned.
And so how do you- Doesn't this get old, though? It gets very old. The classic response is you get a war room together, you get your team together, you look across many tools.
It's all frustrating and stressful, and then, you're probably working late nights to understand what the blast radius is and how you fix it. And it's just Tuesday. And it's just Tuesday.
So autonomous response is meant to deal with that. So the way we work that problem is, it's kind of like, I call it the, it's like an agent harness for remediation. So an agent harness, an example of an agent harness is Cloud Code.
So Cloud Code, you tell it kind of what you want and it generates source code. Sure. We don't change source code.
That's not what we do. But we have a similar concept where we use an agent harness to interact with the endpoints, to pull information about IOCs for those specific events, do a forensic analysis, and create remediation artifacts. So it'll create that remediation scope.
It'll create the fix for you. It'll also create a recurring detection. So now you have a full pipeline that you can go from the Axios issue came out.
You can identify if it's in your environment, and then you can go actually deploy a fix to the entire environment within minutes instead of looking across multiple- That's beautiful ... tools over days. I'm reminded of my days at Cisco.
We did a NAC, network access control, and we did it in a similar way. Basically, we would grab your registry, so we knew at least what your registry said you had. And so when we put that up against a list of what was gold, what was not, and what needed to be patched, or we had to push something, it was really quick because we weren't actually scanning your device.
We were just registry reading, let's call it. Yep. It's funny, I see some of the vulnerability vendors here, scanning vendors here, announcing scan list- Mm-hmm ...
vulnerability, and it's the same thing, the reason. Yeah, it's the same recipe that's historically been done over and over again. And again, I think we have to rethink from first principles.
What goal are we trying to achieve? Exactly. And what are the constraints for that goal?
And then work back to a solution, as opposed to, I think, a lot of the new approaches, and some of them are innovative. Mm. But we need to take bigger leaps than small innovations based on the changes.
We're in a fundamentally different period today than we were- It's a new era. Yeah. There's no doubt.
Completely. No middle product that we don't know of. Not only do you throw away what you've learned over the last 30 years, you build on it.
Yes. But you got to be bold right now. This is not the time to increment little things here.
Correct. It sounds like Furl's really in, though, in an enterprise or SME and up. Yep.
Where you're doing this across a portfolio of endpoints. What's the pushback? Any pushback from people on this?
" And so- They've been saying that a long time, too. And you got to have an agent to fix. I would say, it's an easy rebuttal, though, for most people.
I would say it's like, okay, well, you probably have seven agents for security and none to remediate. So the condensation economic on security- You could almost call them agentless agents, right? Agentless agents.
We did too, that too. Yeah. The ridiculousness of it.
But you can't defy the laws of physics either. Yep. Yeah.
So that's one we hear, but it's pretty easy to get around when the value prop is really trying to secure the endpoint. And if you think about things that are actually fixing things versus detecting and mitigating, you probably don't have a good answer for it, is generally what we found people run into. So that's the first one.
The second that we tend to run into is concerns around AI running amok. And I totally agree. You never want a model to run unsupervised in your environment.
They're just not there yet. Yeah. Fundamentally.
Coming back to GPT-3 in 2022, that thing hallucinated a ton. But models have become significantly smarter. Still much better.
There's new frameworks like agent harnesses that allow them to collect- Absolutely ... context and think better. And so thinking models are a huge leap forward as well.
So they do that less, and with the right context, they do that even less. But that doesn't mean you just fully trust it. And so building a system in place that you can trust that the product can be earned, an AI product can be earned over time, not given by default, is important.
And you layer, you pull back the guardrails as you find that you trust the product to do the capability that was built. Right. I think you got to start almost like at a zero trust and then build it up from there.
Correct. Exactly right. You guys went GA in May.
That's right. So three months out. When's the next version?
Next version's releasing, we just had a release today, actually, this morning. Really? There you go.
Every- That's why it's in the era, man ... one to two days. Yeah.
So things move fast. We need to make sure that we're moving just as fast. I would say, though, there's some big things coming on the roadmap in terms of what we're doing in the future.
I won't reveal too much of that right now. But ultimately, the goal here is solving the gap between what people see coming into signals to securing our endpoints and managing the endpoint as a whole, and the solutions that exist today. And there are many, many gaps to fill.
And I think where our goal here is to continue on that roadmap of driving towards fully helping people out in that area so they can focus on value-added activity versus having to be going through the grind of working tickets to go fix things. So that's the end state. Compliance, configuration, vulnerability, hygiene, all that stuff.
That's where we want to live. I love it. ai.
ai. Hey, man. Derek, thank you so much.
Thanks, Alan. Appreciate it. Appreciate it.
Hey, we're at Black Hat. Hope you're enjoying Black Hat coverage. We're going to have a lot more coming your way.
But for now, I'm Alan Shimel. We're out.