AI Agents That Eliminate 90% of Security Vulnerabilities?
In this episode Alan interviews Snir Ben Shimol, CEO of Zest Security about their new “AI Sweeper Agents” that can cut down the workload on remediation up to 80 or 90% by removing those vulnerabilities that are not actually reachable, exploitable or on some level “real”.
Transcript
Hey everyone. Welcome back here to Techstrong tv. You know, I had the pleasure of meeting this fellow right here.
We were out in, uh, in Vegas for RSA reinvent in December, and he came up to our, uh, suite that we had up there. We did a, a quick interview if it's available on Techron TV and Techron O TT if you go to industry events. But I wanted to follow up with him 'cause I, I love the story.
I love the energy, I love the passion he brings to his role as CEO at Zet. Let me introduce you, my friend Sneer, Ben Shimo. Sneer is coming at us from Tribeca today.
My, one of my favorite places, old Haunting Grounds. Um, sneer, welcome back. It's good to have you on Techstrong tv.
Good to be back, Alan. Thank you for having me. My pleasure.
So for people maybe who didn't catch the, uh, reinvent interview, give let's, you know, let's reinforce, give them a little bit of your background, kind of how you got to be CEO of ZE security and, and more importantly, maybe not that you are not important, but more importantly, the what, what is that security about? Yeah, definitely. Uh, so I'll do it short.
If you want to hear more, definitely go to the previous episode, as you mentioned. Uh, so sne al, A CEO, uh, and co-founder of the security, um, long, long, long, um, journey in cybersecurity, uh, from offensive research and so on. Uh, recently, uh, before, uh, building zest, uh, uh, build cyber security with a few of my friends, uh, to solve the application security, uh, problems and sold the company to Palo Alto Networks.
Uh, that was in 2022. And before that, uh, built from the ground up and heads up all cybersecurity at Varonis public traded company in charge of, uh, product, product security, incident response, forensics, uh, security research and everything against insider threat and data tests. And before that, again, uh, different type of security roles, CSO roles and so on.
So I like to solve problems, and this is like it varonis, we solve the data problem cider resolved the application security problem, and at ZE we're solving the vulnerability and exposure management problem, which turned to be the number one problem today. Uh, like as, as you can tell, uh, since 2024, it was the first year that vulnerability exploitation, uh, suppress, uh, phishing in, um, uh, initial access in attacks. Uh, you have so many vulnerabilities.
And today with the ice, so easy to use AI as a researcher and find zero days and then publish vulnerabilities in 2025. We just started 26, but you can look on the previous year, just 2025 alone, there is an increase of over 22% of new vulnerabilities introduced to the market, which over 60% of them are critical like CVSs nine. That means that, um, low, um, complexity of exploitation, high impact, and how probability, which is crazy.
So if we're thinking about it, um, the most attractive way to hack your organization is by exploiting a vulnerability or misconfiguration, uh, the number of vulnerabilities increasing year over year for over 20 or 30%. And most of these vulnerabilities are weaponized and exploitable. And you take that and you add to it the problem that we experienced, uh, my co-founder led vulnerability management at Akamai, uh, and we experienced that it's not only millions of new vulnerabilities coming in and increasing the backlog, uh, triaging and remediation of these vulnerabilities, 100% manual.
So imagine you have these amazing security tools that you, uh, purchase that gives you all the great visibility to your problems, a lot of vulnerabilities. Hey, we scan this, scan your AWS, we scan your Azure, we scan your service on-prem, and we have all these crazy vulnerabilities. What should I do now?
What can I do with millions of vulnerabilities data from different tools? Uh, orchestration started and it's nice, but it is just like a one list, really one big list of problems. Uh, what about remediation?
What about prioritization? We realize you cannot automate it. Every vulnerability is different.
Every remediation is different. Every, every service is different. Every service is different.
It's like you can't automate vulnerability management and vulnerability remediation as the world chief and organization kind of asking how can I reduce risk, not only manage it, um, there is that problem. It's like, hey, we realize we cannot handle the numbers and we cannot automate. So what can we do?
We're stuck like that for 15 years until AI came in, and this is exactly what the security is. Uh, we're taking vulnerability management that turned into exposure management that basically failed Everyone have backlogs, right? So that means that we're doing something wrong.
And, uh, we introducing for the first time, uh, in 2025, we introduced iGen exposure management platform. That means that you can now leverage AI agents to do all these scalable deterministic analysis of millions of vulnerabilities your organization needs to handle in a very smart way. No more scoring, no more guessing, no more manual work, manual labor, no, no more.
I need 20 or 30 more people to throw over the problem using this agent to actually look into this vulnerability and to give you one answer. Do I need to fix it or I don't need to fix it. And that's exactly the AI sweeper agents we announced today at Zest.
So the way we're helping our organization that we're working with and our customers is we're removing unex exploitable unreachable vulnerabilities from their backlog automatically. And we're simulating remediation to find the best path to actually remediate the vast majority of the vulnerabilities. Um, I think today we reached a really, really big milestone at this that we can sweep the unex exploitable vulnerabilities all across cloud and on-prem autonomously.
And that's a big thing to say, no human action, no human in the loop is needed. Our agent will go and we'll give you one or zero. Do I need to fix it?
Or I don't need to fix it. The results are really, really interesting. Absolutely.
You know, Steve, I'm listening to you talk about it, right? Started a company in 2001, still secure vulnerability management space. Hard to believe 25 years.
We're still talking about the same problems. This this pattern you've described of there's more vulnerabilities this year than last year. The fact of the matter is, most of these vulnerabilities, they're not necessarily sophisticated, you know, in, in terms of, of what you have to do to exploit them.
They're, you know, and, and, and still year after year, you read the Verizon data breach report and you read, you know, these, all of the vulnerability and security reports that come out around RSA every year, right? Um, something like 75, 80, 80 5% of the, of the incidents r even zero days. They're not unknown vulnerabilities.
They're actual like garden variety vulnerabilities that, or misconfigurations that people just like sloppy, sloppy. And, and you know, I'm hoping that is much of a tool that AI is in helping the bad guys to find new vulnerabilities to find zero days. It'll also at the very least, help us clean up sloppy, right?
Because if we could clean up sloppy man that's a, you know, hundreds of times better than where we are now, and then we could worry about the, the really bad stuff, right? That sloppy isn't, it's not sloppy, it's just, you know, really bad stuff. Um, before we jump to the next portion of this, for people who want to get more information about Zest, where can they go The best?
Like we have two places that we're really active and always updating. io. Uh, this is where we're publishing our webinar blog posts, research, product announcement and so on.
And you can read about the AI sweeper agents there. And our LinkedIn page is pretty active as well. We are building communities.
We have a lot of, eh, eh, round tables, security executive events, uh, mostly in like New York, Boston, San Francisco. So our LinkedIn page is really, really, so just look for the security in LinkedIn and look for me in LinkedIn if you have questions or you think AI is a fairytale and it cannot solve their problem. So I'm happy for you to challenge me, that will be great.
Absolutely all rights. Let us turn now to something you guys are calling ai sweeper agents. Talk to us about that.
Yeah, I think, you know, before you, you're starting to fix things and before you're starting to remediate your problems, uh, would it be nice to kind of like clean up the the table? Would it be able to just remove everything that is not relevant And, uh, this is something no one was able to do until now. It's like when we thought about it and it was like, okay, is it guest work?
Is it something weird? It's like, hey, if we can have infinite amount of security engineer, just infinite amount of security engineers and ask each and every one of them to go per each and every one of the vulnerabilities are scanners identified, if it's in the cloud, and if it's on-prem, if it's in the product, and ask this each and every individual security engineer if that specific vulnerability, it's even a risk based on our environment content, right? So that can be a very bad vulnerability.
The vulnerability can be kind of existing in my environment because the scanner identified that I'm running a vulnerable version of something or a vulnerable service or a vulnerable configuration. So it's there. Now the question is, is anyone remote, local insider can do anything about it to weaponize that vulnerability?
And that question is the first, I will say the first stage of eliminating false positive or kind of like reducing that be this is what security engineer is doing. And of course they cannot do it for minutes, but let's assume that we have no number problems. We have security engineer per vulnerability.
So our AI sweeper agent, their sole purpose is to clean up, is to remove, is to sweep out everything that is not relevant. And they're not doing it by looking on, oh, this is only medium. So in our, in our company, medium is not that important.
Let's sweep it out. No, they're not looking into it. They're looking on pure facts.
What does it mean? Facts. You have a vulnerability.
In order to anyone to exploit his vulnerability, he needs to have some kind of requirements. The vulnerability of requirements for exploitation. You need to have this type of permission or the vulnerable asset needs to run in a specific way or the vulnerable, uh, asset needs to sit in a network or environment that's allowing some specific things.
If one or many of these things are not present, there is no way this vulnerability can be weaponized and exploitable to answer this question. You cannot just scan and say, I have a vulnerable, uh, a vulnerable version of this and that, that's what the scanner's doing. Giving you visibility.
Now you need to do the analysis. So what are AI sweeper agent are doing? Are mimicking a person, a really senior security engineer that takes that vulnerability, understand from the vulnerability information what the vulnerability require to be exploited, and then take that requirements and compare this requirements with your environment.
Is this requirement being met? Yes, you probably need to fix it or prioritize it in the next stage. If this requirement's not being met, let's sweep it off.
So that sounds like pretty straightforward, right? It's kind of complicated because there is no automation. Every vulnerability is different.
You need to understand which vulnerability is it, what's the vulnerability required? And then you need to look on different type of things in your environment, like network and permissions and, and uh, the policies and then understand if you can sweep it or not. And what we realized, and we published it last week, we, this specific agent so far all across our customers, and now it's like fully ga sweeped out over 11 million vulnerabilities that most of them are high and critical for the organization.
They just told the security team, don't worry about them. You see all the things that you worry about. You don't need to worry about it anymore.
This is the fact, this is the truth. They're not exploitable, it's all good. Don't focus on them, don't look at them, sweep them out.
So just imagine you run this agent and you wake up in the morning and 90% of all your vulnerabilities, the things that you are about 90% are gone. So you left with couple of hundred of thousands. If you're an enterprise, 10% is pretty, it's still a lot, right?
That's The next thing. But it's only 10%, But it's, it's better than than millions, right? Yeah.
It's like really good first step. And that's exactly what the agents are doing. We're moving and cleaning up the sweeper agents specifically just cleaning up 90% of things you think that are important for you to look at.
But they're not Excellent. You know, this is something, uh, over the years I, I've seen companies try to do this, right? Because you used to have, is it exploitable?
Is it reachable? Is it, you know, is it real? And these kinds of things.
The, the, it's, it's a question of scale, right? In the past, yes, we could do that analysis, reachable exploitable, is it truly a vulnerability, if you will? But to do that, as you say, on a million vulnerabilities, you don't have that kind of bandwidth.
I mean, this, this really is a job that calls for ai, right? That could do it at scale in a, in a, in a good timeframe, right? In the timeframe to make it useful.
Um, these are available now, they're just coming out. What's the story? They are, they were available to our customers for over three months.
And right now we just published that specific, uh, capability that is a complete GA enterprise ready AI sweeper capability that everyone can enjoy. And um, thanks to our kind of early adopters of the AI sweepers, uh, we wanted to announce about it because most of our customers are highly regulated, mostly PCI for example. Uh, and you have different level of regulation when the auditor is coming.
And it's like, who, who is this? Who sweeped out 90% of these problems? Like how dare them?
You need to fix them. And, uh, we announce about the AI sweeper agent only after these auditors kind of ask us, can you please tell everyone that there is a tool that can make our life better and the customer's life better? Because at the beginning they're kind of like, how you remove all these backlog of vulnerabilities?
And when you, they looked on the reasoning and facts, they're like, this is, this is genius how it's not existent. Like it, it saves so much time, it saves so many fights between us, the regulators and the auditors with the securities. It's like, you need to fix it.
And the security, no, we don't need to fix it because it's like right now they just need to look in our platform and we share like a small kind of screenshot of that specific, uh, feature how it looks like. So the auditor clearly see that this is the vulnerability, this is what required to be exploited. This is the evidence from the environment that one or two or three of the requirements are not there.
And there is no argument, there is no conversation to be made. There is just, there are just facts. So once we got this very strong validation also from third party auditors that, that our customers send them, it's like, hey, this is why we sweep them out.
Then we realize that this is the time that we're 100% comfortable to tell everyone we can actually sweep and clean up these vulnerabilities. Absolutely. Excellent.
io, correct? Right? Yes.
That's the best place to go. Also, the LinkedIn page. Sneer, I love what you're doing, right?
This is a space I know. Well, I, I hoping to see more and, and you know, your success is the success that we need in the market to solve this problem. So keep up the great work, man.
Come back. Maybe I, I don't know if you'd go into RSA maybe we'll get together in person there. Definitely.
Like everyone needs to go to RSA even if they want to or they don't want to. But yeah, we're going to be there with the entire team. We have some meetings.
We have events. And actually I'm excited to meet people like you, Alan, like people that can be doing conferences. So Yeah, Definitely.
Absolutely. Well, we'll be, so Monday we put on, it used to be the DevSecOps event at Moscone Center This year it's AI native or securing ai native deaf. Mm-hmm.
So it's, it's more focused, well it's focused on vulnerabilities, pre-deployment, but with feedback loops and everything else. So we're doing that Monday and then all week we're at, uh, broadcast alley, doing live all Week. Amazing.
Yeah. Let's talk, Let's meet. I'll make sure I, You definitely, I didn't think so much.
Thank you. Are we good? From Shial to Shimel?
What can I say? We'll see you next time. Good seeing you Ssir.
We'll see you. Good to see you. Good Luck.
You too. Thank you so much. Cheers.
Alright, Bye-bye. We'll be back with more on text drug TV here in a minute.