Quantro Security Reframes AI Vulnerability Exploitation
AI Changes the Economics of Exploits
Alan Shimel talks with Mehul Revankar, co-founder and CPO of Quantro Security, about why AI vulnerability exploitation is changing cybersecurity economics. Revankar explains that his career has centered on vulnerability research, exposure management and product development at companies including Tenable and Qualys. That background led him to co-found Quantro Security after seeing how AI could transform the way attackers and defenders evaluate real exploitability.
From Vulnerability Noise to Proof
The conversation focuses on new research from Quantro Security and Loginsoft. Revankar says the team built an exploit harness that can set up vulnerable systems, test exploit paths and verify results. He also explains why that process was difficult. AI models sometimes produced fake outcomes when they could not complete a task. The team had to add guardrails, verification steps and independent review to make sure the results were real.
Machine-Speed Offense Raises the Stakes
A key finding is that AI can dramatically lower the cost and time needed to build working exploit proof-of-concepts. Revankar says the research showed exploits could be created for about $3.05 in roughly 13 minutes. He also says the harness exploited more than 70% of the vulnerabilities in the dataset. That shift makes AI vulnerability exploitation a practical concern for security teams, not a distant theory.
What Defenders Need to Rethink
Revankar argues that defenders need to move beyond long lists of vulnerabilities. Security teams need to know which issues are reachable, exploitable and meaningful in their environment. That requires better context, faster validation and more automation. It also changes the competitive pressure on legacy security vendors. If AI can generate scanners, signatures and working exploits faster, cybersecurity platforms need to adapt quickly.
The discussion ends with a look at Quantro Security’s research site and Revankar’s new podcast, Noise to Signal. For security leaders, the main message is direct. AI vulnerability exploitation is changing the speed of offense, and defenders need systems that can verify risk at the same pace.
Transcript
Hey everyone. Welcome back here to Techstrong TV. We've been busy today, but I was really looking forward to having my next guest on.
He's a friend of mine I met. I truthfully met him originally at Qualys, probably four or five years ago, maybe more. He had a senior position there.
His name is Mehul Revankar, like raven. We're not going to say Baltimore Ravens, but Mehul. But I did.
But Mehul is, as I said, a person I've met over the years, a friend, and I'm so proud and happy to hear that he co-founded a new company we're going to hear all about. But first, let's welcome him on here. Mehul, welcome to Techstrong TV.
It's good to have you back. Alan, thank you for having me on. It's such an honor to meet you again and be on your Techstrong TV broadcast.
Absolutely. So look, I kind of pre-announced, you used to be at Qualys and now Quantro. But give people a sense, Mehul, of your own personal journey and specifically maybe in cybersecurity and so forth.
Yeah. I'm a co-founder at Quantro Security. I run product marketing and sales at Quantro Security.
I've been building cybersecurity products for over 20 years. I started my career as an exploit writer, vulnerability researcher at Tenable. So, go a long time back, back to 2005, building vulnerability research teams at Tenable, leading vulnerability research teams at Tenable.
And then more recently, as you said, I was heading the VM/DR product line at Qualys. So I spent more than 20 years building vulnerability management products, exposure management products, compliance, automation. So this is all I've done in my entire life.
And with AI coming along the way, I realized there is a big transformation happening in the way we do cybersecurity. And I thought the only way to do this really well is to start your own company. And that's how I met with my co-founder, Sasan, who was leading the product and engineering teams for cloud security at CrowdStrike.
We partnered, and we started Quantro Security last year. And we are on the cusp of releasing some new research that is coming out from Quantro Security. So I'm super excited to talk to you about it and all the things that Quantro Security is doing.
Love it. I want to spend a little bit of time about the story behind Quantro. Because this is something our audience is always interested in.
There's a lot of people out here, Mehul, like you, who have spent quality parts of their career doing important things, whether that's for end user organizations, other vendors, et cetera. And everyone says, "I'd like to start my own company," but yet very few people do, compared to the people who talk about it. And it's not something you do lightly.
" It's something that you've got to feel it in your chest. You've got to feel it in your guts, in your stomach. Yeah.
" Yeah. " And give up- You mentioned- And give up on all the lucrative salaries and- Right ... everything to start something that you truly believe in.
Otherwise- You just hit the nail on the head. You're venturing into the unknown. You're leaving a safe harbor.
Exactly. And setting sail across the sea, and you don't know where you're going to wind up. Exactly.
Right? Yes. And I think that may be the biggest reason why people talk about it and don't do it, is they're afraid, just like they were afraid to come to the new world.
Right? Right. To leave their home where their people were from.
But you mentioned something. " Yeah. What did you actually see that said, "This is going to change," or, "Here's where it needs to be changed," or, "Here's a problem that maybe was unfixable before, but now we'll be able to maybe fix it"?
" Like I said, I spent almost 20 years doing vulnerability research. So when I started my career, I was literally handwriting exploits for message plugins, signatures, and this required a lot of time and skill to exploit a vulnerability. So you had to research the vulnerability, you had to diff the different source files.
You have to figure out to craft the right exploit and then send the exploit payload over, then compromise the systems. Sometimes it works. It worked on Windows but didn't work on some other versions of Windows.
So you have to do a lot of research. You have to use reverse engineering tools like IDA Pro and so on and so forth. And so this was something, in my humble opinion, required a lot of skill and time to do master.
That thing required a lot of mastery to do it really well. And what we saw is that now, and the cost of exploitation is essentially going to zero with the AI native tools that are coming along. You could literally prompt your way to an exploit.
" Sometimes it would say, "Well, no, I cannot do it," but you can say, "Hey, my grandmother is dying. " And then the model will be, "Oh, I'm sorry to hear about your grandmother. Here's what you can give her.
" But there are other ways to do it. So this is something that we saw, that the nature of AI native offense is going to fundamentally change in the future. So when we started Quantro, we didn't plan for MITAs.
We didn't think about MITAs, but we could see the trajectory of where these things were going a year ago, that AI native offense is going to get Cheap and fast, right? So if attackers are powered with AI native offensive tools, what are defenders supposed to do? Are they supposed to just sit around and be like sitting ducks, or do we arm them with new tools to defend against AI native offense?
And this is where the genesis of Quantro came in, and our thesis was if attackers have AI native offense, we are going to provide defenders with AI native defensive tools so that they can secure their organization at scale, at speed, before the attackers can come and exploit the vulnerabilities and compromise your systems. So that was the basic premise of Quantro Security. We didn't know how to get to where we are today.
We are way advanced in our thinking than what we were when we started the company. But that was the genesis of the idea because we saw where the puck is going, and we wanted to build towards that puck rather than living in this old legacy world of tools and products that we are used to. Makes perfect sense.
Thank you for that. I got to ask you an insider question. Yeah.
Is there something behind the name Quantro that you picked at? Or it was just- Oh ... kind of, I asked AI for some good corporate names and came up with it.
So what we wanted to build is we wanted to build robots for cybersecurity, right? So the quant is the intelligent part. So it's quant is very now, when you're in the financial terms, hey, I'll let my quant do some analysis.
The quant is a reference to an intelligent thing, and ro is the robot. So Quantro is an intelligent robot. That's the- Really ...
that's the thinking behind the naming. " Sure. " So that's how we think about us.
That's your quant. That's my quant. That's my intelligent guy who was actually doing this.
So when we do our analysis, our customers can say, "Hey, that's done by our quant. " I love it. Hey, I want to jump into this report you guys recent study and so forth you had done.
But before we do, people want to get more about Quantro Security. What's the website? security.
security. That's Q-U-A-N- Cyber Defense Team. We have different agents from vulnerability scanning, to exposure management, to remediation, to compliance.
We build all these different AI agents that automate all the grunt work in your cybersecurity workforce. Love it. Go check it out.
But wait for the end of this interview maybe first, so let's finish up. Nihal, I want to pivot now and talk. " And you mentioned Mythos before, and I think before we jump into the report, we got to do a little groundwork because it's almost Mythos and everything Mythos like.
AI's ability to find vulnerabilities at a scale that we really weren't finding them at before because we just didn't have that many humans doing it, has been game changing. It's forced us to reevaluate, right? Because you can't bring AI scale to one side of an equation without upsetting the numbers on the other side of the equation.
And so you need AI scale both at some level. And one of the things, it changes the whole economics of vulnerability exploitation, obviously. Yeah.
So I got to ask you up front, was this report done before Mythos, post Mythos, during Mythos? What effect has Mythos had on it? So Mythos was not like the central reason we did this.
You could say this was during Mythos. But one of the challenges we had explaining the problem set was, everyone knew or at least had an empirical understanding that it's easier to find vulnerabilities, more vulnerabilities are going to be found, but there are no real metrics to find out. Like you would come out and see, hey, 10,000 vulnerabilities disclosed or 500 vulnerabilities disclosed, but no one really knew what was the cost, how fast can these things go and find vulnerabilities.
And we wanted to put a number out there to explain this is what it really means. And that was the basis of our research. Hey, what does it actually cost with these frontier models or open source models to actually go in and create an exploit POC with the latest technology that is out there so that it is much more easier to explain the problem, right?
Otherwise, it is a very he said, she said kind of a thing. How do we build a reproducible part of research that can be independently verified and cross-checked and validated by a third party company, right? So that was the basis of it so that we can get these numbers out there in the world.
And that's how we started with the, because we really wanted to, what is the economics of vulnerability exploitation with AI? Because the game has shifted. The game has completely shifted with AI, but how far has the game shifted was never known.
To give you an example, in my early days of Tenable, it would take me two days to write an exploit. Like doing the research, doing all the work, writing the script, and all those things. Now that is down to 30 minutes.
It's crazy. Isn't it? It is.
Look, I get the same thing in my business. I know. It's so funny.
I actually had a discussion with my wife this morning. She asked me to do something. " And she said, "I thought you're with Futurum, you're not going to have to work as hard.
Why are you working harder than ever? " She said, "But I thought AI makes your work easier. " Right?
It does amazing things. I could do so many more things, but I still have to watch them all. And the worst thing is, this is the worst version of the product you'll ever see because it's just getting better from here.
Every day. Every day. Every day.
This is the worst version of the research. Like the next- I ... research that comes out, it's going to be like five minutes from here, right?
So the things are changing- Exactly ... fast, and organizations have to take notice and take control of the situation. Absolutely.
" And we talked a little bit about the motivation already, but the motivation behind the research w-was to understand the changing economics here. Okay. Correct?
Correct. Now, I always like to ask this kind of thing anyway, because people think you just decide to do a research project, you put out some questions, you look at some things, and you write a report. With AI, it helps you write the report.
But doing research is hard. Getting people to give you answers is hard. Gaining insight is hard.
Yeah. What was the hardest part of the research for this one? The hardest part was to make these models not lie.
So one of the things that we built here at Kontro is the exploit harness. The exploit harness is the entire system that autonomously exploits vulnerabilities. And one of the requirements for the exploit harness to work properly is to set up a vulnerable system and then have the AI exploit the vulnerability.
And we would use the AI models to set up these systems as well. Sometimes it's hard to set up the software, the vulnerable version of the software. And the AI models would try for some time, and then they would give up, and they would realize, "My master, my human master, wants this outcome.
" Because our objective function was build a working exploit, right? So it would spin up a fake system, generate a fake response, and say, "Hey, I exploit it. " So getting that exploit harness really well fine-tuned so that it is not making up stuff, making it is super accurate.
It genuinely tried to exploit the vulnerability, genuinely confirmed the vulnerability without faking it, required a lot of research from our end, and we did this across thousands of vulnerabilities, right? So every vulnerability that we were exploiting, we were verifying the results. And when sometimes the results would look odd, well, this doesn't have all the characteristics of all the other exploits we have seen, but this one looks odd.
But turns out, the models were faking it. Now these models are getting so good that they will do anything that the human master wants them to do. They're basically slaves to the human masters, and they always try to please you, and they make sure that, "My master is always happy," kind of a thing.
And getting the exploit harness was really hard. And the second part was doing the human verification. And this is where we partnered with a team called Loginsoft.
They did the independent analysis of the research, the output that came out. They verified all the results. And building the harness, improving the harness was like the most difficult part from our point of view.
You work with AI enough, you can almost start smelling when they're lying. Yeah. Good point.
When they're stalling or... Yeah. You know what I mean?
You actually see it in the pattern. More and more guardrail so that it's not lying and making things up. Yeah.
Agreed. So this brings us to the heart of it, though. This is the money question.
What are the key findings here? 05, or close to $3, to build and exploit PoC end to end, from discovery to resource- To exploit ... to creating the exploit, to spinning up the lab, to testing against a positive test case- Oh my God ...
testing against a negative test case, and making sure everything works. 05, and it just takes the whole thing about 13 minutes. End to end, it takes 13 minutes, end to end.
And we did, and we analyzed- Wow ... thousands of vulnerabilities as part of this research. More than 70% of the vulnerabilities we were able to exploit with AI.
The dataset that we included as part of this research, our exploit harness was able to exploit more than 70% vulnerabilities, and many of them in the first try, it was able to do it. And as I said, this is the worst version of the exploit harness we have built because this is just going to get better from here. So we are at 75%, 70% roughly, and by the next report drops, we are going to be close to 90%.
So you can imagine what this means for the defenders, because the old tools like CVSS and EPSS, where they were predicting, and CSACV, are irrelevant and obsolete because the only metric that now counts is whether it is exploitable by AI or not exploitable by AI. All these other metrics, in my humble opinion, are irrelevant and obsolete. Meaningless.
Meaningless because- I agree with you ... you exploit with AI. For our audience out there, look, I've been in the vulnerability management world a long time, although you have, too.
We spoke about it recently. This is beyond revolutionary. It's like beyond your wildest dreams that we think we would be able to find this many vulnerabilities and then write actual exploits for them.
Correct. Right? Because how many vulnerabilities, how many CVEs sat out there that there was never an exploit in the wild for?
And they were never prioritized. The thing that I talk about in the report is there is this concept of EPSS, Exploit Prediction Scoring System. 90.
25. So because- Yeah ... they were never part of the equation because, oh, no one has written exploits, so they- No one has the time or, right.
No one has the time. Exactly. They're not going to be exploited in the wild, so let's deprioritize them.
And now it is irrelevant. So I don't know if you follow Gadi Evron and, he's with Knostic, but he has this un-- I forgot the name of the event that he puts on now. It'll be the second one, the second year coming out.
But the bottom line is him and Heather from Google, they predicted this vulnerability apocalypse. Mm-hmm. They predicted it about a year ago.
Mm-hmm. And they almost predicted it almost to the week of when we were going to cross this Rubicon of, we're finding more vulnerabilities that we could exploit than we could deal with. Right?
And that's really what the fear here is. It makes my next question almost obvious, but what does this mean for the CISOs? What does it mean for the security teams out here?
What are they supposed to do? Do they give up and go home? What do we do?
No. My fundamental thinking is this requires a complete reimagining of the architecture of cyber defense, in the sense the same way where drones change the equation on the battlefield. Right?
You have a cheap $100 drone taking out a $100 million tank. These tanks are slow. They call that asymmetric warfare, right?
It is asymmetric warfare. So, from a CISO point of view, the only vulnerabilities or the risks that matter in this were, is it vulnerable? Is it reachable?
Is it exploitable? If it meets those criterias, you have to take action. Right?
Doesn't matter if it's part of CSAC. Doesn't matter what the scoring system is. As long as it is exploitable, exposed to the internet or whatever it is, you have to take actions.
You have to take it out. And you have to do this in a very 24/7 continuous monitoring kind of a thing. You can't do it like a point in time, not even daily at this point.
You have to have AI agents do this because these are things that are not humanly possible. Right? So you have to imagine things, what is it that we cannot do that is humanly possible?
So, deploying AI native solutions, obviously, this is like I'm just talking my own book here, but it seems so obvious to me that this is the world that is coming towards you, whether you like it or not, and you have to adapt. These legacy tools may not work for you. You may have to have a fresh set of eyes to look at new tools that are coming on the market.
Let's examine that for a second. Look, you were at Tenable a long time. Tenable's still a great company.
You were at Qualys. Qualys is a great company. Rapid7.
There's the old vulnerability people that I competed against when I was doing this in 2003 and '08. And then there's all the AppSec people, right? The people who do a different kind of co-- dynamic, static testing, et cetera, but they're still finding vulnerabilities in code.
Yeah. What does this mean for all of them, for this whole industry, right? These legacy vendors, I speak to them on here all the time.
They're all trying to pivot and they're trying to, because someone moved the cheese, right? And everyone's trying to find where to go. But what does it mean?
What does it mean for them? I think they're in a difficult spot in the sense that one is they have to take care of their existing customers, their existing platforms, the platforms that they have built that is pre-AI, right? So now they have to figure out a way to transition to this AI world, which is moving fast and has some landmines that you don't want to step on, because you could make one product change, and you could offend all your customers.
Right? So, you could push something that is AI, because they have gone from a very deter-- We are going from a very deterministic results and outputs to a very heuristic outcome because the AI, the same result you run tomorrow could be different from an AI's point of view because it's based on heuristics. It's not deterministic.
It is not the same result, and so on and so forth. So you cannot make a big change to your product line, to your company strategy. You could always claim that we are getting towards AI and whatnot.
So I think they face two problems. One is obviously the architectural and the platform engineering that has to happen. And the second is the moats are falling apart.
You can now build a scanner with AI, and you can build all the signatures with AI. We just showed you that we can create exploits end to end working in 13 minutes. So where is the moat?
What moats do they have? Do they have to adapt quickly? So they have to adapt quickly, and if they don't adapt, new players will come in and take the place that they have.
So that is like the perennial challenge. Obviously partner with newer companies or get acquired by a bigger company. Well, but that's, and that is the security way, right?
The little fish get eaten by the medium fish, and the big fish eat the medium fish, and yet the bigger fish eat the big fish. Sometimes the little fish- And that's what they- Sometimes the little fish figures out to go to the bigger smaller pond, and there is no one, and it gets bigger. Every once in a while, exactly.
One makes it up through. In every generation, there's a few. Yeah.
Like The Wizz. Right? Who- The Wizz of the world.
The Wizz, a perfect example Perfect example. But seriously, they need innovation and very often legacy vendors buy innovation, and that's really the point. They don't create innovation.
Either they buy or they get bought. Or they get bought themselves because they become somewhat irrelevant. But Mahul, we're almost out of time.
security. The research report itself, the economics of vulnerability exploitation, can they get it off the website? Is that the best place?
They can get it off the website. We also have a dedicated website for this research report where the entire narrative and the story unfolds. It is vulnerability research lab.
Can you repeat that again? I'm sorry. Can you- Yeah.
The- The dedicated website is? ai. That is our research- Okay ...
unit that we have done in partnership with Loginsoft, which independently verified the results. Obviously, the results are available on our website, but we have created this dedicated website so that it doesn't clutter with the messaging and the narrative and so on. So you can go and check out the research, download the report, and partner with us if you want to, and see how we can change the economics of vulnerability exploitation.
One last thing. Hey, I'm coming on your podcast. A little round about.
I'm going to be on the other side of the camera. What's the name of the podcast? Where can people follow that?
" It is inspired by your theory, which is no hype, more signal. I think that is what you always claim. So I cannot go with hype and signal, I have to go with something else.
" So you'll be coming on "Noise to Signal," where we'll be talking about your career and your journey because I think the thing that is not app-- This is like a glitch in the matrix. You've interviewed thousands of people, right? But I haven't seen a deep dive interview of you because you are the OG in this space.
You're the OG in- Yeah. I'm a mystery wrapped in an enigma. An enigma wrapped in a mystery.
But I'm looking forward to coming on. We'll check it out. Awesome.
" Mahul, thank you so much. security. security.
Awesome. We're going to take a break. We'll be back with more "Techstrong TV" in just a minute.