IVANTI is leveraging large language models (LLMs) to improve the identification and remediation of software vulnerabilities, a move prompted by the effectiveness of these models in the cybersecurity domain. Daniel Spicer, Ivanti's Chief Security Officer, explained that the company started using LLMs to both find and fix vulnerabilities that traditional tools often miss.
Notably, Ivanti's automation efforts have allowed them to discover significant security flaws, evidenced by the unraveling of CVE-2026-10520, a major vulnerability initially flagged by LLMs rather than human researchers. Spicer highlighted challenges surrounding the cost of using LLMs and the quality of AI-generated bug reports, expressing optimism about reducing 'slop' and improving report accuracy this year compared to the previous one.
However, he remains cautious about the potential use of these models in offensive cyberattacks and emphasized ongoing work to refine and enhance their processes. The project's continual evolution reflects both the rapid advancements in AI capabilities and the need for robust security practices to keep pace with evolving threats.