Skip to content

Security1 publisher2 min readPublished

Gremlin reports clearing nine times as many vulnerabilities with the same staff

Frederic Bull says his team processed just over nine times the vulnerability volume in a year without adding headcount and cut time to remediate by 5%, a self-reported figure with no absolute counts behind it.

The Watch · Security desk

Photograph accompanying Gremlin reports clearing nine times as many vulnerabilities with the same staff
Photo: helpnetsecurity.com

What happened

  • Frederic Bull, Security Officer at Gremlin, told Help Net Security the team processed just over nine times as many vulnerabilities in the past year as the year before, at the same staffing level.
  • He credited LLMs and supporting harnesses for absorbing the increase without extra headcount, and said time to remediate fell by just over 5% across the same period.
  • He said NVD has reprioritized classifications and left a large number of reported vulnerabilities unclassified because it cannot keep up with the volume of reports.

Compiled by The WatchSomething wrong?How this is made

Why it matters

  • capability In Bull's account, exploit development no longer needs the expertise it used to, so the defender's historic edge in skill narrows to a numbers contest between red and blue.
  • constraint If NVD leaves reported flaws unclassified, teams cannot rank a swollen queue on severity data that was never assigned, and the ranking work lands on them.
  • exposure The scoping guarantee covers what an agent may technically call, which leaves agent-to-agent chains relying on operators catching a bad action before it lands.
  • decision Holding headcount flat commits the team to a review layer staffed by people senior enough to overrule confident but wrong tool output, changing who gets hired next.

Nine times the volume at the same headcount is nine times the throughput per person [1]. As a delta, intake rose about 800 percent while time to remediate fell by just over 5 percent [2]. The leverage landed on how many findings moved through the queue, and barely on how fast any one of them closed.

This is one security officer's self-reported number from an interview, not an audited one. It comes without absolute counts or a definition of what processing a vulnerability covers [15]. A move from 200 findings to 1,800 is a different engineering problem than 20,000 to 180,000, and deduplication, auto-closure and false-positive suppression all count as processing. Bull said the increase "certainly left a gap in our process" [9], and credited AI tools, "largely LLM's and supporting harnesses" [8].

On models, Bull said the question he hears most often is "What data was this model trained on?" [2] The one he hears rarely: "How do you maintain authority and integrity of the data in question." [3] His answer is old machinery. Least privilege through authentication and access controls, session-based RBAC via OIDC/OBO, permissions scoped to the context [4]. "By continuing to implement modern solutions like session-based RBAC and appropriately scoped permissions, we can guarantee that AI agents never exceed their technical capability," he said [5].

Guarantee is a strong word, and in that sentence it is bounded by technical capability. Bull adds a second control for the case that is growing: as agent-to-agent communication becomes more prevalent, he said, the same strategies support stricter human-in-the-loop architectures so operators can "recognize and correct issues before damage occurs" [6]. Scoping decides what an agent is permitted to call. A chain of agents, each inside its own scope, can still produce an action nobody approved.

Bull's threat model is about who can build an exploit now. He called the change "an erosion of the asymmetry of ability that the security industry has historically benefitted from" [11], with exploits now devised and deployed by people who lack the underlying skill, and increasingly faster than the people who have it [12]. If symmetry arrives, he said, "In essence a question of how large the red team is compared to the blue." [13]

He also said NVD has had to reprioritize classifications, leaving a large number of reported vulnerabilities unclassified because it cannot handle the volume of reports [10]. A team absorbing nine times the intake has to do that triage in-house.

Bull said hiring now favors people with the experience to catch confident but wrong AI output [14].

What to watch

  • Whether Gremlin publishes absolute counts and a definition of processed, including dedup and auto-closure rates, behind the 9x.
  • Whether NVD's own status reporting confirms the scale of unclassified reported vulnerabilities Bull describes.
  • Whether scoped session-based RBAC holds as a containment control once agent-to-agent calls replace human approval steps in production.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories