TLDRocket
Sign in

AI floods security teams with flaws — business context sets priorities

The New Stack Megan Carnegie

Security scans keep flagging “urgent” flaws that turn out to be low risk. The real job isn’t finding issues — it’s knowing which ones actually matter.

Based on reporting by The New Stack, Megan Carnegie — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

A security researcher scanning a 300-person B2B company with a global footprint found an internet-exposed database with weak authentication. On paper, it looked like a serious, obvious fix-first problem. Then came the twist: it was a resettable test database used to evaluate job candidates, not a system holding client data.

That little detour captures the core problem. Scanners and researchers can surface a lot of findings, but they can’t tell a business how much damage a compromise would really cause without context. Jon Rose, founder of IOmergent, says security work is full of competing priorities and that teams have to be ruthless about where they spend time.

The pressure is not just from security tools. Companies are already dealing with more feature requests, more technical debt, reorgs, and in some cases people who are also expected to monitor and correct AI agents. Security teams then get buried under identity events, firewall logs, endpoint alerts, vendor feeds, and threat intel, all of which can look urgent at first glance.

That is why severity scores like CVSS are only a starting point. A score can describe how a flaw works, but it does not tell you whether the affected service is public, isolated, tied to customer transactions, or protected by controls. Rose’s advice is to start with reachability, then ask what the weakness actually leads to, and whether it sits on a system that matters to the business.

The source also points to exploit signals that help separate theory from active danger, including CISA’s Known Exploited Vulnerabilities catalog and the Exploit Prediction Scoring System. But none of that replaces judgment. The real risk, Rose says, is unacknowledged backlog — an exception that nobody owns, nobody reviews, and nobody can defend later.

AI is making both sides of the problem worse. It helps teams find more issues, but it also speeds up exploit research and can introduce new vulnerabilities of its own. The practical answer is boring and necessary: use AI to answer the analyst’s basic questions fast, then let people make the business call on what gets fixed first.

My take — AI-written commentary, not fact-checked reporting

The industry keeps pretending that more alerts equal more security, which is adorable in the way a spreadsheet is adorable. Without business context, vulnerability management is just expensive panic with nicer dashboards. The sane move is to rank by reachability, impact, and ownership — not by whatever score fell out of the scanner that morning.

Read more about this at: The New Stack

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.