There usually is a crucial time lapse from when a vulnerability is newly disclosed to when security scanners are finally updated to scan for it. Nucleus Security says it wants to close that gap.
The cybersecurity outfit focused on unified exposure management is expanding its platform with Nucleus Helix, an AI Agent for natural-language interaction with security data and workflows. The expansion adds two other capabilities: Nucleus Discover for early exposure detection and expanded Nucleus Insights for vulnerability and threat intelligence.
The company says the expansion is aimed at the growing remediation pressure with rapid AI-assisted vulnerability discovery. Nucleus Discover, it said, is designed to bridge that gap by identifying potential exposure before scanner signatures become available or the next scan cycle runs.
It specifically pointed to the three-day window for the highest-risk vulnerabilities under CISA’s BOD 26-04, adding that such directives are pushing the “pressure to detect and remediate critical exposures.”
“We are not positioning (Helix) as ‘AI versus human analysis,’” Scott Kuffer, co-founder and chief product officer at Nucleus Security, told CSO. “What matters is whether it helps teams reach the right decision faster and more consistently.” The company claims the expansion will use the new AI for reasoning and investigation while relying on its existing automation capabilities to keep executing approved workflows.
Acting on vulnerability NEWS before a scanner picks it
One of the key offerings of the expansion is Nucleus Discover’s Early Warning System, or NEWS. It aims to combine Nucleus Insights’ real-time vulnerability and threat intelligence with information Nucleus already collects about a customer’s environment, including software, asset ownership and existing exposure data.
The company said it can identify systems that may be affected by a newly disclosed vulnerability before scanner coverage is available.
Kuffer said the goal is not to replace active scanner validation. Instead, NEWS is intended to give security teams an earlier and more targeted starting point for investigating potentially affected systems.
Rather than attempting to continuously scan an entire enterprise, Nucleus proposes that teams use the indicators generated from previous scans, asset context, software inventories, and other automatically collected information to narrow the scope of active scanning and use them to confirm potential exposure.
Kuffer cited CVE-2026-44416 as one example. As of August 21, Nucleus says it had found and confirmed the CVE, which carries a CVSS score of 9.8 and was first published on August 20, in numerous customer environments.
“Not only did Nucleus detect this vulnerability, but we also have patch guidance available, along with a threat-informed rating for this CVE, which we downgraded to Medium from the 9.8 CVSS score,” Kuffer said. “Leading scanners such as Tenable still do not have a plugin published to find this vulnerability.”
He did not provide a specific measurement comparing the discovery time with a conventional scanning workflow.
Helix separates AI reasoning from execution
The Helix AI Agent provides a natural-language interface for security practitioners, CISOs, and developers to interact with exposure data, workflows, and program configuration.
Today, Kuffer said, the agent’s role is primarily research and reasoning. It can search and investigate exposure data, explain vulnerabilities, surface remediation guidance, create queries, and help build dashboards and automations, he added.
For production processes, the Helix agent can effectively “write the code” of the Nucleus platform through its interface, letting the Automation engine then execute the logic. “AI helps determine what should happen; deterministic automation makes sure it happens consistently,” Kuffer said.
In a press release shared with CSO ahead of its publication Tuesday, Nucleus said Helix’s reasoning is grounded in Nucleus Insights and the Nucleus Data Core, including exploit intelligence, CISA SSVC data, Patch Tuesday information and remediation context.
The company added that it treats upstream data, including AI-generated data, as untrusted and applies its existing verification approach to assess the quality and relevance of remediation, guidance, queries, investigation results and prioritization. Nucleus Insights is available now. The Helix AI Agent and Nucleus Discover with Early Warning are scheduled to become available in September.
No Responses