{"id":9226,"date":"2026-08-25T13:00:00","date_gmt":"2026-08-25T13:00:00","guid":{"rendered":"https:\/\/cybersecurityinfocus.com\/?p=9226"},"modified":"2026-08-25T13:00:00","modified_gmt":"2026-08-25T13:00:00","slug":"nucleus-wants-to-get-ahead-of-scanners-on-new-vulnerabilities","status":"publish","type":"post","link":"https:\/\/cybersecurityinfocus.com\/?p=9226","title":{"rendered":"Nucleus wants to get ahead of scanners on new vulnerabilities"},"content":{"rendered":"<div>\n<div class=\"grid grid--cols-10@md grid--cols-8@lg article-column\">\n<div class=\"col-12 col-10@md col-6@lg col-start-3@lg\">\n<div class=\"article-column__content\">\n<div class=\"container\"><\/div>\n<p class=\"wp-block-paragraph\">There usually is a crucial time lapse from when a vulnerability is newly disclosed to when security scanners are finally updated to scan for it. Nucleus Security says it wants to close that gap.<\/p>\n<p class=\"wp-block-paragraph\">The cybersecurity outfit focused on unified <a href=\"https:\/\/www.csoonline.com\/article\/4206354\/why-exposure-management-is-replacing-vulnerability-management.html\">exposure management<\/a> is expanding its platform with Nucleus Helix, an AI Agent for natural-language interaction with security data and workflows. The expansion adds two other capabilities: Nucleus Discover for early exposure detection and expanded Nucleus Insights for vulnerability and threat intelligence.<\/p>\n<p class=\"wp-block-paragraph\">The company says the expansion is aimed at the growing remediation pressure with rapid <a href=\"https:\/\/www.csoonline.com\/article\/4198016\/socs-face-a-human-challenge-as-ai-speeds-alerts-and-threats.html\">AI-assisted<\/a> vulnerability discovery. Nucleus Discover, it said, is designed to bridge that gap by identifying potential exposure before scanner signatures become available or the next scan cycle runs.<\/p>\n<p class=\"wp-block-paragraph\">It specifically pointed to the three-day <a href=\"https:\/\/www.csoonline.com\/article\/4183750\/cisa-tells-agencies-to-patch-smarter-not-harder-foreshadowing-broader-industry-practice.html\">window<\/a> for the highest-risk vulnerabilities under CISA\u2019s BOD 26-04, adding that such directives are pushing the \u201cpressure to detect and remediate critical exposures.\u201d<\/p>\n<p class=\"wp-block-paragraph\">\u201cWe are not positioning (Helix) as \u2018AI versus human analysis,\u2019\u201d Scott Kuffer, co-founder and chief product officer at Nucleus Security, told CSO. \u201cWhat matters is whether it helps teams reach the right decision faster and more consistently.\u201d The company claims the expansion will use the new AI for reasoning and investigation while relying on its existing automation capabilities to keep executing approved workflows.<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>Acting on vulnerability NEWS before a scanner picks it<\/h2>\n<p class=\"wp-block-paragraph\">One of the key offerings of the expansion is Nucleus Discover\u2019s Early Warning System, or NEWS. It aims to combine Nucleus Insights\u2019 real-time vulnerability and threat intelligence with information Nucleus already collects about a customer\u2019s environment, including software, asset ownership and existing exposure data.<\/p>\n<p class=\"wp-block-paragraph\">The company said it can identify systems that may be affected by a newly disclosed vulnerability before scanner coverage is available.<\/p>\n<p class=\"wp-block-paragraph\">Kuffer said the goal is not to replace active scanner validation. Instead, NEWS is intended to give security teams an earlier and more targeted starting point for investigating potentially affected systems.<\/p>\n<p class=\"wp-block-paragraph\">Rather than attempting to continuously scan an entire enterprise, Nucleus proposes that teams use the indicators generated from previous scans, asset context, software inventories, and other automatically collected information to narrow the scope of active scanning and use them to confirm potential exposure.<\/p>\n<p class=\"wp-block-paragraph\">Kuffer cited <a href=\"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-44416\" target=\"_blank\" rel=\"noopener\">CVE-2026-44416<\/a> as one example. As of August 21, Nucleus says it had found and confirmed the CVE, which carries a CVSS score of 9.8 and was first published on August 20, in numerous customer environments.<\/p>\n<p class=\"wp-block-paragraph\">\u201cNot only did Nucleus detect this vulnerability, but we also have patch guidance available, along with a threat-informed rating for this CVE, which we downgraded to Medium from the 9.8 CVSS score,\u201d Kuffer said. \u201cLeading scanners such as Tenable still do not have a plugin published to find this vulnerability.\u201d<\/p>\n<p>He did not provide a specific measurement comparing the discovery time with a conventional scanning workflow.<\/p>\n<h2 class=\"wp-block-heading\"><a><\/a>Helix separates AI reasoning from execution<\/h2>\n<p class=\"wp-block-paragraph\">The Helix AI Agent provides a natural-language interface for security practitioners, CISOs, and developers to interact with exposure data, workflows, and program configuration.<\/p>\n<p class=\"wp-block-paragraph\">Today, Kuffer said, the agent\u2019s role is primarily research and reasoning. It can search and investigate exposure data, explain vulnerabilities, surface remediation guidance, create queries, and help build dashboards and automations, he added.<\/p>\n<p class=\"wp-block-paragraph\">For production processes, the Helix agent can effectively \u201cwrite the code\u201d of the Nucleus platform through its interface, letting the Automation engine then execute the logic. \u201cAI helps determine what should happen; deterministic automation makes sure it happens consistently,\u201d Kuffer said.<\/p>\n<p class=\"wp-block-paragraph\">In a press release shared with CSO ahead of its publication Tuesday, Nucleus said Helix\u2019s reasoning is grounded in Nucleus Insights and the Nucleus Data Core, including exploit intelligence, CISA SSVC data, Patch Tuesday information and remediation context.<\/p>\n<p class=\"wp-block-paragraph\">The company added that it treats upstream data, including AI-generated data, as untrusted and applies its existing verification approach to assess the quality and relevance of remediation, guidance, queries, investigation results and prioritization. Nucleus Insights is available now. The Helix AI Agent and Nucleus Discover with Early Warning are scheduled to become available in September.<\/p>\n<\/div>\n<\/div>\n<\/div>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>There usually is a crucial time lapse from when a vulnerability is newly disclosed to when security scanners are finally updated to scan for it. Nucleus Security says it wants to close that gap. The cybersecurity outfit focused on unified exposure management is expanding its platform with Nucleus Helix, an AI Agent for natural-language interaction [&hellip;]<\/p>\n","protected":false},"author":0,"featured_media":9227,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[],"class_list":["post-9226","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-education"],"_links":{"self":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9226"}],"collection":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=9226"}],"version-history":[{"count":0,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/posts\/9226\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=\/wp\/v2\/media\/9227"}],"wp:attachment":[{"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=9226"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=9226"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybersecurityinfocus.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=9226"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}