Ondrej Vlcek, CEO of AISLE and former CEO of Avast, on why AI vulnerability discovery is not as commoditized as the industry thinks, and why remediation is still the real bottleneck.
In this episode I sit down with Ondrej Vlcek, Founder and CEO at AISLE. Ondrej spent roughly 30 years in cybersecurity, joining Avast as employee number six or seven doing kernel-mode driver work on Windows 95, eventually becoming CTO and then CEO, taking the company public and selling it to NortonLifeLock in a nearly $9 billion transaction. He co-founded AISLE in the fall of 2024 to close the loop from discovery through triage, remediation, and verification. His team has now disclosed 350 plus CVEs across projects like OpenSSL and curl.
We get into why the moat sits in the system and not the model, why the gray market price of vulnerabilities has not collapsed even as models get cheaper, and what it actually takes to ship a patch a maintainer will accept.
In this episode: - Going from Avast intern to CEO, and why vulnerability management was the next problem - The jagged frontier, and why bigger models do not always mean better results - Which classes of bugs got cheap to find and which are still genuinely hard - Why vulnerability prices have not collapsed despite all the model progress - Building a model-agnostic system with bespoke benchmarks for model selection - Sovereign AI, on-prem and air-gapped deployment, and why findings are the real crown jewels - Triage, reachability, and why most findings are not actually exploitable - Patch verification, regression risk, and mitigations for embedded systems that cannot be patched - How AISLE earned trust from curl after Daniel Stenberg killed the bug bounty - Whether a CVE count is a vanity metric - Build versus buy as model capability keeps getting cheaper - What breaks first in the CVE and open source maintainer ecosystem - What AppSec leaders should change next quarter
Chapters 0:00 Intro 0:24 From Avast employee number six to a $9 billion exit 3:26 Why vulnerability management, and why now 5:15 The jagged frontier and what bigger models miss 10:36 The economics of finding bugs, and why prices have not collapsed 12:11 Building a model-agnostic system with real benchmarks 14:30 Sovereign AI, air-gapped deployment, and who sees your findings 19:42 Triage, reachability, and why remediation is the bottleneck 24:48 Patches that break things, and systems you cannot redeploy 25:39 curl, Daniel Stenberg, and death by a thousand slops 29:35 Is a CVE count a vanity metric? 31:34 Build versus buy when capability keeps getting cheaper 34:41 What breaks first in the next 18 months 39:46 What AppSec leaders should do next quarter 41:13 Closing
Podden och tillhörande omslagsbild på den här sidan tillhör
Chris Hughes. Innehållet i podden är skapat av Chris Hughes och inte av,
eller tillsammans med, Poddtoppen.