As AI-powered cyber threats continue to escalate, a growing number of companies are turning to Large-Language Models (LLMs) for vulnerability remediation. One such firm is Ivanti, which has been at the forefront of this trend after discovering a critical flaw in its Sentry mobile gateway product using an LLM. We spoke with Daniel Spicer, Ivanti’s Chief Security Officer, about the company’s pioneering use of LLMs and what it means for the future of cybersecurity.
Ivanti’s decision to deploy LLMs was sparked by the growing realization that these advanced models could be a game-changer in vulnerability remediation. In late February, Spicer and his team began exploring the potential of Claude 4.6 models, which they found to be surprisingly effective in identifying vulnerabilities that traditional tools often miss. Building on this success, Ivanti kicked off an internal project to develop use cases for LLMs in both vulnerability discovery and resolution.
One of the key challenges that Spicer’s team faced was finding the right balance between automation and human oversight. “We had two tracks: one focused on automatically resolving vulnerabilities, and the other aimed at helping us find vulnerabilities that our existing tooling missed,” he explained. By using LLMs to identify weaknesses in code, Ivanti can now clear out these issues before they become exploitable vulnerabilities.
So far, the results have been impressive. While Spicer was hesitant to disclose exact numbers, he hinted at a significant reduction in vulnerability counts since implementing the LLM-powered approach. “We’re planning on releasing some of this research in the coming months,” he promised. Ivanti’s decision to invest in direct licenses with Anthropic has also paid off, allowing them to tap into the expertise and capabilities of the leading AI firm.
The use of LLMs in vulnerability remediation raises several questions about cost and scalability. “We’re still grappling with these issues,” Spicer acknowledged, but emphasized that Ivanti is committed to finding solutions. The company’s experience highlights the need for more research and development in this area, as well as greater collaboration between industry leaders.
As AI-powered threats continue to evolve, companies like Ivanti are taking a proactive stance by embracing innovative technologies like LLMs. While there are still challenges to overcome, the potential benefits of this approach cannot be overstated. By automating vulnerability remediation and improving code quality, organizations can reduce their attack surface and stay ahead of emerging threats.
In practical terms, Spicer’s advice for other companies is clear: “Don’t wait – start exploring LLMs now.” With Ivanti leading the charge in this field, it’s essential for security professionals to stay informed about the latest developments. By investing time and resources into understanding the potential of LLMs, organizations can future-proof their defenses against AI-powered threats and protect themselves from even the most sophisticated attacks.
Source: Dark Reading — 2026-07-20