Remediating Vulnerabilities With LLMs: Inside Ivanti’s Automation Push

As cybersecurity teams struggle to keep pace with the ever-evolving landscape of threats, one software vendor is exploring an innovative approach to vulnerability remediation: leveraging large-language models (LLMs) to identify and fix flaws in their products. Ivanti’s chief security officer, Daniel Spicer, recently shared insights into the company’s project, which has already yielded surprising results.

Ivanti’s decision to deploy LLMs was sparked by a critical vulnerability discovered last month in its Sentry mobile gateway product. Rather than being identified by a human researcher or third-party vendor, the flaw was pinpointed by an LLM. This breakthrough prompted Ivanti to accelerate its use of advanced models to augment its engineering and security red teams. The goal is to increase the efficiency and effectiveness of vulnerability identification and remediation, particularly for flaws that evade traditional tooling.

The project, initiated in mid-February, has two primary tracks: finding vulnerabilities that existing tools miss, and automatically resolving weaknesses identified by static application security testing (SAST) and dynamic application security testing (DAST) scanners. The latter involves using LLMs to pre-resolve issues before submitting them back to engineers for review.

Spicer explained that the use of LLMs has shown surprising effectiveness in the early stages, but several challenges remain. One key concern is cost: while Ivanti has invested in direct licenses with Anthropic, the vendor behind Project Glasswing, it’s unclear whether this approach will scale financially for other organizations. Another issue is human-in-the-loop viability – how to balance the efficiency of LLM-driven remediation with the need for human oversight and review.

In terms of concrete results, Spicer couldn’t provide exact numbers yet on vulnerabilities found or fixed, but promised that Ivanti would release some research in the coming months. However, he did mention that the team has seen significant improvements in vulnerability resolution rates since implementing LLMs.

While Ivanti’s experience with LLMs is promising, it also raises important questions about the role of AI in cybersecurity and the potential implications for traditional security practices. As threats continue to evolve at a rapid pace, the use of advanced models like LLMs may become an essential component of vulnerability remediation strategies – but only if organizations can navigate the challenges surrounding cost, human oversight, and model limitations.

For security teams looking to explore similar approaches, Ivanti’s experience offers valuable lessons. While LLM-driven remediation shows promise, it’s crucial to carefully consider the costs and feasibility of implementation within your organization. Furthermore, it’s essential to strike a balance between leveraging AI for efficiency gains and maintaining human oversight to ensure accuracy and effectiveness in vulnerability remediation.


Source: Dark Reading — 2026-07-20