OpenAI’s Aardvark: A Welcome Step Forward in AI-Driven Security, But Just the Beginning

RiskOn Thursday, OpenAI introduced Aardvark, their Security Research Agent designed to help developers and security teams discover and fix vulnerabilities at scale. As someone who’s spent the past year building AI remediation solutions at Backline, I found myself reflecting on what this announcement means for our industry. My reaction? Genuinely positive. This validates what we’ve […]
Episode 4 – It’s the fix that matters

In this episode, Maor and Eran sit down with Paul Trulove, Chief Product Officer at AppViewX and former CPO at SailPoint, to explore what truly defines success in security products. They discuss why the industry still celebrates detection over resolution, the difference between orchestrating remediation and actually fixing what’s broken, and how the next generation of tools and teams can make “time to fix” the metric that really matters.
From Chaos to Confidence: Vulnerability Remediation With Guided AI

When I meet security leaders and engineering managers, I often hear the same concern about automation in remediation: “If we let an AI tool fix things automatically, how do we stay confident in the process?” This question isn’t theoretical; it plays out every day inside organizations. Security teams chase growing backlogs, SLAs loom, and regulators […]
Stop the whack-a-mole game: Turning npm Supply-Chain Chaos into Automated Remediation

In the span of a few weeks, the JavaScript ecosystem has been hit by back-to-back software supply-chain incidents. First came the s1ngularity/Nx compromise in late August. Then, this week, the Shai-Hulud campaign arrived with a twist: a self-replicating, worm-style payload that moved quickly through the npm ecosystem. Public write-ups from SCA and CNAPP vendors have […]
Episode 3 – Fixing is Loving

In this episode of Backline Unfiltered, we’re joined by David Cross, CISO of Atlassian and new member of Backline.ai’s advisory board, for a candid conversation about bridging the gap between security and engineering.
Together with Eran Leib and Maor Goldberg, we dive into why the traditional model of security “finding” and engineering “fixing” leads to friction—and how we can flip that script.
We talk about the real goal: fixing vulnerabilities, not filing tickets. And how Backline is enabling teams to move from pointing fingers to solving problems—faster, together.
When AI Breaks Trust: The Problem with Unreliable Security Fixes

AI is infiltrating every corner of the software development lifecycle (SDLC), from code generating functions to generating entire test suites. These tools promise productivity boosts and reduced development time, but when it comes to critical tasks like fixing security vulnerabilities, many developers are hesitant to adopt AI-based solutions. In this blog, we unpack why developers […]
The Realities of Security Remediation—Voices from the Trenches

Let’s talk honestly about the remediation grind facing security teams in 2025.
The Rise of AI Agents in Cybersecurity: Insights from RSA Conference 2025

RSA Conference 2025 in San Francisco confirmed that AI agents are rapidly transforming cybersecurity, moving from simple copilots to autonomous systems capable of executing complex, multi-step tasks. This shift is already reshaping how organizations detect, respond to, and manage cyber threats, but the journey toward full automation, where AI can not only identify but also […]
Why Now?

Timing is everything. In sports, a fraction of a second could determine victory or defeat.
The State of Remediation: Why Security Backlogs Keep Growing

In the ever-evolving world of cybersecurity, organizations are facing an overwhelming challenge: the growing backlog of unresolved security findings. Despite advances in detection technologies, the gap between identifying security findings and remediating them continues to widen. Security Findings? Let’s define what we mean by Security Findings. Sometimes also referred to as vulnerabilities, these security findings […]