CFOtech Australia - Technology news for CFOs & financial decision-makers
Australia
Astelia launches agentic AI to cut vulnerability noise

Astelia launches agentic AI to cut vulnerability noise

Fri, 24th Jul 2026 (Today)
Mark Tarre
MARK TARRE News Chief

Astelia has launched agentic artificial intelligence functions for its exposure management platform, adding automated reachability analysis and remediation workflows across the vulnerability lifecycle.

The new functions assess newly disclosed vulnerabilities, determine whether they are reachable in a customer's environment, evaluate operational impact, and coordinate remediation steps between security and IT teams. Human approval remains in place at key decision points, and each action is logged for audit purposes.

The launch comes as security teams face a rising volume of disclosed vulnerabilities and shorter exploit timelines. Astelia argues that many alerts do not reflect genuine exposure because a flaw may exist in software yet still be inaccessible to an attacker in a specific network environment.

Its platform is built around reachability analysis, which examines whether a vulnerability can be reached and exploited in a particular organisation. It does this by correlating network topology with the technical conditions required to exploit a vulnerability.

According to Astelia, that approach shows that less than 1% of findings represent real exposure. In one enterprise deployment, it reduced about 40 million identified vulnerabilities to fewer than 2,000 that were actually reachable.

Once a reachable issue is identified, the platform recommends ways to remove the exposure. Measures can include configuration changes, network segmentation, compensating controls, or a software patch, depending on the environment.

Why reachability matters

The launch reflects a wider shift in cybersecurity operations as teams try to prioritise the small number of vulnerabilities that present immediate risk rather than work through large volumes of alerts. That challenge has grown as artificial intelligence tools have increased the speed of vulnerability discovery and exploitation.

Alon Noy, Co-Founder and Chief Executive Officer of Astelia, linked the product update to that pressure on defenders.

"The release of Claude Mythos marked a turning point for vulnerability management," said Noy. "It showed that vulnerability discovery and exploitation could happen at machine speed. Organisations can no longer afford to treat every vulnerability the same. Understanding which ones are actually reachable is what allows security teams to respond before exposure becomes an incident."

The new agentic layer is designed to automate repetitive analysis and coordination work while leaving final security decisions under human control. The platform also integrates with more than 100 MCP-enabled systems.

Operational pressure

Security teams often have to manage growing numbers of exploitable vulnerabilities without a matching increase in staffing. In response, vendors have increasingly focused on tools that aim to improve prioritisation, reduce manual triage, and connect remediation work across teams.

Nadav Ostrovsky, Co-Founder and Chief Technology Officer of Astelia, said the company sees reachability analysis as the basis for both prioritisation and response.

"Reachability gives security teams the evidence they need to act more precisely," said Ostrovsky. "The same network intelligence that tells us a vulnerability is reachable also tells us how to make it unreachable. We're seeing strong traction with Fortune 100 enterprises because that approach helps security teams keep pace with the growing volume of newly disclosed vulnerabilities and exploits. The new agentic layer builds on that foundation while keeping security teams in control."

A customer example in the announcement highlighted the scale of the filtering problem facing large organisations. An unnamed Chief Information Security Officer at a Fortune 100 financial enterprise described a reduced alert burden and faster triage.

"Astelia got our security team out from under millions of CVE alerts we were never going to work through, and pointed us at the fraction of vulnerabilities attackers could actually reach. Each exposure comes with evidence and mitigation options, which cut our triage time by over 80%," said the Chief Information Security Officer of a Fortune 100 financial enterprise.

Astelia's argument is that exposure management should focus less on the total number of known vulnerabilities and more on the subset that can be exploited in practice within a live environment. Its latest launch extends that view by adding automation to analysis and remediation workflows while retaining approval gates for human operators.