New predictive remediation capability signals a fundamental shift in how enterprises must think about security in the age of AI-accelerated development
The cybersecurity industry has spent decades building better ways to find vulnerabilities. Averlon thinks that’s no longer enough — and with the launch of Precog, the company is making a pointed argument that the only real answer is stopping exploitable risk before it ever reaches production.
Precog is a predictive remediation capability that plugs into CI/CD pipelines — including GitHub — and evaluates proposed code and infrastructure changes for real exploitability before they are merged. When a risky change is detected, developers don’t just get a warning: they get the fix, delivered right alongside the alert, in their existing workflow.
The timing of this launch is deliberate. Google Cloud’s Mandiant M-Trends 2026 report delivers a sobering data point: mean time to exploit has collapsed from 63 days in 2018 to an estimated negative seven days in 2025. That’s not a typo. Exploitation is now beginning before patches are even available. Layer on top of that the emergence of frontier AI models specifically tuned for offensive security work — the report calls out Claude Mythos and GPT-5.5-Cyber by name as signals of what’s coming — and the math for security teams becomes brutal. The window between exposure and exploitation is no longer shrinking; in many cases, it has already closed.
“Security teams have relied on finding and fixing vulnerabilities after they reach production,” said Sunil Gottumukkala, CEO of Averlon. “AI has made that untenable from both directions: it is generating new vulnerabilities faster than teams can triage them, and it is collapsing the window between exposure and exploitation. You cannot remediate your way out of that.”
What separates Precog from a conventional security scanner is context. Rather than flagging findings based on generic CVSS severity scores, Precog evaluates whether a proposed change would actually be exploitable in the customer’s specific environment — accounting for internet reachability, exposed services, and existing compensating controls. The result is a much shorter list of findings that genuinely matter, rather than the long tail of theoretically risky items that would never be exploitable in practice.
This sits on top of Averlon’s broader Remediation Operations platform — what the company is positioning as a new operating model it calls RemOps. The core premise is simple but consequential: finding risk and closing risk are fundamentally different problems, and the industry has over-invested in the former. Averlon’s platform ingests security findings from across the environment, determines what is truly exploitable, prioritizes by business impact, and drives automated remediation through developer workflows. The company says customers have reduced remediation time by up to 90 percent and alert noise by up to 95 percent — cutting SOC backlogs from thousands of open findings down to a handful requiring action.
Precog extends this model to the left, catching the risk before it ever becomes a production finding in the first place.
Rounding out the announcement is Vulnerability Intelligence, Averlon’s CVE research feed available at research.averlon.ai. It gives security teams contextual data on emerging vulnerabilities — exploitability, attacker requirements, privilege levels, user interaction requirements, and evidence of active exploitation in the wild — giving teams the signal they need to triage emerging threats without wading through noise.
Chris Steffen, VP of Research at Enterprise Management Associates, framed the broader industry shift well: “AI is changing both sides of the software lifecycle. It is accelerating development while also introducing code that is often not ready for production. With AI also accelerating the discovery and exploitation of weaknesses in that software, security teams can no longer rely only on post-production detection and backlog management.”
For VMblog readers managing security programs, CI/CD pipelines, or DevSecOps initiatives, the message from Averlon is worth sitting with. The industry has been talking about shifting security left for years. Precog is a concrete product argument that the conversation needs to move even further — not just earlier in the SDLC, but before the code ever touches a production environment.





