Uploaded May 2026 | Updated September 2026, 1 hour ago
Jorge Gimenez (Kraken, ES)
Modern vulnerability management suffers not from a lack of data, but from an overload of it. Security teams receive thousands of vulnerability findings from scanners, cloud platforms, and bug bounty programs, each providing fragmented and incomplete context. As a result, vulnerabilities are often evaluated in isolation, making triage slow and inconsistent and delaying remediation of issues that actually pose real risk. This talk presents a practical vulnerability triage enrichment process built around AI agents. Instead of treating findings as individual alerts, these agents aggregate all available context related to a detection. Each alert is expanded by examining how the code is written, where and how it runs, and whether the vulnerable functionality can realistically be reached. Bringing this information together into a single view helps analysts move faster and make more consistent risk decisions.
---
Jorge Gimenez is a Security Engineer at Kraken on the Vulnerability Management team, where he works on vulnerability triage, security automation, and risk prioritization at scale. Before joining Kraken, he worked as a red teamer focused on malware development and infrastructure hacking, a perspective he brings into his current role.
Jorge Gimenez (Kraken, ES)
Modern vulnerability management suffers not from a lack of data, but from an overload of it. Security teams receive thousands of vulnerability findings from scanners, cloud platforms, and bug bounty programs, each providing fragmented and incomplete context. As a result, vulnerabilities are often evaluated in isolation, making triage slow and inconsistent and delaying remediation of issues that actually pose real risk. This talk presents a practical vulnerability triage enrichment process built around AI agents. Instead of treating findings as individual alerts, these agents aggregate all available context related to a detection. Each alert is expanded by examining how the code is written, where and how it runs, and whether the vulnerable functionality can realistically be reached. Bringing this information together into a single view helps analysts move faster and make more consistent risk decisions.
---
Jorge Gimenez is a Security Engineer at Kraken on the Vulnerability Management team, where he works on vulnerability triage, security automation, and risk prioritization at scale. Before joining Kraken, he worked as a red teamer focused on malware development and infrastructure hacking, a perspective he brings into his current role.










