-

ArmorCode Advances Agentic Vulnerability Remediation at Black Hat with Risk Discipline and AI Cost Savings

New Context Risk Graph Capabilities and Purpose-Built Anya Agents Focus AI on the Vulnerabilities that Create Real Business Risk, While Reducing Duplicate Work and Costs

LAS VEGAS--(BUSINESS WIRE)--ArmorCode, the leader in Unified Exposure Management, today announced at Black Hat USA 2026 a major expansion of its Agentic Control Plane. Four new Anya AI agents help security teams analyze cloud risks, assess vulnerability exploitability, identify mitigation strategies, and coordinate patch orchestration. It also unveiled new Context Risk Graph capabilities for expanded attack path analysis, network reachability and patch management. Together, these enhancements help security teams move beyond vulnerability discovery to accurately and quickly prioritize and remediate the risks that matter most, while reducing duplicate AI analysis and operational costs.

At #BlackHat @code_armor unveils new Anya #AI agents and expanded Context Risk Graph capabilities, so #security teams can move beyond vulnerability discovery to prioritize and remediate the risks that matter most while reducing duplicate AI analysis cost

Share

Agentic Vulnerability Remediation Requires Deeper Context

Security teams face a growing volume of vulnerabilities across applications, cloud environments, infrastructure, containers and software supply chains. Attackers can chain seemingly isolated weaknesses into paths that reach critical systems and data. While AI accelerates response, without sufficient context, it can generate inaccurate fixes, introduce security or compliance risks and increase costs as developers and security teams repeatedly ask separate agents to analyze the same issues without shared memory.

ArmorCode solves this problem by giving AI agents the context they lack. The expanded Context Risk Graph builds on ArmorCode’s existing vulnerability insights model, which connects security findings with asset inventory, ownership, business context, threat intelligence and remediation data.

New Context Risk Graph capabilities include:

  • Expanded Attack Path Analysis: Uses vulnerability insights to correlate findings and environmental context, determine what’s reachable and exploitable, and generate high-fidelity attack path visualizations.
  • Network Topology and Reachability Context: Traces how exposures connect across applications, clouds, containers, infrastructure and network environments.
  • Patch Management Integration: Helps teams understand patch availability, plan remediation and coordinate action through existing systems.
  • And Existing Compensating Control Integration: Connects with technologies such as web application firewalls (WAFs) and endpoint detection and response (EDR) platforms to reduce exposure while permanent fixes are underway.

“Finding vulnerabilities was never the hard part,” said Mark Lambert, Chief Product Officer at ArmorCode. “The challenge is understanding which findings create real attack paths and what actions will reduce risk. Threat actors can cheaply chain together findings that teams previously deprioritized in attacks, and defenders find that AI without context is both inaccurate and expensive. ArmorCode gives AI the security context it needs to fix what actually matters, and do it economically.”

Purpose-Built AI Agents Turn Risk Insights Into Action

The expanded Context Risk Graph provides Anya’s agentic workforce with a richer understanding of enterprise risk. New and existing Anya agents act on this enriched context to determine what presents a real attack path, identify the right response and accelerate remediation, allowing teams to reuse trusted context instead of repeatedly building separate agents or paying for the same analysis multiple times.

Purpose-built Anya agents are grounded in the data unified within the ArmorCode platform, which processes more than 300 billion findings annually across more than 375 integrations. Organizations can use prebuilt agents or create custom agents through the Anya harness to support their own security processes and policies.

Helping security teams take action faster, the new Anya AI agents include:

  • Vulnerability Researcher: Investigates the real-world exploitability of a CVE within an organization’s environment and explains how it could be used in an attack.
  • Mitigation Engineer: Works with existing compensating controls, including WAF rules and EDR policies to contain risk until a permanent fix can be applied.
  • Cloud Security Engineer: Evaluates cloud misconfigurations and exposures against the broader environment to identify risks with meaningful business impact.
  • And Patch Orchestrator: Plans and sequences patch rollouts across affected systems to support efficient remediation with minimal disruption.

Chandra Sekar, Chief Marketing Officer at ArmorCode, said: “Every security team is being pushed to adopt AI, and every finance leader is watching the AI bill climb. ArmorCode brings financial and risk discipline to agentic remediation so enterprises can make smarter security decisions without the runaway costs of pointing AI at everything.”

Measurable Security Outcomes

The impact of this approach is reflected in measurable improvements for organizations using ArmorCode to reduce risk and unify exposure management. By correlating security and business context, the platform helps organizations identify the approximately 3% of findings that represent about 80% of their actual risk. And ArmorCode customers have already achieved a 75% reduction in mean time to remediate (MTTR), 60% reduction in vulnerability backlog and more than a 3X first-year return on investment.

Learn more about the expanded Context Risk Graph, new Anya agents and ArmorCode’s approach to economical agentic remediation.

Connect with ArmorCode at Black Hat

ArmorCode sponsors The Purple Book Community for PBC Connect at Black Hat on August 4 at Mandalay Bay, Las Vegas. The event will feature discussions on AI security, vulnerability remediation and emerging risk, including a fireside chat with Jason Clinton, Deputy CISO at Anthropic, and Phil Venables, former CISO of Google Cloud and Goldman Sachs. View the agenda and reserve a seat, and participate in the ArmorCode Capture the Flag hacking event following the main program.

About ArmorCode

ArmorCode helps enterprises manage security risk and governance across today’s heterogeneous technology environments. The ArmorCode Agentic AI Platform gives security teams a system of action, moving from fragmented signals to owned, policy-driven, auditable decisions. Its unified exposure management capabilities deliver visibility, insight and control across four solutions: Application Security Posture Management, Vulnerability Management, Software Supply Chain Security and AI Exposure Management.

Processing over 300 billion findings a year across hundreds of native integrations, ArmorCode unifies, prioritizes and drives remediation across applications, cloud, code, infrastructure and AI. Powered by Anya, the industry’s first agentic AI framework for enterprise security, ArmorCode is trusted by global enterprises to reduce exposure and adopt AI and modern software practices with confidence, without replacing existing tools or forcing vendor consolidation.

For more information, visit www.armorcode.com.

Contacts

Media Contact:
CONTOS DUNNE COMMUNICATIONS
armorcode@cdc.agency
+1 (408) 776-1400 (o); +1 (408) 893-8750 (m)

Back to Newsroom