Why LLMs Fall Short in Vulnerability Management

No ratings

Presented at Snowfroc 2025 by

LLMs are often marketed as transformative tools capable of automating complex tasks, such as identifying and fixing security vulnerabilities. However, in practice, LLMs face significant technological and operational limitations. This talk examines why LLMs, despite their impressive language understanding and contextual reasoning capabilities, are often ill-suited for critical aspects of vulnerability management, including open source dependencies, contextual prioritization, supply-chain attacks, and operational remediation.