Nucleus Security says its new tools can spot a vulnerability before your scanner even knows it exists

A new early-warning feature aims to cut the days-long gap between a software flaw going public and security teams being able to scan for it.

ThreatVectr Newsdesk· 4 min read
Photoreal, news-editorial style, 16:9 framing, full-frame edge-to-edge composition
Share

Key points

  • Nucleus Security is launching three new products, including an AI assistant called Helix, an early-detection tool called Discover, and expanded threat intelligence under Nucleus Insights.
  • A feature called the Early Warning System found CVE-2025-44416, a critical software flaw with a severity score of 9.8 out of 10, in customer environments on 21 August, one day after it was first published publicly.
  • As of that same date, Nucleus says major scanning tools including Tenable had not yet released a detection plugin for the flaw.
  • The Helix AI agent and Discover with Early Warning are scheduled to be available in September 2025; Nucleus Insights is available now.
  • The Nucleus team stresses that AI handles research and reasoning while separate, rule-based automation handles actual execution.

When a new software flaw becomes public knowledge, there is usually a gap of several days before the security tools companies use to scan their systems are updated to look for it. During that window, criminals who spotted the same news can move faster than defenders.

Nucleus Security, a company that helps organisations track and fix security weaknesses across their software and systems, says it has built a way to shrink that gap.

What is Nucleus actually launching?

Three things, announced this week. First, Nucleus Discover with an Early Warning System, which tries to flag systems that might be affected by a newly disclosed flaw before any scanner has been updated to detect it. Second, Helix, an AI assistant that lets security staff ask questions in plain English and get back analysis, suggested fixes, and workflow drafts. Third, expanded Nucleus Insights, the company's existing feed of vulnerability and threat intelligence.

The tools are aimed at the growing pressure security teams face as AI makes it easier and faster for researchers and criminals alike to find new flaws.

How does early warning without a scanner actually work?

Scanners work by matching what they find on a network against a library of known flaws. That library takes time to update after a new flaw is disclosed.

Nucleus Discover sidesteps that wait. Instead of scanning afresh, it cross-references the details of a newly announced flaw against information the platform already holds about a customer's environment: what software they run, which teams own which systems, and what previous scans have found. If the flaw affects a piece of software and Nucleus already knows a customer runs that software, it flags the likely exposure straight away.

Detail Value
Example CVE CVE-2025-44416
CVSS severity score 9.8 / 10 (critical)
CVE first published 20 August 2025
Nucleus detection confirmed 21 August 2025
Tenable plugin available as of 21 Aug No
Nucleus revised risk rating Medium (downgraded from 9.8)

Scott Kuffer, co-founder and chief product officer at Nucleus Security, told CSO Online that the goal is not to replace traditional scanning but to give teams a narrower, more targeted list of systems worth checking first.

Where does AI fit in, and should that worry anyone?

Helix, the new AI assistant, is deliberately kept away from actually changing anything on a company's systems. It can read data, write explanations, draft queries, and suggest automations. A separate, deterministic automation engine, meaning software that follows fixed rules with no improvisation, is what actually carries out any approved action.

"AI helps determine what should happen; deterministic automation makes sure it happens consistently," Kuffer said.

Nucleus also says it treats data coming from AI sources as untrusted by default, applying its own checks before acting on any AI-generated guidance. That is a sensible design choice: AI models can hallucinate plausible-sounding but wrong information, and a security tool acting on bad data could send teams chasing ghosts.

Should security teams trust this?

The early-warning approach is genuinely useful in principle. Knowing which of your systems probably runs a vulnerable piece of software is better than knowing nothing, even if a scanner has not confirmed it yet. The honest caveat, which Kuffer acknowledged, is that these are indicators rather than confirmed detections.

For ordinary people: if your employer uses software that handles your data, tools like this help the security team find problems faster. That is a good thing. It does not eliminate risk, but it does reduce the time attackers have to act before defenders catch up.

© 2026 Threat Vectr