Nucleus Security says its new tools can spot a vulnerability before your scanner even knows it exists
A new early-warning feature aims to cut the days-long gap between a software flaw going public and security teams being able to scan for it.

Key points
- Nucleus Security is launching three new products: an AI assistant called Helix, an early-detection tool called Discover, and expanded threat intelligence under Nucleus Insights.
- A feature called the Early Warning System found CVE-2025-44416, a critical flaw with a severity score of 9.8 out of 10, in customer environments on 21 August, one day after it was first published publicly.
- As of 21 August, Nucleus says major scanning tools including Tenable had not yet released a detection plugin for that flaw.
- Helix and Discover with Early Warning are scheduled for September 2026; Nucleus Insights is available now.
- Nucleus treats AI as the reasoning layer only: separate, rule-based automation handles any actual execution.
When a new software flaw becomes public knowledge, there's usually a gap of several days before the tools companies use to scan their systems are updated to look for it. During that window, criminals who spotted the same news can move faster than defenders.
Nucleus Security, a company that helps organisations track and fix security weaknesses, says it has built a way to shrink that gap. We've tracked the vendor pitch that AI can rescue overwhelmed security programmes in five pieces over the past 90 days; this one at least pairs the AI story with a concrete mechanism worth examining.
What is Nucleus actually launching?
Three things, announced this week. First, Nucleus Discover with an Early Warning System, which tries to flag systems that might be affected by a newly disclosed flaw before any scanner has been updated to detect it. Second, Helix, an AI assistant that lets security staff ask questions in plain English and get back analysis and workflow drafts. Third, expanded Nucleus Insights, the company's existing feed of vulnerability and threat intelligence.
The tools are aimed at the pressure security teams face as AI makes it faster for researchers and criminals alike to find new flaws.
How does early warning without a scanner actually work?
Scanners work by matching what they find on a network against a library of known flaws. That library takes time to update after a new flaw is disclosed.
Nucleus Discover sidesteps that wait. Instead of scanning afresh, it cross-references a newly announced flaw against information the platform already holds: what software a customer runs, which teams own which systems, what previous scans have found. If the flaw affects software Nucleus already knows a customer runs, it flags the likely exposure straight away.
| Detail | Value |
|---|---|
| Example CVE | CVE-2025-44416 |
| CVSS severity score | 9.8 / 10 (critical) |
| CVE first published | 20 August 2025 |
| Nucleus detection confirmed | 21 August 2026 |
| Tenable plugin available as of 21 Aug | No |
| Nucleus revised risk rating | Medium (downgraded from 9.8) |
Scott Kuffer, co-founder and chief product officer at Nucleus Security, told CSO Online the goal isn't to replace traditional scanning but to give teams a narrower, more targeted list of systems worth checking first.
Where does AI fit in, and should that worry anyone?
Helix is deliberately kept away from changing anything on a customer's systems. It can read data, draft queries, and suggest automations. A separate, deterministic automation engine, meaning software that follows fixed rules with no improvisation, is what actually carries out any approved action.
"AI helps determine what should happen; deterministic automation makes sure it happens consistently," Kuffer told CSO Online.
Nucleus also says it treats data from AI sources as untrusted by default, applying its own checks before acting on any AI-generated guidance. That's a sensible design choice. AI models can produce plausible-sounding but wrong information, and a security tool acting on bad data could send teams chasing ghosts.
Should security teams trust this?
The early-warning approach is genuinely useful in principle. Knowing which of your systems probably runs a vulnerable piece of software is better than knowing nothing, even before a scanner confirms it. The honest caveat, which Kuffer acknowledged, is that these are indicators rather than confirmed detections. No specific measurement comparing Nucleus's discovery time against a conventional scanning workflow was offered.
For ordinary readers: if your employer uses software that handles your data, tools like this help the security team find problems faster. It doesn't eliminate risk, but it does reduce the time attackers have to act before defenders catch up.



