Securing The Build: AI, AppSec & Exposure Management
Why vulnerability counts don’t predict breaches, and what actually does.
“How many vulnerabilities do we have?” stops being a useful question the moment AI agents and MCP servers enter your stack, because that count only climbs no matter what your team does. At Black Hat USA 2026, Mend.io CEO Azi Cohen and EVP, Chief Product Officer Asaf Saar sat down with Cybercrime Magazine to explain what actually predicts breach risk: reachability, exploitability, and business context, three things most organizations still aren’t measuring. They make the case for trading vulnerability counting for exposure management, and for briefing boards on AI risk the way they already hear about financial and operational risk, with a trend line and a plan instead of a scare tactic.
Speakers:
- Azi Cohen, Co-Founder and CEO – Mend.io
- Asaf Saar, EVP Product –Β Mend.io
- Sam White – Cybercrime Magazine