Automating the Patch: AI Agents for Code Security and Beyond

Rashmi Nagpal

Attackers exploit vulnerabilities in days, but organizations take months to patch them, creating a 97-day average exposure window. With over 29,000 new CVEs reported in 2023, human-scale security is no longer a viable defense against machine-scale threats. This talk demonstrates a practical solution: a multi-agent AI system that automates the security operations lifecycle. This system autonomously detects vulnerabilities with fine-tuned LLMs, generates patches, and validates fixes. We will walk through the architecture of this „Code Guardian” and learn its capabilities.

Following this, we will introduce Patchstack’s mVDP program, which streamlines vulnerability disclosure for WordPress plugin and theme developers, and demonstrate how such agentic building blocks can accelerate the security operations lifecycle using open-source large language models.