Lineaje Debuts Platform Designed to Automate Software Vulnerability Remediation

Lineaje has introduced a new platform intended to help organizations continuously detect and remediate exploitable software vulnerabilities as artificial intelligence reshapes both software development and cybersecurity.

The company’s Continuous Vulnerability Elimination Factory, known as CVEF, is designed to automate vulnerability management across proprietary applications, open-source software, AI-generated code and containers. An optional capability called Frontier Defense™ focuses on identifying and patching previously unknown vulnerabilities uncovered by advanced AI models.

The release reflects growing concern among security professionals that AI is changing how software is developed while also giving attackers new ways to identify weaknesses. As organizations rely more heavily on AI coding assistants, security teams face increasing challenges in tracking code quality, dependencies and software supply chain risks.

According to Lineaje, research conducted by Lineaje Labs found that vulnerabilities once considered difficult to exploit may become significantly more dangerous when advanced AI models are used by attackers. The company said the percentage of vulnerabilities considered practically exploitable increased from roughly 1.5 percent to more than 90 percent in scenarios involving frontier AI models.

“AI is fundamentally transforming both how software is built and how it’s attacked, while regulators are increasingly imposing remediation mandates measured in hours, not weeks,” said Javed Hasan, Co-Founder and CEO of Lineaje. “CVEF with Frontier Defense extends traditional AppSec by enabling enterprises to continuously identify, validate, and remediate all traditional and novel exploitable vulnerabilities within a 24-hour autonomous find-and-fix cycle. Enterprises, even those overwhelmed by vulnerability exposure, can now get to no exploitable vulnerabilities in 90 days and stay there.”

The platform is designed to integrate with existing enterprise security and development environments rather than replace them. It automates much of the vulnerability remediation process while allowing organizations to maintain policy controls and human approval over security changes.

A management component coordinates AI agents responsible for remediation planning, testing, approvals and validation. Meanwhile, the platform’s scanning capability continuously analyzes source code, repositories, software dependencies, build artifacts, binaries and containers for vulnerabilities and software supply chain risks.

When a security issue is identified, the platform can generate remediation recommendations, prepare software fixes and coordinate testing before approved updates are deployed. Lineaje said the goal is to reduce the amount of manual work required from developers while accelerating remediation timelines.

The company also said developers receive pre-tested fixes through existing coding environments and security workflows. According to Lineaje, that process can reduce the effort needed to remediate both traditional and newly discovered vulnerabilities by as much as 90 percent.

Frontier Defense expands those capabilities by focusing on vulnerabilities identified through frontier AI models and large language model-based security platforms. The system uses multiple secured AI sandbox environments to evaluate vulnerabilities, verify exploitability and generate compatible software patches.

Lineaje said the capability also maintains a centralized record of newly discovered vulnerabilities, verified exploits and remediation patches across multiple AI model runs. The company said the approach is intended to improve collaboration between security and engineering teams while reducing the time required to move from discovery to remediation.

“Organizations are rapidly adopting AI to increase developer productivity and velocity, and we believe software supply chain security needs to be a top priority for risk management programs,” said Melinda Marks, Practice Director, Cybersecurity at Omdia. “Lineaje’s work in this area is valuable as organizations need modern application security capabilities that don’t just alert, but actively assess, remediate, verify, and govern software risk within development workflows. Lineaje’s outcome-based approach directly addresses this operational bottleneck.”

The platform also creates records documenting remediation activities, testing and approvals, giving organizations additional visibility into their software security operations and supporting governance requirements.

“Enterprises are under pressure to reduce software risk without adding more complexity to already stretched security and development teams,” said Srijit Menon, Partner, Digital Trust and National Head, Third Party Risk Management, KPMG in India. “Through our alliance with Lineaje, we are helping organizations take a more proactive and resilient approach to software supply chain security. Innovations complement this effort by helping improve software transparency and vulnerability management. Together, we can bring greater automation, visibility, and governance to complex software ecosystems while reducing risk and strengthening cyber resilience.”

CVEF joins Lineaje’s broader software supply chain security portfolio, which includes Gold Open Source, SBOM360, UnifAI and xBOM Manager. The company said the products are designed to help organizations improve visibility into software components, reduce exploitable vulnerabilities and strengthen security across modern development environments.

Join our LinkedIn group Information Security Community!

No posts to display