Cybersecurity
Devin-powered service promises to clear 80% of security backlogs
LTM and Cognition's Devin-powered remediation service promises to clear 80% of CVE backlogs at 30% lower cost. But the partnership targets only high-confidence fixes first, and every patch needs human sign-off. We examine whether AI can really scale vulnerability management.
Emmanuel Fabrice Omgbwa Yasse AI-assisted
2026-08-01 · 4 min read

Enterprise security has a numbers crisis. According to Cognition's announcement, the volume of AI-powered attacks has tripled, and teams now face 10 to 100 times more security findings than they did a few years ago. A large share are false positives, but separating the real threats from the noise still demands human hours that nobody has. LTM, a managed security provider serving over 260 clients including 26 of the Fortune 500 and the top five global banks, is now trying to solve that equation with an AI software engineer.
LTM partnered with Cognition to embed Devin, the autonomous coding agent, into a managed service called BlueVerse RightLogic. Devin ingests findings from the vulnerability scanners enterprises already run, prioritizes them by business criticality and regulatory exposure, and ships pull requests that fix the ones it can handle. LTM engineers review every patch before merge and handle the complex edge cases that require human judgment. The companies say the service can clear 80 percent of a customer's CVE backlog, up from the 60 percent they delivered before Devin was in the loop.
The security volume crisis
The volume problem is not abstract. Attackers now deploy low-cost AI swarms that probe every possible entry point, and the tools most enterprises rely on still stop at detection. They flag a vulnerability but leave validation and remediation to humans, who already have more alerts than they can process. The same fatigue shows up across the industry, research on security models notes that even the best general AI deliberately limits its cybersecurity skills. Generative AI has also supercharged phishing attacks, eroding the margin that traditional email filters and training once provided.
LTM's client base is particularly exposed. Financial institutions hold sensitive data and face strict regulatory timelines for patching. CISA's Known Exploited Vulnerabilities catalog, which lists actively exploited flaws such as CVE-2026-45659 in SharePoint Server, forces agencies to patch within days. A managed service that promises to clear the majority of that backlog before a deadline has obvious appeal.
How BlueVerse RightLogic works
The service is built on three pillars. First, managed remediation: RightLogic ingests findings from existing scanners, ranks them, and routes high-confidence fixes to Devin for end-to-end remediation. LTM engineers take the rest. Second, enterprise scale and governance: Devin provides autonomous capacity across tens of thousands of findings, an orchestration pattern where a general agent tackles bulk work while specialists handle the edges. LTM applies remediation playbooks, compliance rules, and coding standards built for regulated industries. The companies say this combination is designed to clear 80 percent of a CVE backlog, a claim jointly backed by both parties. Third, continuous improvement: every engagement sharpens LTM's playbooks, encoding each customer's rules so future remediation runs faster.
It is the first of five joint offerings the two companies plan to bring to market, covering application modernization and SDLC transformation. A large pool of LTM engineers has already been trained on Devin, so customer teams can be productive from day one.
Claims under the microscope
The headline numbers deserve scrutiny. The 30 percent lower cost claim compares Devin Security Swarm against “the nearest comparable alternative,” but Cognition does not name that alternative or disclose the methodology behind the comparison. The 80 percent backlog clearance is an improvement from 60 percent, but that earlier figure was also delivered by LTM without Devin, so the delta may partly reflect process refinement rather than the AI alone. Analysis of AI coding agent costs has shown that enterprises often lack visibility into the real economics of such tools.
There is also a well-known gap between benchmark performance and production reliability. A model that scores 96.58 on a structured benchmark may still stumble on the messy, context-dependent vulnerabilities that real codebases hide. Research on AI agent harness evolution documents this gap between benchmark scores and real-world reliability. Cognition says Devin finds “more verified vulnerabilities at 30% lower cost,” but verification here still requires a human reviewer before any fix is merged. That manual gate keeps quality high but limits throughput to the availability of security engineers, which is exactly the bottleneck the service claims to break.
The table below summarizes the key metrics and the caveats that surround them.
| Metric | Claimed value | Context |
|---|---|---|
| CVE backlog clearance | 80% | Up from 60% per LTM and Cognition; improvement may have non-AI contributors |
| Cost reduction | 30% lower than nearest comparable alternative | Comparable alternative not named; methodology undisclosed |
| Human review | Every fix reviewed before merge | Quality gate but also a throughput constraint |
| False positive rate | Not stated | Service ingests from existing scanners; no separate FP reduction claimed |
Financial services first
RightLogic launches in banking, financial services, and insurance, where Devin has already been tested and LTM holds deep institutional relationships. Harsh Naidu, LTM's Chief Business Officer for Banking & Financial Services, said the sector is under pressure to strengthen security while accelerating AI adoption, and that the service helps clients “reduce vulnerability backlogs, automate remediation, and improve cyber resilience.” Gardner Johnson, Cognition's VP of Global Partnerships, framed the problem in blunter terms: “Security has become a volume problem that no human team can staff its way out of.”
The partnership plan to scale RightLogic into other industries, including application modernization work. For now, the real test is whether Devin can consistently ship fixes that pass human review at a pace that actually relieves the backlog, not just reorganizes it. The numbers are bold, but the proof will be in the pull requests that don't get rejected.
- Source : The AI that promises to clear 80% of your security backlog — 2026-07-28
Get the tech essentials in 3 minutes every morning
One email, every weekday, with what actually matters in AI and tech.