In the Wild with VulnCheck
Topic: Regulation, Data Gaps, and AI Are Colliding
2026 didn't bring one change to vulnerability management. It brought three, all at once.
In this episode of In the Wild with VulnCheck, Patrick Garrity, Security Researcher, and Kimber Duke, Principal Product Manager, break down how these three forces are converging, and what it means for how security teams prioritize, report, and keep pace.
In this month's In the Wild with VulnCheck, Patrick Garrity, Security Researcher, and Kimber Duke, Principal Product Manager, break down how these three forces are converging, and what it means for how security teams prioritize, report, and keep pace.
We'll cover:
-
Government regulation: how CRA's September 11 reporting clock and CISA's BOD 26-04 are changing what "fast enough" means
-
Impacted services: what NIST's pullback on NVD enrichment (29,000+ CVEs moved to "Not Scheduled" in a single week) actually leaves uncovered, and how CISA's own data is affected
-
AI and mass adoption: why AI-generated code is outpacing manual security review, and what that does to the volume side of the equation
- A full timeline of what's changed in 2026 and why it matters now, not eventually
Past Topics:
January 28th: Tales from the Exploit Mines
February 25th: Inside the Exploitation Files
March 25th: Expectations vs Reality
April 29th: CISA, NIST, and Mythos — oh my
May 27th: Fuzzers to Frameworks: Hot takes on the new AI-Powered Vulnerability Discovery Stack
June 24th: BOD 26-04, Decoded: What It Means for Federal Agencies and Everyone Else
July 29th: A First Look at the 1H 2026 State of Exploitation Report
August 26th: Regulation, Data Gaps, and AI Are Colliding
Upcoming Dates:
September 30th: Topic TBD
October 28th: Topic TBD
November and December: Dates and Topics TBD

