Automated vulnerability scanners provide a lot of false positives reports, this create a lot of work for Security Analyst and some of them hate them. Are Vulnerability scanners broken?
Not necessary, still the automated vulnerability scanners provide a lot of help to identify weakness of the system or OS and it is cheaper compering to a penetration testing.
Security is an ongoing process, automated scanner help to increase the security bar of any system but at the same time it shouldn't replace any penetration testing. After you keep running the automated tool you bring a penetration tester. The pentester will focus in the most difficult weakness because you found the easy one with vulnerability scanner.
So, Are Vulnerability scanners broken? No, they keep helping to protect the data.