{
 "license": "CC-BY-4.0",
 "attribution": "Fide AI, Agentic Cyber Explorer",
 "url": "https://agentic-cyber-explorer.pages.dev/events/google-big-sleep-cve-2025-6965-2025/",
 "asOf": "2026-09-26",
 "id": "google-big-sleep-cve-2025-6965-2025",
 "date": "2025-07-15",
 "datePrecision": "day",
 "title": "Google says Big Sleep found SQLite CVE-2025-6965 before attackers could exploit it",
 "lane": "defense",
 "kind": "vulnerability-disclosure",
 "summary": "Google reports that, working from Google Threat Intelligence information, the Big Sleep agent found a critical SQLite memory-corruption flaw (CVE-2025-6965) that Google says was known only to threat actors and at risk of exploitation. Google says it reported the flaw for patching before attackers could exploit it, says it believes this is the first time an AI agent directly foiled an in-the-wild exploitation effort, and says Big Sleep is being applied to open-source projects.",
 "whyItMatters": "Google describes it as an AI agent directly foiling a planned exploitation; if accurate, it shows defensive agents being used operationally, not only in research.",
 "actors": [
  "google",
  "google-deepmind",
  "google-project-zero",
  "google-threat-intelligence-group",
  "sqlite"
 ],
 "topics": [
  "vulnerability-discovery",
  "threat-intelligence"
 ],
 "atlas": [],
 "artifacts": [
  "big-sleep"
 ],
 "sources": [
  {
   "url": "https://blog.google/innovation-and-ai/technology/safety-security/cybersecurity-updates-summer-2025/",
   "publisher": "Google",
   "title": "A summer of security: empowering cyber defenders with AI",
   "date": "2025-07-15",
   "type": "primary",
   "accessed": "2026-09-25"
  },
  {
   "url": "https://cloud.google.com/blog/products/identity-security/cloud-ciso-perspectives-our-big-sleep-agent-makes-big-leap",
   "publisher": "Google Cloud Blog",
   "title": "Cloud CISO Perspectives: Our Big Sleep agent makes a big leap, and other AI news",
   "date": "2025-07-17",
   "type": "primary",
   "accessed": "2026-09-25"
  }
 ],
 "keyFacts": [
  {
   "fact": "Big Sleep discovered CVE-2025-6965 in SQLite based on intel from Google Threat Intelligence; Google describes it as critical and known only to threat actors.",
   "locator": "Section '1. Giving defenders an edge with agentic capabilities'"
  },
  {
   "fact": "Google believes this is the first time an AI agent has been used to directly foil efforts to exploit a vulnerability in the wild.",
   "locator": "Same section"
  },
  {
   "fact": "Sandra Joyce (VP, Google Threat Intelligence) says GTIG threat intelligence and Big Sleep together identified the flaw, which Google reported for patching before the attackers could exploit it.",
   "locator": "Cloud CISO Perspectives, Sandra Joyce"
  }
 ],
 "significance": 4,
 "fideQuestions": [],
 "methods": [
  "ai-assisted-exploitation",
  "ai-vulnerability-discovery"
 ],
 "review": "assistant-drafted",
 "addedOn": "2026-09-25"
}