<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
<title>Vulnerability discovery · Agentic Cyber Explorer</title>
<link>https://agentic-cyber-explorer.pages.dev/topics/vulnerability-discovery/</link>
<atom:link href="https://agentic-cyber-explorer.pages.dev/topics/vulnerability-discovery/feed.xml" rel="self" type="application/rss+xml"/>
<description>New records, findings, and answers on vulnerability discovery, from Fide AI's Agentic Cyber Explorer.</description>
<language>en</language>
<copyright>Fide AI. Data licensed CC BY 4.0.</copyright>
<lastBuildDate>Sat, 26 Sep 2026 12:00:00 GMT</lastBuildDate>
<item>
<title>Google's PageBreak agent finds over 500 XSS bugs in its own web apps using deterministic validators</title>
<link>https://agentic-cyber-explorer.pages.dev/events/google-pagebreak-web-vulnerability-agent-2026/</link>
<guid isPermaLink="false">event:google-pagebreak-web-vulnerability-agent-2026</guid>
<pubDate>Thu, 24 Sep 2026 12:00:00 GMT</pubDate>
<category>Defense &amp; research</category>
<description>Google's Product Security team describes PageBreak, an internal agent mostly using Gemini models that hunts vulnerabilities in Google's first-party web applications and only reports findings confirmed by non-AI validators against running applications. Google reports over 500 XSS vulnerabilities found with near-zero false positives, while apps on its high-assurance web frameworks yielded only 2 XSS bugs as of 4 September 2026. It shows a concrete design for suppressing AI-generated false positives. Google also reports that apps built on its secure-by-design frameworks yielded very few bugs to the agent, though that comparison is an uncontrolled self-report.</description>
</item>
<item>
<title>Google releases Gemini 3.8 Flash Cyber for trusted defenders, emphasizing automated patching</title>
<link>https://agentic-cyber-explorer.pages.dev/events/google-gemini-3-8-flash-cyber-2026/</link>
<guid isPermaLink="false">event:google-gemini-3-8-flash-cyber-2026</guid>
<pubDate>Wed, 02 Sep 2026 12:00:00 GMT</pubDate>
<category>Defense &amp; research</category>
<description>Google introduced Gemini 3.8 Flash Cyber, a cybersecurity-tuned model with more permissive cyber mitigations, available only to trusted defenders through a new Fairwind Program. Google says it prioritized vulnerability fixing over exploitation and reports 47.2% pass@1 on Collinear's CWE-Bench patching benchmark, over 70% on an internal 20-language discovery benchmark, and 2.6 times more correct Chrome patches than larger commercial models. It is a gated, defense-oriented model release that foregrounds patching metrics rather than offensive capability.</description>
</item>
<item>
<title>Glasswing update: over 10,000 high-severity bugs found, but only 75 of 530 disclosed OSS bugs patched</title>
<link>https://agentic-cyber-explorer.pages.dev/events/anthropic-glasswing-initial-update-2026/</link>
<guid isPermaLink="false">event:anthropic-glasswing-initial-update-2026</guid>
<pubDate>Fri, 22 May 2026 12:00:00 GMT</pubDate>
<category>Defense &amp; research</category>
<description>Anthropic reports that about 50 Glasswing partners used Claude Mythos Preview to find more than ten thousand high- or critical-severity vulnerabilities, and that its own scan of over 1,000 open-source projects produced 6,202 model-estimated high/critical findings. Of 1,752 assessed, mostly by six independent firms, 90.6% were true positives; Anthropic estimates 530 high/critical bugs disclosed, of which 75 were patched, and says triage and patching capacity, not discovery, is the bottleneck. It gives rare pipeline-level numbers showing AI vulnerability discovery outpacing the human capacity to verify, disclose and fix.</description>
</item>
<item>
<title>Maintainers report AI-generated vulnerability reports overwhelming kernel and bounty triage</title>
<link>https://agentic-cyber-explorer.pages.dev/events/maintainers-ai-bug-report-flood-2026/</link>
<guid isPermaLink="false">event:maintainers-ai-bug-report-flood-2026</guid>
<pubDate>Mon, 18 May 2026 12:00:00 GMT</pubDate>
<category>Defense &amp; research</category>
<description>Help Net Security reported that Linus Torvalds described the Linux kernel security list as almost entirely unmanageable because of heavily duplicated AI-assisted reports, and that GitHub tightened its bug bounty submission requirements, with a GitHub engineer saying some programs elsewhere had shut down. The article also notes that curl ended bounty payments after a surge of low-quality AI reports. Human triage capacity, not discovery, is emerging as the bottleneck for AI-scale vulnerability finding.</description>
</item>
<item>
<title>UK NCSC issues ten questions for organizations using AI models to find vulnerabilities</title>
<link>https://agentic-cyber-explorer.pages.dev/events/ncsc-ten-questions-ai-vulnerability-discovery-2026/</link>
<guid isPermaLink="false">event:ncsc-ten-questions-ai-vulnerability-discovery-2026</guid>
<pubDate>Mon, 11 May 2026 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>The head of the NCSC's Vulnerability Management Group published ten questions for organizations considering AI-driven vulnerability discovery. The questions stress having a process to triage and fix findings, prioritizing exploitable issues, weighing data, permission, legal and jurisdiction risks of the chosen model, starting with the external attack surface, and planning for future models. It is government guidance on the operational side effects of defensive AI vulnerability discovery, such as unmanageable finding volume.</description>
</item>
<item>
<title>Anthropic launches Project Glasswing to give defenders early access to Claude Mythos Preview</title>
<link>https://agentic-cyber-explorer.pages.dev/events/anthropic-project-glasswing-2026/</link>
<guid isPermaLink="false">event:anthropic-project-glasswing-2026</guid>
<pubDate>Tue, 07 Apr 2026 12:00:00 GMT</pubDate>
<category>Defense &amp; research</category>
<description>Anthropic launched Project Glasswing with AWS, Apple, Broadcom, Cisco, CrowdStrike, Google, JPMorganChase, the Linux Foundation, Microsoft, NVIDIA and Palo Alto Networks to use the unreleased Claude Mythos Preview for defensive security work, extending access to over 40 more organizations that maintain critical software. Anthropic committed up to $100M in usage credits and $4M in donations to open-source security groups, and reports Mythos Preview found thousands of high-severity vulnerabilities, including in every major operating system and browser. It is a large, restricted-access defensive deployment of a model its developer does not plan to make generally available, pending safeguards for Mythos-class models.</description>
</item>
<item>
<title>OSS-CRS makes AIxCC reasoning systems runnable locally; OpenSSF adopts it as a sandbox project</title>
<link>https://agentic-cyber-explorer.pages.dev/events/oss-crs-aixcc-systems-openssf-2026/</link>
<guid isPermaLink="false">event:oss-crs-aixcc-systems-openssf-2026</guid>
<pubDate>Mon, 09 Mar 2026 12:00:00 GMT</pubDate>
<category>Defense &amp; research</category>
<description>Researchers led by Georgia Tech released OSS-CRS, a locally deployable framework for running and combining AIxCC cyber reasoning systems, noting that all seven open-sourced finalist systems depended on competition cloud infrastructure that no longer exists. Porting the winning Atlantis system, they found 10 previously unknown bugs (three high severity) in 8 OSS-Fuzz projects; OpenSSF welcomed OSS-CRS into its AI/ML Security Working Group in April 2026. It addresses the gap between open-sourcing competition systems and making them usable by maintainers.</description>
</item>
<item>
<title>OpenAI relaunches Aardvark as Codex Security, reporting 1.2M commits scanned and 14 CVEs</title>
<link>https://agentic-cyber-explorer.pages.dev/events/openai-codex-security-research-preview-2026/</link>
<guid isPermaLink="false">event:openai-codex-security-research-preview-2026</guid>
<pubDate>Fri, 06 Mar 2026 12:00:00 GMT</pubDate>
<category>Defense &amp; research</category>
<description>OpenAI renamed Aardvark to Codex Security and opened a research preview to ChatGPT Pro, Enterprise, Business and Edu customers. OpenAI reports that in 30 days it scanned over 1.2 million commits in its beta cohort and flagged 792 critical and 10,561 high-severity findings, that beta changes cut false positives by more than 50%, and that its open-source reports led to 14 CVEs. It gives rare operational-scale figures, self-reported by the vendor, on AI code-scanning volume and false-positive reduction, alongside a program for open-source maintainers.</description>
</item>
<item>
<title>Anthropic releases Claude Code Security in limited preview to scan code and propose patches</title>
<link>https://agentic-cyber-explorer.pages.dev/events/anthropic-claude-code-security-2026/</link>
<guid isPermaLink="false">event:anthropic-claude-code-security-2026</guid>
<pubDate>Fri, 20 Feb 2026 12:00:00 GMT</pubDate>
<category>Defense &amp; research</category>
<description>Anthropic released Claude Code Security as a limited research preview for Enterprise and Team customers, with expedited free access for open-source maintainers. The tool reasons about data flow across a codebase, re-examines each finding in a multi-stage verification pass, assigns severity and confidence ratings, and proposes patches that are applied only with human approval. It packages frontier-model vulnerability finding for defenders with explicit human approval gates, amid concerns about the same capability aiding attackers.</description>
</item>
<item>
<title>AIxCC SoK finds stability decided results and many validated AI patches were still semantically wrong</title>
<link>https://agentic-cyber-explorer.pages.dev/events/aixcc-sok-competition-lessons-2026/</link>
<guid isPermaLink="false">event:aixcc-sok-competition-lessons-2026</guid>
<pubDate>Sat, 07 Feb 2026 12:00:00 GMT</pubDate>
<category>Defense &amp; research</category>
<description>A systematization-of-knowledge paper by organizers and competitors analyzes AIxCC's design, the seven finalist architectures and results beyond the scoreboard. It reports that system stability and accuracy penalties decided rankings, that LLM-based systems found vulnerabilities a fuzzing baseline missed, and that among patches passing all automatic validation, manual review found semantic errors in 38-46% from baseline agents; the top two systems had 83.8% and 79.2% competition-scored patch accuracy. It gives a detailed account, beyond the scoreboard, of what autonomous cyber reasoning systems achieved and where their patches failed.</description>
</item>
<item>
<title>Anthropic reports over 500 human-validated high-severity open-source vulnerabilities found with Claude Opus 4.6</title>
<link>https://agentic-cyber-explorer.pages.dev/events/anthropic-opus-4-6-500-zero-days-2026/</link>
<guid isPermaLink="false">event:anthropic-opus-4-6-500-zero-days-2026</guid>
<pubDate>Thu, 05 Feb 2026 12:00:00 GMT</pubDate>
<category>Defense &amp; research</category>
<description>Anthropic's Frontier Red Team reports that Claude Opus 4.6, run in a VM with standard tools but no custom harness, found and validated more than 500 high-severity vulnerabilities in open-source software, focusing on memory corruption that can be confirmed with sanitizers. Every bug was validated before reporting, initially by Anthropic researchers who also wrote patches and later with external researchers; examples include Ghostscript, OpenSC and CGIF. It shows a general-purpose model finding bugs in heavily fuzzed code out of the box and describes the validation effort needed to avoid burdening maintainers.</description>
</item>
<item>
<title>All 12 CVEs in OpenSSL's January 2026 advisory credited to AISLE, which says its AI system found them</title>
<link>https://agentic-cyber-explorer.pages.dev/events/aisle-openssl-january-2026-advisory/</link>
<guid isPermaLink="false">event:aisle-openssl-january-2026-advisory</guid>
<pubDate>Tue, 27 Jan 2026 12:00:00 GMT</pubDate>
<category>Defense &amp; research</category>
<description>OpenSSL's 27 January 2026 security advisory lists 12 CVEs, one High and one Moderate, all reported by researchers from Aisle Research, who also developed several of the fixes. AISLE states the issues were discovered by its AI system and that it accounted for 13 of 14 OpenSSL CVEs in 2025; the OpenSSL advisory itself credits the researchers but does not describe the discovery method. It is a concrete, maintainer-published record of an AI-security firm's findings dominating a critical library's security release.</description>
</item>
<item>
<title>OpenAI announces Aardvark, a GPT-5 agent that finds, validates and proposes patches for vulnerabilities</title>
<link>https://agentic-cyber-explorer.pages.dev/events/openai-aardvark-private-beta-2025/</link>
<guid isPermaLink="false">event:openai-aardvark-private-beta-2025</guid>
<pubDate>Thu, 30 Oct 2025 12:00:00 GMT</pubDate>
<category>Defense &amp; research</category>
<description>OpenAI announced Aardvark, a GPT-5-powered agent in private beta that builds a threat model of a repository, scans commits, tries to trigger suspected flaws in a sandbox, and attaches Codex-generated patches for human review. OpenAI reports 92% recall on known and synthetically introduced vulnerabilities in its 'golden' repositories and ten CVEs from open-source scanning, and planned pro-bono scanning for some non-commercial projects. It combined LLM reasoning, sandbox validation and patch generation in one defensive agent from a frontier lab, later relaunched as Codex Security.</description>
</item>
<item>
<title>Anthropic says it trained Claude Sonnet 4.5 for defensive vulnerability finding and patching</title>
<link>https://agentic-cyber-explorer.pages.dev/events/anthropic-building-ai-cyber-defenders-2025/</link>
<guid isPermaLink="false">event:anthropic-building-ai-cyber-defenders-2025</guid>
<pubDate>Fri, 03 Oct 2025 12:00:00 GMT</pubDate>
<category>Defense &amp; research</category>
<description>Anthropic reports that a small team focused Claude Sonnet 4.5 training on finding and patching vulnerabilities and on testing simulated security infrastructure, while avoiding enhancements that clearly favour offence. It reports Sonnet 4.5 results on Cybench and CyberGym, a preliminary patching study in which 15% of patches were judged semantically equivalent to human references, and invites work on SOC and SIEM automation. It is an explicit statement by a frontier lab that it steered model training toward defensive cyber skills, with measured results and patching caveats.</description>
</item>
<item>
<title>AIxCC final: Team Atlanta wins as systems patch 43 of 54 found synthetic bugs and find 18 real ones</title>
<link>https://agentic-cyber-explorer.pages.dev/events/darpa-aixcc-final-results-2025/</link>
<guid isPermaLink="false">event:darpa-aixcc-final-results-2025</guid>
<pubDate>Fri, 08 Aug 2025 12:00:00 GMT</pubDate>
<category>Defense &amp; research</category>
<description>DARPA reports that seven finalist cyber reasoning systems analyzed over 54 million lines of code, found 54 unique synthetic vulnerabilities in 63 challenges and patched 43, and found 18 real non-synthetic vulnerabilities with 11 patches. Team Atlanta won $4 million, Trail of Bits $3 million and Theori $1.5 million; DARPA and ARPA-H added $1.4 million for real-world integration and four systems were open-sourced on the day. It is an organizer-verified, competition-scale measurement of autonomous AI vulnerability discovery and patching, with open-sourced systems others can reuse.</description>
</item>
<item>
<title>Google reports Big Sleep found and reproduced 20 vulnerabilities in open-source projects</title>
<link>https://agentic-cyber-explorer.pages.dev/events/google-big-sleep-20-vulnerabilities-2025/</link>
<guid isPermaLink="false">event:google-big-sleep-20-vulnerabilities-2025</guid>
<pubDate>Mon, 04 Aug 2025 12:00:00 GMT</pubDate>
<category>Defense &amp; research</category>
<description>Google's vice president of security announced that Big Sleep had reported 20 vulnerabilities, mostly in open-source projects such as FFmpeg and ImageMagick, with details withheld pending fixes. A Google spokesperson told TechCrunch each flaw was found and reproduced by the agent without human intervention, with a human expert reviewing reports before submission. It documents a human-in-the-loop reporting model for AI-found bugs at a time when maintainers were complaining about low-quality AI reports.</description>
</item>
<item>
<title>Google says Big Sleep found SQLite CVE-2025-6965 before attackers could exploit it</title>
<link>https://agentic-cyber-explorer.pages.dev/events/google-big-sleep-cve-2025-6965-2025/</link>
<guid isPermaLink="false">event:google-big-sleep-cve-2025-6965-2025</guid>
<pubDate>Tue, 15 Jul 2025 12:00:00 GMT</pubDate>
<category>Defense &amp; research</category>
<description>Google reports that, working from Google Threat Intelligence information, the Big Sleep agent found a critical SQLite memory-corruption flaw (CVE-2025-6965) that Google says was known only to threat actors and at risk of exploitation. Google says it reported the flaw for patching before attackers could exploit it, says it believes this is the first time an AI agent directly foiled an in-the-wild exploitation effort, and says Big Sleep is being applied to open-source projects. Google describes it as an AI agent directly foiling a planned exploitation; if accurate, it shows defensive agents being used operationally, not only in research.</description>
</item>
<item>
<title>BountyBench measures AI agents on detect, exploit and patch tasks from real bug bounties</title>
<link>https://agentic-cyber-explorer.pages.dev/events/stanford-bountybench-2025/</link>
<guid isPermaLink="false">event:stanford-bountybench-2025</guid>
<pubDate>Wed, 21 May 2025 12:00:00 GMT</pubDate>
<category>Defense &amp; research</category>
<description>BountyBench, from Stanford-led researchers, builds 40 bug bounties across 25 real-world systems into 120 Detect, Exploit and Patch tasks with dollar values attached. In the first version the best Detect score was 5%, while OpenAI Codex CLI and Claude Code scored 90% and 87.5% on Patch, well above their Exploit scores. A July 2025 revision with more agents reported Codex CLI with o3-high at 12.5% on Detect and 90% on Patch. It puts offensive and defensive agent performance on the same real codebases and expresses results in bounty dollars.</description>
</item>
<item>
<title>UK NCSC judges AI-assisted vulnerability research is the most significant AI cyber development to 2027</title>
<link>https://agentic-cyber-explorer.pages.dev/events/ncsc-ai-cyber-threat-to-2027-2025/</link>
<guid isPermaLink="false">event:ncsc-ai-cyber-threat-to-2027-2025</guid>
<pubDate>Wed, 07 May 2025 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>The NCSC's second assessment judges that AI will almost certainly make elements of intrusion more effective through 2027, with AI-assisted vulnerability research and exploit development the most significant development. It warns that the window between disclosure and exploitation, already days, will shrink further, and judges fully automated end-to-end advanced attacks unlikely before 2027. It is a government forecast on autonomous attack timelines that 2026 frontier model evidence can be tested against.</description>
</item>
<item>
<title>OSS-Fuzz AI-generated fuzz targets find 26 vulnerabilities, including OpenSSL CVE-2024-9143</title>
<link>https://agentic-cyber-explorer.pages.dev/events/google-oss-fuzz-ai-26-vulnerabilities-2024/</link>
<guid isPermaLink="false">event:google-oss-fuzz-ai-26-vulnerabilities-2024</guid>
<pubDate>Wed, 20 Nov 2024 12:00:00 GMT</pubDate>
<category>Defense &amp; research</category>
<description>Google reports that AI-generated and AI-enhanced fuzz targets in OSS-Fuzz found 26 new vulnerabilities in projects that already had extensive fuzzing, including CVE-2024-9143 in OpenSSL. The LLM workflow drafts targets, fixes compilation errors, fixes runtime issues and triages crashes, and gained coverage in 272 C/C++ projects. It is a vendor-documented case of LLM-driven tooling finding a CVE in critical, heavily tested software.</description>
</item>
<item>
<title>Google's Big Sleep agent finds exploitable stack buffer underflow in SQLite before release</title>
<link>https://agentic-cyber-explorer.pages.dev/events/google-big-sleep-sqlite-first-vulnerability-2024/</link>
<guid isPermaLink="false">event:google-big-sleep-sqlite-first-vulnerability-2024</guid>
<pubDate>Fri, 01 Nov 2024 12:00:00 GMT</pubDate>
<category>Defense &amp; research</category>
<description>Google Project Zero and Google DeepMind report that Big Sleep, an LLM agent evolved from Project Naptime, found an exploitable stack buffer underflow in SQLite during a variant-analysis experiment seeded with newly landed commits. The bug was reported in early October 2024 and fixed the same day, before it appeared in an official release; Google believes this was the first public example of an AI agent finding such a memory-safety flaw in widely used software. It marked the move from benchmark results to a real, previously unknown vulnerability found by an LLM agent and fixed before users were exposed.</description>
</item>
<item>
<title>AIxCC semifinal: AI systems find 22 synthetic vulnerabilities, patch 15, and find one real SQLite bug</title>
<link>https://agentic-cyber-explorer.pages.dev/events/darpa-aixcc-semifinal-results-2024/</link>
<guid isPermaLink="false">event:darpa-aixcc-semifinal-results-2024</guid>
<pubDate>Sun, 11 Aug 2024 12:00:00 GMT</pubDate>
<category>Defense &amp; research</category>
<description>DARPA reports that in the AIxCC semifinal at DEF CON 32, nearly 40 cyber reasoning systems were tested on challenge projects based on Jenkins, the Linux kernel, Nginx, SQLite3 and Apache Tika. Competitors' systems found 22 unique synthetic vulnerabilities, patched 15, and found one real-world SQLite3 bug; seven teams advanced with $2 million each and must open-source their systems after the final. It gave organizer-verified numbers on how well AI cyber reasoning systems could find and patch vulnerabilities in challenge projects built on widely used open-source software.</description>
</item>
<item>
<title>US Executive Order 14110 names offensive cyber capability as a dual-use foundation model risk</title>
<link>https://agentic-cyber-explorer.pages.dev/events/us-eo-14110-ai-cyber-provisions-2023/</link>
<guid isPermaLink="false">event:us-eo-14110-ai-cyber-provisions-2023</guid>
<pubDate>Mon, 30 Oct 2023 12:00:00 GMT</pubDate>
<category>Policy &amp; standards</category>
<description>President Biden's executive order on safe, secure and trustworthy AI defined dual-use foundation models partly by their potential to enable offensive cyber operations through automated vulnerability discovery and exploitation. It required developers to report red-team results to the government and directed a federal pilot using AI to find and fix vulnerabilities in government systems. The order was revoked by Executive Order 14179 on January 23, 2025. It was a US executive instrument that treated automated vulnerability discovery and exploitation as a reportable frontier-model risk, and its revocation reset the US baseline.</description>
</item>
<item>
<title>Google reports LLM-written fuzz targets raise OSS-Fuzz code coverage in early experiments</title>
<link>https://agentic-cyber-explorer.pages.dev/events/google-oss-fuzz-llm-fuzz-targets-2023/</link>
<guid isPermaLink="false">event:google-oss-fuzz-llm-fuzz-targets-2023</guid>
<pubDate>Wed, 16 Aug 2023 12:00:00 GMT</pubDate>
<category>Defense &amp; research</category>
<description>Google's open source security team reports an experiment connecting OSS-Fuzz to an LLM that writes new fuzz targets for under-fuzzed code and revises them when they fail to compile. Google reports coverage gains of 1.5% to 31% across sample projects, and that an LLM-generated target rediscovered an already-known OpenSSL vulnerability in code that previously lacked fuzzing coverage. It is an early documented use of LLMs to automate a defensive testing step that maintainers usually do by hand.</description>
</item>
<item>
<title>DARPA launches the AI Cyber Challenge to build AI systems that find and fix open-source vulnerabilities</title>
<link>https://agentic-cyber-explorer.pages.dev/events/darpa-aixcc-launch-2023/</link>
<guid isPermaLink="false">event:darpa-aixcc-launch-2023</guid>
<pubDate>Wed, 09 Aug 2023 12:00:00 GMT</pubDate>
<category>Defense &amp; research</category>
<description>At Black Hat USA 2023, DARPA announced the AI Cyber Challenge (AIxCC), a two-year competition to build AI-driven systems that automatically find and fix vulnerabilities in critical open-source software. Anthropic, Google, Microsoft and OpenAI agreed to provide technology and expertise to competitors, OpenSSF served as challenge advisor, and semifinal and final rounds were scheduled for DEF CON 2024 and 2025. AIxCC became a large public test of LLM-based cyber reasoning systems for defensive vulnerability discovery and repair.</description>
</item>
</channel>
</rss>
