Security1 distinct publisher3 min readUpdated
Ten months of production use, 12 assigned CVEs, and a two-day sweep of stolen repositories. Discovery has stopped being the bottleneck; human validation has become one.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Google's Mandiant has published the internals of a tool it calls the Agentic Vulnerability Discovery Harness, a chain of AI agents that reads source code hunting for exploitable flaws, and says the harness produced more than 100 verified, high-severity findings in two days during a live investigation into stolen corporate repositories [1][2]. The number that matters is not 100; it is two days, because the same class of pipeline pointed at the same stolen code by someone else would run just as fast.
The harness has been in use inside Mandiant for ten months, and in that period has scanned tens of millions of lines of code and produced tens of thousands of findings, according to a blog post from the Google Threat Intelligence Group [3][4]. Mandiant researchers Alex Tselevich and Michael Maturi write that the work has yielded 12 assigned CVEs, including CVE-2026-13242 and CVE-2026-55803, with roughly another dozen in active disclosure [5][6]. That is about 24 identifiers either issued or pending [20], against a ten-month average of a little over one assigned CVE per month [21] and a burst rate of at least 50 verified high-severity findings per day during the repository investigation [22]. The disclosure pipeline is orders of magnitude slower than the discovery pipeline.
The architecture is unglamorous and that is its strength. Built on Google's Agent Development Kit, it runs as a sequence of specialised agents, each passing output to the next [7]: a threat modeling stage that maps the codebase and marks what to skip, such as test directories, with a human signing off on the model before anything else runs [8]; entry point discovery across every in-scope file, from web routes to inter-process listeners [9]; context enrichment that gathers the permission checks and sanitizers a reviewer would otherwise chase by hand [10]; hypothesis generation split between access-control problems and dangerous data flows [11]; and validation by several agents deliberately run at high temperature, with a synthesis agent sorting each hypothesis into confirmed, disproven, or rejected [12].
Then a person checks it. Mandiant consultants reproduce the exploit and run proof-of-concept code, and findings that fail are discarded [13]. Tselevich and Maturi explicitly tell defenders building similar harnesses to validate manually [14]. Mandiant says it fought the traditional false-positive problem by having agents challenge each other and test conclusions against rules written by its own consultants, organised by software domain and then by language, framework, and vulnerability type so the knowledge is reusable [15][16]. It also declined to grade itself on public vulnerability datasets, building synthetic vulnerable codebases instead, on the concern that current models may have memorised the public sets during training [17].
That last detail is the most honest thing in the post, and it is worth reading alongside the marketing line. The researchers argue manual review cannot keep pace and that traditional scanners miss too much [18], and that the harness proves defenders can reclaim the advantage against adversarial AI [19]. The first half is a capability claim with evidence behind it. The second is a hope: nothing in the disclosure documents an attacker running such a harness, and the asymmetry cuts the wrong way, since an adversary auditing stolen code does not need reproducible proof-of-concept sign-off before acting.
Watch whether the second dozen CVEs land, and how long assignment takes [6]. Watch whether the organisations whose repositories were stolen can triage at the rate the harness reads. If your source code has ever left your perimeter, treat it as under review by someone with a validation queue shorter than yours.
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Mandiant says AVDH found over 100 verified, high-severity flaws in just two days during a live investigation into stolen corporate repositories.
To grade its own performance Mandiant built synthetic, deliberately vulnerable codebases rather than relying on public vulnerability datasets, out of concern that current models may have seen those datasets during training and could be recalling answers rather than reasoning.
Google's Mandiant disclosed the workings of an internal tool called the Agentic Vulnerability Discovery Harness (AVDH), which uses chains of AI agents to hunt for vulnerabilities in source code.
In that ten-month period AVDH scanned tens of millions of lines of code and produced tens of thousands of findings, according to a blog post published by the Google Threat Intelligence Group.
The tool has uncovered dozens of assignable flaws in widely used web extensions and open-source projects, resulting in 12 assigned CVEs, including CVE-2026-13242 and CVE-2026-55803.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed vendor account, no external verification
The cluster contains one article relaying one vendor blog post. Methodology is unusually specific - named researchers, five named pipeline stages, the ADK substrate, the rule taxonomy, and a stated reason for using synthetic evaluation sets - and 12 CVE assignments with two named identifiers are checkable artefacts. But every performance number is self-reported, no precision, recall, or false-positive rate accompanies the tens of thousands of findings, no synthetic-benchmark scores are published, and no independent party corroborates the two-day sweep.
Real internal production use, no external users
Adoption is genuine but confined to the originating vendor: ten months of continuous internal use, tens of millions of lines of code scanned, deployment inside a live incident investigation, and downstream CVE assignments against third-party projects. Nothing in the supplied source indicates external availability, customers running AVDH, or any other organisation operating a comparable harness, so breadth of adoption is one organisation deep.
Headline throughput outruns published rigour
The framing - 100-plus critical bugs in two days, and a harness whose success 'proves defenders can reclaim the advantage against adversarial AI' - is stronger than what the supplied material substantiates. There is no false-positive rate against tens of thousands of findings, no synthetic-benchmark score, no comparison against the traditional scanners it disparages, and no attacker-side measurement behind the adversarial-AI claim. The vendor's own insistence that findings be validated by hand, and that consultants discard failures, points the other way from the automation headline; roughly 1.2 assigned CVEs per month is a sober counterweight to the two-day number.
Vendor capability marketing, relayed largely intact
The originating material is a Google Threat Intelligence Group blog post about a tool Google's own Mandiant built on Google's own Agent Development Kit, operated by Mandiant consultants whose services the results advertise. Both the performance figures and the concluding claim about defender advantage serve that commercial interest. The publisher relays the account with minimal adversarial framing, though it does carry the researchers' caution about manual validation.
Moderate on what was said, low on what it means
Confidence is high that Mandiant disclosed this pipeline and made these claims - the article is specific, dated, and quotes named researchers - and the CVE identifiers are verifiable in principle. Confidence is low on effectiveness, sustainability, and generalisability: one publisher, one vendor source, no metrics on precision, no external replication, and no information on availability or cost.
security
Moscow's crews stopped stealing passwords. Now they ask victims to approve the login.1 distinct publisher
leadership
UNC6671 did not retire: four brands, one helpdesk script, and calls to personal phones1 distinct publisher
build
Grok 4.6 lands in Copilot two days after launch, and the model picker becomes a procurement problem1 distinct publisher
security
Google's reference agent approved a $10,000 refund on a $149 order, on purpose1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 19, 2026