Skip to content

Topic

AI-Driven Vulnerability Research

The use of AI models and automated tools to find, analyze, and exploit software vulnerabilities, reshaping security research and disclosure practices.

Current stories

buildOne report1 publisher

Cantina's open-weights exploit model ran a 60-task security eval for $2.38

Cantina released apex-flash-1, an open-weights vulnerability-research model it says solved 40 of 60 tasks for $2.38, against $74.68 for Claude Opus 5 High. There is no hosted endpoint, so teams download the 321-billion-parameter weights, pay for their own inference and verify the numbers themselves.

Publishers:runtimewire.com

Reality

Evidence45
Adoption
Insufficient
Hype gap+35
Incentives70
Confidence40
buildConfirmed2 publishers

GPT-5.6 Sol Ultra turned public V8 patch commits into a working Chrome exploit for $1,597

Hacktron reports that GPT-5.6 Sol Ultra built a complete Chrome/V8 exploit chain in a controlled test for $1,596.89 of model compute. The benchmark handed the model the source tree and the public security-fix commits, so the figure covers only the compute for one lab task.

Publishers:hacktron.airuntimewire.com

Reality

Evidence55
Adoption
Insufficient
Hype gap+45
Incentives70
Confidence55
securityConfirmed3 publishers

CISA reframes the CVE program around data quality as 2026 heads for 96,000 records

Disclosure volume is climbing faster than the process around it. CISA's answer is a framework that describes what a good CVE record is and how the program should be judged on producing one.

Perspective Coverage

3 publishers
Builder
Builder 33%
Operator
Operator 50%
Investor
Investor 17%

Reality

Evidence68
Adoption
Insufficient
Hype gap+30
Incentives55
Confidence66