Google security agents find more than 100 high-severity software flaws in two days
THE BRIEF
Google Mandiant described an internal Agentic Vulnerability Discovery Harness that used chains of AI agents to identify more than 100 verified high-severity issues during a two-day investigation. The system has been used across tens of millions of lines of code and illustrates how AI can accelerate offensive and defensive security research.
WHY IT MATTERS
AI dramatically compresses vulnerability-discovery timelines. Defenders may need to assume that exploitable weaknesses will be found and weaponized faster than traditional patch cycles were designed to handle.
WHO SHOULD CARE
Application security teams, software vendors and CISOs.
WHAT TO DO NOW
- Shorten remediation cycles
- Expand automated code review
- Prepare for AI-accelerated vulnerability discovery
VERIFICATION NOTE
Selected from the SecBriefs radar and backfilled from the named source.