Security firm Intruder has developed an AI-powered system that automatically identifies previously unknown software vulnerabilities by combining code analysis with large language models. The tool already discovered and exploited a WordPress plugin zero-day.
Intruder's "vulnerability vending machine" represents a significant shift in how security researchers approach code analysis. The system feeds code segments into language models, enabling automated detection of complex vulnerabilities that traditional static analysis tools often miss.
The breakthrough came when the system identified a previously unknown zero-day flaw in a WordPress plugin. Intruder followed responsible disclosure protocols, working with affected parties before public revelation. The company reports additional vulnerabilities already discovered through the same process.
The approach combines code slicing—breaking software into manageable segments—with LLM capabilities to understand context and identify logical flaws. This hybrid method proves more effective than conventional vulnerability scanning, which typically focuses on known attack patterns.
The development underscores both the promise and risk of AI in cybersecurity. Automated vulnerability discovery accelerates security research and patch development, benefiting defenders. However, the same technology could enable attackers to identify exploits at scale.
Intruder's responsible disclosure approach demonstrates awareness of these dual-use implications. The company discovered vulnerabilities through coordinated disclosure rather than public exploit, allowing vendors time to develop and deploy patches.
The system's ability to find complex vulnerabilities reflects broader trends in AI-assisted security. Machine learning models trained on code patterns can identify subtle logical errors and security weaknesses humans might overlook. The addition of LLM reasoning capabilities enhances this further, allowing the system to understand intent and potential attack vectors.
As vulnerability discovery becomes increasingly automated, the security industry faces pressure to accelerate patch cycles and improve code quality upstream. The emergence of such tools may also shift the economics of bug bounty programs and vulnerability research.
Intruder has not disclosed the full technical details or timeline for broader deployment, suggesting the tool remains in controlled evaluation. The company's focus on responsible disclosure indicates plans to work with vendors before scaling the system's capabilities.
Visa is enabling expired payment cards to continue processing contactless transactions through a new feature. The move allows cardholders to keep using their old cards for tap-to-pay purchases even after expiration.
A Texas-based student discovered and reported an unauthorized AI system being used for cyberattacks. The disclosure prompted immediate investigation and security responses from affected organizations.
Iranian cyber actors shut down a small UK power generation facility for four days, according to sources cited by The Telegraph. The incident coincides with a broader wave of attacks targeting US water utilities attributed to Iran-affiliated groups.
A supply-chain attack is exploiting legitimate device-update apps to infect Android-based car head units with malware. The compromised devices are being enlisted into proxy botnets or used for ad fraud schemes.