News: 0178627244

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Google Says Its AI-Based Bug Hunter Found 20 Security Vulnerabilities (techcrunch.com)

(Saturday August 09, 2025 @05:45PM (EditorDavid) from the bug-hunt dept.)


"Heather Adkins, Google's vice president of security, [1]announced Monday that its LLM-based vulnerability researcher Big Sleep found and reported 20 flaws in various popular open source software," [2]reports TechCrunch :

> Adkins said that Big Sleep, which is developed by the company's AI department DeepMind as well as its elite team of hackers Project Zero, [3]reported its first-ever vulnerabilities , mostly in open source software such as audio and video library FFmpeg and image-editing suite ImageMagick. [There's also a "medium impact" [4]issue in Redis

>

> Given that the vulnerabilities are not fixed yet, we don't have details of their impact or severity, as Google [5]does not yet want to provide details , which is a standard policy when waiting for bugs to be fixed. But the simple fact that Big Sleep found these vulnerabilities is significant, as it shows these tools are starting to get real results, even if there was a human involved in this case.

>

> "To ensure high quality and actionable reports, we have a human expert in the loop before reporting, but each vulnerability was found and reproduced by the AI agent without human intervention," Google's spokesperson Kimberly Samra told TechCrunch.

Google's vice president of engineering [6]posted on social media that this demonstrates "a new frontier in automated vulnerability discovery."



[1] https://x.com/argvee/status/1952390039700431184

[2] https://techcrunch.com/2025/08/04/google-says-its-ai-based-bug-hunter-found-20-security-vulnerabilities/

[3] https://issuetracker.google.com/issues?q=componentid:1836411&s=type:desc&s=issue_id:desc&pli=1

[4] https://issuetracker.google.com/issues/433679595

[5] https://googleprojectzero.blogspot.com/2025/07/reporting-transparency.html

[6] https://x.com/royalhansen/status/1952424018663162235



And how many false-positives did it find? (Score:2)

by Brain-Fu ( 1274756 )

I have tried pasting chunks of code into AI prompts and saying "where are the bugs?"

The answers included a lot of "this might be a problem if [condition that clearly does not apply]." Or it sees a potential problem that is prevent by an "if" statement shortly before it. Or it just starts hallucinating about common functions not doing what they clearly and reliably do. It has very rarely found any actual bugs for me, and that one time it did, it was an obvious bug I already knew about.

I think an AI bug fi

Our country has plenty of good five-cent cigars, but the trouble is
they charge fifteen cents for them.