OpenAI has released a private beta for a new AI agent called Aardvark that acts as a security researcher, finding vulnerabilities and applying fixes, at scale.
“Software security is one of the most critical—and challenging—frontiers in technology. Each year, tens of thousands of new vulnerabilities are discovered across enterprise and open-source codebases. Defenders face the daunting tasks of finding and patching vulnerabilities before their adversaries do. At OpenAI, we are working to tip that balance in favor of defenders,” OpenAI wrote in a blog post.
The agent continuously analyzes source code repositories to identify vulnerabilities, assess their exploitability, prioritize severity, and propose patches. Instead of using traditional analysis techniques like fuzzing of software composition analysis, Aardvark uses LLM-powered reasoning and tool-use.
It is designed to work alongside developers and also integrates with existing workflows like GitHub and Codex so that it can provide insights without disrupting software development speed.
Additionally, OpenAI’s testing of Aardvark found that it is also capable of finding bugs like logic flaws, incomplete fixes, or privacy issues.
It has been internally used at OpenAI and a couple of its alpha partners over the last several months, and in testing on “golden” repositories, it found 92% of known and synthetically-introduced vulnerabilities.
OpenAI also announced that it will offer pro-bono scanning to certain non-commercial open source projects to improve security of the open source ecosystem.
“Aardvark represents a new defender-first model: an agentic security researcher that partners with teams by delivering continuous protection as code evolves. By catching vulnerabilities early, validating real-world exploitability, and offering clear fixes, Aardvark can strengthen security without slowing innovation,” OpenAI wrote.
The post OpenAI announces agentic security researcher that can find and fix vulnerabilities appeared first on SD Times.
from SD Times https://ift.tt/JLzRV3j
Comments
Post a Comment