{"id":429,"date":"2026-08-09T12:17:09","date_gmt":"2026-08-09T12:17:09","guid":{"rendered":"https:\/\/43.156.46.27\/?p=429"},"modified":"2026-08-09T12:17:09","modified_gmt":"2026-08-09T12:17:09","slug":"vulnerability-research-in-the-agentic-age","status":"publish","type":"post","link":"https:\/\/haco.zone\/?p=429","title":{"rendered":"Vulnerability Research in the Agentic Age"},"content":{"rendered":"\n<figure class=\"wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio\"><div class=\"wp-block-embed__wrapper\">\n<iframe loading=\"lazy\" title=\"Black Hat USA 2026 Keynote: Vulnerability Research in the Agentic Age\" width=\"640\" height=\"360\" src=\"https:\/\/www.youtube.com\/embed\/VNYe3Cnk5Pw?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe>\n<\/div><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The &#8220;Agentic Age&#8221; of Vulnerability Research (Yan Shoshitaishvili)<\/strong><br>Professor Yan Shoshitaishvili argues that cybersecurity has moved beyond traditional methods and simple Large Language Models (LLMs) into the &#8220;Agentic Age,&#8221; where autonomous AI workflows are fundamentally changing how software bugs are found.<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>The Problem with the Old Way:<\/strong>\u00a0Traditionally, finding vulnerabilities was a slow, human-intensive academic process. Researchers would develop new static or dynamic analysis tools (like fuzzers), which required massive manual effort and struggled to scale.<\/li>\n\n\n\n<li><strong>The Problem with Raw AI:<\/strong>\u00a0Simply pasting code into an LLM (like ChatGPT) and asking it to find bugs doesn&#8217;t work well. It generates too much &#8220;slop&#8221; (false positives and hallucinations) that overwhelm security teams.<\/li>\n\n\n\n<li><strong>The Breakthrough\u2014Vulnerability Properties:<\/strong>\u00a0Yan\u2019s team discovered that the key is teaching AI agents specific &#8220;vulnerability properties&#8221; (the abstract shapes or logic of how a specific type of hack works).<\/li>\n\n\n\n<li><strong>Massive Scale Discovery:<\/strong>\u00a0By combining these properties with autonomous AI workflows, his team analyzed Huawei&#8217;s new HarmonyOS. The AI agents autonomously discovered hundreds of new, zero-day, privilege-escalation vulnerabilities at a speed and scale that would be impossible for human researchers.<\/li>\n\n\n\n<li><strong>The &#8220;Rust&#8221; Counter-Argument:<\/strong>\u00a0To test if modern, &#8220;memory-safe&#8221; programming languages would stop AI hackers, Yan&#8217;s team used AI to rewrite critical C libraries into Rust. However, when they turned their vulnerability-finding agents loose on the new Rust code, the AI still found numerous flaws\u2014proving that while memory-safe languages stop certain bugs, AI will simply adapt and find logic, concurrency, and time-of-check bugs instead.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Implications for the Future of Cybersecurity<\/strong><br>Yan concludes the keynote with several stark warnings and predictions for the industry:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Responsible Disclosure is Broken:<\/strong>\u00a0The traditional method of quietly reporting bugs to vendors and waiting for patches is obsolete. AI agents can now find hundreds of bugs in a matter of days, meaning vendors will soon be overwhelmed by a tsunami of legitimate vulnerability reports.<\/li>\n\n\n\n<li><strong>Model Restriction Won&#8217;t Work:<\/strong>\u00a0Attempting to lock down or restrict access to advanced AI models to prevent malicious hacking is a flawed strategy. Open-source models and community-driven workflows will inevitably catch up.<\/li>\n\n\n\n<li><strong>Humans Are Still Necessary:<\/strong>\u00a0Despite the power of AI, humans don&#8217;t need to stop learning how to hack. Humans are no longer needed for the manual labor of finding bugs, but their creativity is required to understand threat models, extract new vulnerability properties, and direct the AI agents.<\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>The &#8220;Agentic Age&#8221; of Vulnerability Research (Yan Shoshitaishvili)Professor Yan Shoshitaishvili [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[3],"tags":[35,5],"class_list":["post-429","post","type-post","status-publish","format-standard","hentry","category-black-hat","tag-llm","tag-security"],"_links":{"self":[{"href":"https:\/\/haco.zone\/index.php?rest_route=\/wp\/v2\/posts\/429","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/haco.zone\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/haco.zone\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/haco.zone\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/haco.zone\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=429"}],"version-history":[{"count":1,"href":"https:\/\/haco.zone\/index.php?rest_route=\/wp\/v2\/posts\/429\/revisions"}],"predecessor-version":[{"id":430,"href":"https:\/\/haco.zone\/index.php?rest_route=\/wp\/v2\/posts\/429\/revisions\/430"}],"wp:attachment":[{"href":"https:\/\/haco.zone\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=429"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/haco.zone\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=429"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/haco.zone\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=429"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}