Google's Mandiant Deploys AI Pipeline That Uncovers 100+ Critical Vulnerabilities in Just Two Days
Summary
Google's Mandiant team unleashes a powerful multi-agent AI pipeline called AVDH that discovered over 100 critical security vulnerabilities in just two days, analyzing tens of millions of lines of code in 10 months and resulting in 12 assigned CVEs across widely used software.
Key Points
- Google's Mandiant team deploys the Agentic Vulnerability Discovery Harness (AVDH), a multi-agent AI pipeline built on Google ADK, to rapidly identify and validate critical security vulnerabilities in source code at machine speed.
- In just 10 months, AVDH has analyzed tens of millions of lines of code, uncovered over 100 critical vulnerabilities in two days during a single incident response engagement, and resulted in 12 assigned CVEs across widely used web extensions and open-source projects.
- AVDH combines sequential AI agents for threat modeling, entry point discovery, data flow analysis, and hypothesis validation with mandatory human expert review and a distilled knowledge system, creating a two-layered defense strategy alongside CodeMender's continuous scanning.