Thursday, October 1, 2026

Just write the right prompt

 900 vulnerability hypotheses and 12 billion tokens.

"Just write the right prompt," they said.


The project by the numbers:

๐Ÿ”Ž 900 vulnerability hypotheses proposed by models.

๐Ÿงช 69 findings confirmed with working PoCs.

๐Ÿ›  103 groups of findings submitted to developers; fixes already accepted for 46.

๐Ÿค– 1,173 human prompts and 615 sub-agents.

⏱️ Approximately 210 agent-hours of work.

๐Ÿ”ฅ 12.16 billion tokens processed.

Sergey Gordeychik, co-founder and CEO of CyberOK, presented a talk at ZeroNights 2026 (https://zeronights.ru/) titled "May Rust In Peace Be With You" (https://t.me/cyberok_news/253). It covered vulnerability discovery using AI and the engineering required to turn model outputs into actual zero-days and fixes.


It all began with a project requiring the processing of millions of packets, the choice of Rust, and the question: "Does a safe language mean a safe application?" It evolved into a proprietary research pipeline and discoveries within Rust libraries, RustDesk, Chromium, OpenAI Codex, and Linux.


Behind the numbers lie threat models, independent search passes, fuzzing, convincing AI errors, the futility of SAST, and interactions with maintainers.


And there are also vulnerabilities in the very tools we trust to find vulnerabilities.


AI is changing the economics of bug hunting. Yet, proving the issue and getting the fix to users is still a job for one of us. Attackers have the same tools—and they don't need to wait for PR approval.


We need to learn to stay one step ahead.


๐Ÿ”— rust-in-peace: code, methodology, and public findings (https://github.com/scadastrangelove/rust-in-peace)

No comments:

Post a Comment