Google-owned Mandiant disclosed an internal AI-assisted vulnerability discovery platform, the Agentic Vulnerability Discovery Harness (AVDH), saying it identified more than 100 verified high-severity software flaws in two days during a live investigation tied to stolen corporate repositories. Mandiant said the system has been used internally for about ten months, scanned tens of millions of lines of code, and produced tens of thousands of findings, including dozens of assignable vulnerabilities affecting widely used web extensions and open-source projects.
Mandiant said the work has already led to 12 assigned CVEs, including CVE-2026-13242 and CVE-2026-55803, with roughly another dozen cases still in coordinated disclosure. The company described AVDH as a pipeline of specialized AI agents handling threat modeling, entry-point discovery, context enrichment, hypothesis generation, and validation, while stressing that human analysts still review threat models and manually reproduce exploits before findings are accepted. To reduce false positives, agents are designed to challenge one another’s conclusions and apply consultant-authored rules by language, framework, and vulnerability type; Mandiant also said it evaluated the system on synthetic intentionally vulnerable codebases rather than public benchmarks to avoid model-training contamination.

Track how attackers are adapting to this technology.
4 events from the most recent confirmed update back to the earliest known activity.
Google published a Threat Intelligence blog post describing Mandiant's internal AVDH system, its multi-agent workflow, and its use in agentic source-code review. The disclosure emphasized human validation and techniques intended to reduce false positives.
Mandiant said findings from AVDH have already resulted in 12 assigned CVEs, including CVE-2026-13242 and CVE-2026-55803. It also said about a dozen additional vulnerabilities are under active disclosure.
During a live investigation involving stolen corporate repositories, Mandiant said AVDH identified more than 100 verified high-severity vulnerabilities in just two days. The company presented this as a real-world demonstration of the system's effectiveness.
Mandiant said its Agentic Vulnerability Discovery Harness (AVDH), an AI-assisted source-code vulnerability discovery system, has been running internally for ten months. During that period it scanned tens of millions of lines of code and generated tens of thousands of findings.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
helpnetsecurity.com
Open sourcecloud.google.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.