DARPA’s AI Cyber Challenge demonstrated autonomous systems can find and repair flaws in critical-infrastructure open-source software: finalists analyzed more than 54 million lines across 63 challenges, discovered 54 synthetic vulnerabilities, patched 43, and identified 18 real vulnerabilities undergoing responsible disclosure. Team Atlanta—Georgia Tech, Samsung Research, KAIST, and POSTECH—won the competition; DARPA and ARPA-H plan to transition the technology and open-source all seven finalist systems.
Aarno Labs separately demonstrated AI-assisted remediation on CVE-2018-18732 in Tenda AC18 firmware, where the ntpServer CGI parameter reaches a 260-byte stack buffer through an unchecked strcpy, enabling overwrite of saved control-flow state. A language model produced a 12-byte binary patch replacing the copy with a 256-byte-bounded strncpy, and CodeHawk reportedly discharged the resulting write-bound proof obligation; however, Aarno Labs cautioned that the verified change fixes only this flaw and noted another undisclosed API-contract misuse in shared library code.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
During the August 2024 semifinals, AIxCC systems identified 37% of synthetic vulnerabilities and patched 25% of those identified.
Aarno Labs reported identifying a second, more serious API-contract misuse in shared library code shared across product lines, but did not disclose technical details or establish reachability from fromSetSysTime.
Aarno Labs analyzed CVE-2018-18732 in the Tenda AC18 httpd binary, where an attacker-controlled ntpServer parameter reaches strcpy into a 260-byte stack buffer in fromSetSysTime. A language-model-generated three-instruction patch replaced strcpy with strncpy using a 256-byte bound, and CodeHawk reportedly discharged the destination write-bound obligation without lost invariants elsewhere in the function.
During the final competition, teams found 18 real non-synthetic vulnerabilities and submitted 11 patches; one C-code vulnerability was patched independently by maintainers. DARPA said four finalist cyber reasoning systems were released immediately as open source and added $1.4 million in transition prizes.
DARPA announced Team Atlanta as the winner of the two-year AI Cyber Challenge, with Trail of Bits and Theori placing second and third. The finalist systems analyzed 63 challenges spanning more than 54 million lines of code, discovering 54 synthetic vulnerabilities and patching 43 of them.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.