Google’s Bug Po-Powred hunter has just reported his first lot of security vulnerability.
Heather Adkins, Vice President of Google security, Announced Monday which is the vulnerability researcher based on LLM Big Sleep found and has reported 20 defects in various popular open source software.
Adkins said that Big Sleep, which is developed by the Department of the Deepmind company and its Hacker Project Zero elite team, First vulnerabilities reportedMainly in Open Source Software such as the FFMIGGI AUDIO AND VIDEO LIBRARY AND IMAGE-EDING SUITAMAGICK.
Since vulnerabilities are not yet fixed, we have no details on their impact or gravity, like Google Des does not want the APVID details yetwhich is a standard policy when waiting for the bug to be fixed. But the simple fact that Big Sleep has discovered that these vulnerability is significant, as it shows that these tools are starting to obtain reality, even if in this case there was a human being.
“To guarantee high quality and impossible relationships, we have a human expert in the cycle before relationships, but every vulnerability was found and reproduced by the agent to without human intervention,” the spokesman for Google Kimberly Samra told Techcrunch.
Royal Hansen, vice president of Google’s engineering, Written on x That the results demonstrate “a new frontier in the automated discovery of vulnerability”.
LLM powered tools that can look for and find vulnerability They are already a reality. In addition to the great sleep, there is Runsybil and Xbow, among others.
Techcrunch event
San Francisco
|
27-29 October 2025
XBOW has obtained titles Has reached the top Of one of the US rankings at the Bounty Bug Hackerone platform. It is important to note that in most boxes, these relationships have a human being at a certain point in the process to verify that the bug hunter with AI’s air has found a legitimate vulnerability, as in the case of large sleep.
Vlad Ionescu, co-founder and Chief Technology Officer of Runsybil, a startup that develops AI Poor Bug hunters, told Techcrunch that Big Sleep is a “legitimate” project, since it has “good design, the people behind it know what they do. It has the search for bugs and the search for Deepmind has the fire power to launch it.”
There is a lot of promises hatefully with these tools, but which also mean negative sides. Several people who maintain several software projects have complained Bug relationships that are actually hallucinationsWith some who call them the cutting equivalent of ai slop insects.
“This is the problem in which people are meeting, is that we have a lot of things that seem gold, but in reality it is only a shit,” Ionescu said previously to Techcrunch.