Research · curated 21 Jul 2026
AI Assisted Vulnerability Research on Embedded Targets | QTNKSR
First reported quentinkaiser.be
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
AI coding agents lower the barrier to autonomous offensive vulnerability research against hard, poorly-tooled targets like RTOS firmware, illustrating how agentic AI can be operationalized for exploit development.
Security researcher Quentin Kaiser documents an experiment using OpenAI's Codex coding harness (running gpt-5.x models) as an autonomous agent for vulnerability research and exploit development against embedded real-time operating systems, including eCos and Broadcom BFC cable modems. The agent is equipped with skill sets (Trail of Bits marketplace, ghidra-rpc, and a custom eCos offensive-research skill) to navigate firmware, reverse-engineer with Ghidra/radare2, and stage exploits.