Research · curated 21 Jul 2026

AI Assisted Vulnerability Research on Embedded Targets | QTNKSR

Coverage timeline

18 Jul 2026quentinkaiser.be

Single-source research — first reported, latest, and curated coincide.

Why it matters

AI coding agents lower the barrier to autonomous offensive vulnerability research against hard, poorly-tooled targets like RTOS firmware, illustrating how agentic AI can be operationalized for exploit development.

Security researcher Quentin Kaiser documents an experiment using OpenAI's Codex coding harness (running gpt-5.x models) as an autonomous agent for vulnerability research and exploit development against embedded real-time operating systems, including eCos and Broadcom BFC cable modems. The agent is equipped with skill sets (Trail of Bits marketplace, ghidra-rpc, and a custom eCos offensive-research skill) to navigate firmware, reverse-engineer with Ghidra/radare2, and stage exploits.