Research · curated 15 Jul 2026
We built a vulnerability vending machine: AI tokens in, zero-days out
First reported bleepingcomputer.com
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
Fully automated LLM-driven pipelines that discover and exploit zero-days in widely used software signal that AI-accelerated offensive vulnerability research is moving from theory to practical capability, shrinking the window defenders have to patch.
Intruder describes building an automated pipeline that pairs LLMs with the Joern code-scanning engine and a 'program slice' technique to find and exploit vulnerabilities in production software with no human in the loop. The team reports discovering a remote, multi-stage SQL injection zero-day (CVE-2026-3985) in a WordPress plugin with over 300,000 users, fully automated from discovery through exploitation.