Powered by OpenAIRE graph
Found an issue? Give us feedback
image/svg+xml art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos Open Access logo, converted into svg, designed by PLoS. This version with transparent background. http://commons.wikimedia.org/wiki/File:Open_Access_logo_PLoS_white.svg art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos http://www.plos.org/ ZENODOarrow_drop_down
image/svg+xml art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos Open Access logo, converted into svg, designed by PLoS. This version with transparent background. http://commons.wikimedia.org/wiki/File:Open_Access_logo_PLoS_white.svg art designer at PLoS, modified by Wikipedia users Nina, Beao, JakobVoss, and AnonMoos http://www.plos.org/
ZENODO
Report . 2026
License: CC BY
Data sources: ZENODO
ZENODO
Report . 2026
License: CC BY
Data sources: Datacite
ZENODO
Report . 2026
License: CC BY
Data sources: Datacite
versions View all 2 versions
addClaim

Proven Exploitable: The Practitioner's Guide to AI-Augmented Vulnerability Discovery

Authors: Priyadarshini, Bindiya;

Proven Exploitable: The Practitioner's Guide to AI-Augmented Vulnerability Discovery

Abstract

Two AI systems — Microsoft MDASH and Anthropic's Claude Mythos Preview — have crossed a capability threshold that changes the economics of vulnerability discovery. MDASH found 16 confirmed vulnerabilities in Microsoft's May 2026 Patch Tuesday release using a 100+ agent ensemble, achieving 96.55% on the CyberGym benchmark. Mythos Preview achieved 83.1% as a single frontier model — more than 16 percentage points ahead of the prior state of the art. Commercial SAST tools score 30–50% on the same benchmark. This paper gives practitioners the technical depth to evaluate and deploy these systems honestly. It covers the MDASH five-stage pipeline, Mythos autonomous discovery workflow, real-world CVE evidence, enterprise integration architecture including a deployment mapping and reachability layer, Microsoft Sentinel and MCP server integration, supply chain and third-party scanning, incident response workflows, and language-by-language coverage assessment. Eight prioritised recommendations for security engineers and CISOs. AI-assistance disclosure included. All primary sources verified against original publications. Companion paper: Calibrated to Act: The Practitioner's Guide to Building an Agentic SOC That Knows When Not to Act — https://doi.org/10.5281/zenodo.21157411

Keywords

AI security vulnerability discovery MDASH Mythos supply chain security enterprise security CyberGym penetration testing SAST security architecture

  • BIP!
    Impact byBIP!
    selected citations
    These citations are derived from selected sources.
    This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
    0
    popularity
    This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network.
    Average
    influence
    This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
    Average
    impulse
    This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network.
    Average
Powered by OpenAIRE graph
Found an issue? Give us feedback
selected citations
These citations are derived from selected sources.
This is an alternative to the "Influence" indicator, which also reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
BIP!Citations provided by BIP!
popularity
This indicator reflects the "current" impact/attention (the "hype") of an article in the research community at large, based on the underlying citation network.
BIP!Popularity provided by BIP!
influence
This indicator reflects the overall/total impact of an article in the research community at large, based on the underlying citation network (diachronically).
BIP!Influence provided by BIP!
impulse
This indicator reflects the initial momentum of an article directly after its publication, based on the underlying citation network.
BIP!Impulse provided by BIP!
0
Average
Average
Average
Green