
Vulnerabilities and exploits: where are we headed?
Why AI makes vulnerability discovery defense-favoring (after a rough 2026-2027) but keeps exploitation offense-favoring. A follow-up to my Epoch AI piece.
Updates from https://tchauvin.com. Focus: AI safety and cybersecurity.
Live Last read · last published · next check

Why AI makes vulnerability discovery defense-favoring (after a rough 2026-2027) but keeps exploitation offense-favoring. A follow-up to my Epoch AI piece.

Links: [X thread] [LT paper] [B3IT paper] [tchauvin.com blog post]

Getting to ninety-five isn’t so simple

[paper]

[paper, website]

Target audience: cybersecurity people, and AI / AI safety people.

Below are some areas in the field of cybersecurity in AI where I would like to see progress.

A previous blog post introduced the eyeballvul vulnerability detection benchmark.

[paper]

Today I’m releasing eyeballvul, an open-source benchmark designed to enable the evaluation of SAST vulnerability detection tools, especially ones based on language models.