AI Models Replicate Zero-Day Discovery in Cybersecurity Research

AI Models Replicate Zero-Day Discovery in Cybersecurity Research

First seen 8 May 2026, 07:08 UTC Risky.Bizwww.provos.org 77% similarity 39.7

Article Content

Browse articles
ThreatCluster

Niels Provos demonstrated that older AI models can autonomously discover zero-day vulnerabilities using his IronCurtain orchestration framework. This research challenges the notion that only advanced models like Anthropic's Mythos can find such vulnerabilities. Provos successfully replicated findings from recent high-profile reports, including a 27-year-old vulnerability in the OpenBSD TCP SACK implementation, which he originally authored. His workflows utilized commercial models such as Opus and Sonnet, as well as open-weight models like Z.AI's GLM 5.1. The orchestration framework allows for structured vulnerability discovery without relying solely on the models' capabilities. The cost of investigations ranged from $30 to $150 per run, depending on the model used. This research opens new avenues for vulnerability discovery beyond proprietary systems.

Key Points: • Niels Provos replicated zero-day discoveries using older AI models, challenging current narratives. • The IronCurtain framework enables structured vulnerability discovery without advanced models. • Investigations using commercial models cost between $30 and $150, making it accessible.

ThreatCluster AI

Timeline

2026-05-08
Provos publishes findings on zero-day discovery
Niels Provos reveals his research on using older AI models to discover vulnerabilities, including a 27-year-old bug he authored.
www.provos.org
2026-05-08
Podcast discusses Provos' research
James Wilson interviews Niels Provos about his orchestration framework and its effectiveness in finding vulnerabilities.
Risky.Biz

Community

Browse all →