Offensive-Security Submersion AI's Basin Model Uncovers Critical Vulnerabilities
Article Content
- •Submersion AI's Basin model ranks 8th globally on CyberGym with an 80.8% score.
- •Basin uncovered critical zero-day vulnerabilities, including CVE-2026-86733 and CVE-2026-82450.
- •The model operates within customer infrastructure, ensuring data sovereignty and security.
Submersion AI launched its new cybersecurity model, Basin, which achieved an 80.8% score on the CyberGym benchmark, ranking 8th globally. Basin has successfully identified high-severity zero-day vulnerabilities in widely used software, including CVE-2026-86733 (Snipe-IT) and CVE-2026-82450 (BookStack). The model operates entirely within customer-controlled environments, addressing security concerns related to hosted AI. It is designed to help security teams detect vulnerabilities that attackers might exploit. The vulnerabilities discovered by Basin are now publicly assigned to the Submersion.ai Security Research Team. The launch of Basin comes amid ongoing discussions about the impact of AI on cybersecurity and the need for advanced tools to keep pace with evolving threats.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Submersion AI and CVE-2026-72898 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Trezor Data Breach Exposes 80,689 Customers to Phishing Risks A significant data breach at Trezor's logistics partner, ShipMonk, has exposed personal information of approximately 80,689 customers, including names, email addresses, phone numbers, and shipping addresses. The breach was enabled by a critical SQL injection vulnerability (CVE-2026-72898) in the Metabase analytics…
Critical Zero-Day Exploits Target F5 and Check Point Products F5 Networks released emergency hotfixes for a critical zero-day vulnerability, CVE-2026-94127, in its BIG-IP Access Policy Manager on September 22, 2026, after confirming active exploitation. This flaw allows unauthenticated remote code execution (RCE) and has a CVSS score of 9.8. Concurrently, Check Point disclosed…