Artificial intelligence has become a double-edged sword in the field of cybersecurity. While attackers use it to automate and accelerate their malicious campaigns, security companies also employ it to defend themselves. In this context, Google has taken a significant step by publishing the blueprint of its agent-based vulnerability discovery system, a tool that has proven capable of finding over a hundred critical flaws in just two days.

Table of contents [Show]
The system, called Agentic Vulnerability Discovery Harness (AVDH), is an internal multi-agent AI infrastructure developed by Mandiant, the security company acquired by Google in 2022 and now part of Google Cloud. Mandiant has decided to share the design of this tool so that it can be adopted by other security teams and open-source developers, in a move that seeks to raise the level of collective protection against increasingly sophisticated threats.
The relevance of this announcement lies in the current context, where cybercrime has industrialized its operations. As we have already analyzed in the impact of AI on cybercrime, attackers no longer act in a linear fashion, but rather deploy continuous and optimized operations. Against this, traditional defenses fall short, and it is here that tools like AVDH make a difference.
According to Alex Tselevich and Michael Maturi, Mandiant analysts, the system has shown enormous potential during the ten months they have been using it. In a recent investigation into the theft of corporate repositories, AVDH managed to identify 100 critical vulnerabilities in just 48 hours, a time that would have been unthinkable with manual review. This finding not only accelerates incident response, but also allows security teams to prioritize their efforts on the most urgent threats.

AVDH's ability to analyze tens of millions of lines of code in a short time makes it an invaluable tool. In the mentioned case, the agents identified dozens of flaws in widely used web extensions and open-source projects, underscoring its impact on the security of the digital ecosystem in general.
AVDH's success is based on its orchestrated architecture of multiple agents, which work in a coordinated manner to amplify the discovery and validation of vulnerabilities. Unlike traditional scanners that rely on pattern matching, AVDH agents are specialized and actively validate hypotheses. This means they do not just launch generic alerts, but rather map execution paths, verify logic flaws, and contrast results against human-defined rules.
This approach significantly reduces the problem of 'alert fatigue', one of the main challenges in automated security. By filtering out noise and focusing on real vulnerabilities, analysts can spend their time assessing impact and designing mitigations, instead of reviewing thousands of false positives.

The publication of this blueprint has direct implications for businesses. First, it offers a practical guide to implementing similar systems, which could democratize access to advanced detection technologies. Second, it underscores the importance of adopting a proactive approach to cybersecurity, especially when attackers are already using AI to overcome traditional defenses.
For IT professionals, this news reinforces the need to train in the use of AI tools applied to security. Furthermore, the automation of routine tasks, such as code review, frees up time for teams to focus on more strategic aspects, such as incident response and continuous improvement of security postures.
At ForgeNEX, we have already explored how automation is transforming business processes, as in our practical guide on n8n and AI. Cybersecurity is no exception, and the integration of intelligent agents into security workflows is a logical step in this evolution.
Google and Mandiant's initiative not only demonstrates the potential of AI in cyber defense, but also sets a precedent for open collaboration in the industry. By sharing the blueprint, an ecosystem is fostered where companies can build on these advances, improving collective security.
However, we must not forget that the arms race in cybersecurity is continuous. While defenders adopt AI, attackers also refine their techniques. Therefore, it is crucial that organizations not only invest in technology, but also in talent and processes that allow them to leverage it to the fullest.
In short, the publication of AVDH is a milestone that marks the path towards more agile and effective cybersecurity. Companies that know how to integrate these capabilities into their operations will be better positioned to face future threats.
Original source: ComputerWorld. Analysis and adaptation by ForgeNEX.