Forescout Verde Labs benchmarks AI models for vulnerability research and autonomous exploit generation
Technical Analysis
Summary
Hide ▲
Show ▼
Forescout’s Verde Labs found that 50 AI models now perform vulnerability research and exploit development much more effectively, making unknown bugs easier for inexperienced attackers to find. The shift matters because half of the tested models could generate working exploits autonomously. The benchmark suggests AI-assisted offense has moved from novelty to practical capability.
Related Happenings
Google GTIG analysis of adversary AI use for exploit development and attack orchestration
Technical Analysis
First: 11.05.2026 16:00
Last: 11.05.2026 16:00
Sources 1
About this happening:
**Google Threat Intelligence Group** published findings showing **adversaries using AI** for **exploit development** and **attack orchestration**, signaling that model-assisted tr...
Google GTIG analysis of adversary AI use for exploit development and attack orchestration
Technical AnalysisAbout this happening: **Google Threat Intelligence Group** published findings showing **adversaries using AI** for **exploit development** and **attack orchestration**, signaling that model-assisted tr...
Enterprise AI deployments need governance and segmentation after red-team failures
Defensive Guidance
First: 24.04.2026 15:10
Last: 24.04.2026 15:10
Sources 1
About this happening:
**Enterprise AI deployments** are exposing familiar security gaps, making **governance**, **segmentation**, and **red-team validation** urgent to reduce the risk of **data theft**...
Enterprise AI deployments need governance and segmentation after red-team failures
Defensive GuidanceAbout this happening: **Enterprise AI deployments** are exposing familiar security gaps, making **governance**, **segmentation**, and **red-team validation** urgent to reduce the risk of **data theft**...
OpenNDS zero-day vulnerabilities (multiple vulnerabilities)
Vulnerability
First: 17.04.2026 16:20
Last: 17.04.2026 16:20
Sources 1
How related:
During testing Forescout said that using single prompts, the RAPTOR agentic framework, and the firm’s own extensions, they discovered four new zero-day vulnerabilities in OpenNDS which is widely deployed.
About this happening:
Researchers uncovered **four new zero-day vulnerabilities** in **OpenNDS**, creating unknown-risk exposure in a **widely deployed** software component. The flaws were found using...
OpenNDS zero-day vulnerabilities (multiple vulnerabilities)
VulnerabilityHow related: During testing Forescout said that using single prompts, the RAPTOR agentic framework, and the firm’s own extensions, they discovered four new zero-day vulnerabilities in OpenNDS which is widely deployed.
About this happening: Researchers uncovered **four new zero-day vulnerabilities** in **OpenNDS**, creating unknown-risk exposure in a **widely deployed** software component. The flaws were found using...
OpenAI launches GPT‑5.4‑Cyber and expands TAC access for cyber defense
Security Tool/Service
First: 15.04.2026 19:00
Last: 15.04.2026 19:00
Sources 1
About this happening:
OpenAI launched **GPT‑5.4‑Cyber** and expanded **Trusted Access for Cyber (TAC)**, giving vetted defenders broader access to a **cyber-permissive** model for **defensive workflows...
OpenAI launches GPT‑5.4‑Cyber and expands TAC access for cyber defense
Security Tool/ServiceAbout this happening: OpenAI launched **GPT‑5.4‑Cyber** and expanded **Trusted Access for Cyber (TAC)**, giving vetted defenders broader access to a **cyber-permissive** model for **defensive workflows...
AISI and NCSC guidance on cybersecurity basics after Mythos Preview testing
Public Sector Action
First: 14.04.2026 12:30
Last: 14.04.2026 12:30
Sources 1
About this happening:
The **UK AI Security Institute (AISI)** and **National Cyber Security Centre (NCSC)** urged organizations to strengthen **cybersecurity basics** after evaluating **Anthropic’s Myt...
AISI and NCSC guidance on cybersecurity basics after Mythos Preview testing
Public Sector ActionAbout this happening: The **UK AI Security Institute (AISI)** and **National Cyber Security Centre (NCSC)** urged organizations to strengthen **cybersecurity basics** after evaluating **Anthropic’s Myt...
Timeline
-
17.04.2026 16:20 2 articles · 1mo ago
Forescout Verde Labs benchmarks AI vulnerability research and exploit generation
Technical Analysis UpdateOn 2026-04-17, Forescout’s Verde Labs said it tested 50 AI models from commercial, open-source, and underground sources and found that all could complete vulnerability research tasks while half could generate working exploits autonomously. The strongest models, Claude Opus 4.6 and Kimi K2.5, could find and exploit vulnerabilities without complex prompts, and testing with single prompts, RAPTOR, and custom extensions uncovered four new zero-day vulnerabilities in OpenNDS.
Show sources
- Commercial AI Models Show Rapid Gains in Vulnerability Research — www.infosecurity-magazine.com — 17.04.2026 16:20
- Commercial AI Models Show Rapid Gains in Vulnerability Research — www.infosecurity-magazine.com — 17.04.2026 16:20