GC3 AI hackathons for government code remediation
Public Sector Action
Summary
Hide ▲
Show ▼
GC3 ran weekly AI hackathons that uncovered and helped remediate 407 vulnerabilities across nine UK government departments, reducing exploitable risk in public-sector code. The initiative found issues including authentication bypass, data exposure, and remote code execution. All critical and high-risk exploitable weaknesses were remediated, and no exploitation was identified. The effort also showed how frontier models can support cross-boundary vulnerability discovery and triage.
Related Happenings
Microsoft MDASH enters limited private preview for AI-driven vulnerability discovery at scale
Security Tool/Service
H score16
First: 13.05.2026 16:46
Last: 13.05.2026 16:46
Sources 1
About this happening:
Microsoft's **MDASH** has entered **limited private preview**, adding a new **AI-driven vulnerability discovery** service that can validate and prove exploitable defects at scale....
Microsoft MDASH enters limited private preview for AI-driven vulnerability discovery at scale
Security Tool/ServiceAbout this happening: Microsoft's **MDASH** has entered **limited private preview**, adding a new **AI-driven vulnerability discovery** service that can validate and prove exploitable defects at scale....
OpenAI launches Daybreak cybersecurity initiative for AI-powered vulnerability detection and patch validation
Security Tool/Service
H score10
First: 12.05.2026 09:55
Last: 12.05.2026 09:55
Sources 1
About this happening:
OpenAI's **Daybreak** launch adds an **AI-powered cybersecurity service** for **vulnerability detection** and **patch validation**, helping organizations fix flaws before attacker...
OpenAI launches Daybreak cybersecurity initiative for AI-powered vulnerability detection and patch validation
Security Tool/ServiceAbout this happening: OpenAI's **Daybreak** launch adds an **AI-powered cybersecurity service** for **vulnerability detection** and **patch validation**, helping organizations fix flaws before attacker...
Popular open-source web-based system administration tool zero-day 2FA-bypass security flaw
Vulnerability
H score27
First: 11.05.2026 16:00
Last: 11.05.2026 16:00
Sources 1
About this happening:
An **AI-assisted zero-day** in a **popular open-source web-based system administration tool** created a **2FA-bypass** risk before the flaw was closed by the vendor. **GTIG** said...
Popular open-source web-based system administration tool zero-day 2FA-bypass security flaw
VulnerabilityAbout this happening: An **AI-assisted zero-day** in a **popular open-source web-based system administration tool** created a **2FA-bypass** risk before the flaw was closed by the vendor. **GTIG** said...
Prominent cybercrime threat actors AI-assisted zero-day exploitation campaign
Campaign
H score39
First: 11.05.2026 16:00
Last: 11.05.2026 16:00
Sources 1
About this happening:
An **AI-assisted zero-day exploitation campaign** was planned by **prominent cybercrime threat actors**, but the effort was **disrupted before deployment** and did not reach its i...
Prominent cybercrime threat actors AI-assisted zero-day exploitation campaign
CampaignAbout this happening: An **AI-assisted zero-day exploitation campaign** was planned by **prominent cybercrime threat actors**, but the effort was **disrupted before deployment** and did not reach its i...
Google GTIG analysis of adversary AI use for exploit development and attack orchestration
Technical Analysis
H score36
First: 11.05.2026 16:00
Last: 11.05.2026 16:00
Sources 1
About this happening:
**Google Threat Intelligence Group** published findings showing **adversaries using AI** for **exploit development** and **attack orchestration**, signaling that model-assisted tr...
Google GTIG analysis of adversary AI use for exploit development and attack orchestration
Technical AnalysisAbout this happening: **Google Threat Intelligence Group** published findings showing **adversaries using AI** for **exploit development** and **attack orchestration**, signaling that model-assisted tr...
Timeline
-
15.06.2026 12:30 2 articles · 2h ago
GC3 scans government repositories with frontier AI models and remediates 407 findings
Initial DisclosureGC3, an initiative from NCSC and DSIT, used frontier AI models in weekly in-person hackathons to scan public code repositories across nine UK government departments, identifying 407 findings including authentication bypass, data exposure, and remote code execution. All critical and high-risk exploitable weaknesses were remediated, and no evidence of exploitation was identified.
Show sources
- UK Government Finds 400+ Vulnerabilities in AI Hackathons — www.infosecurity-magazine.com — 15.06.2026 12:30
- UK Government Finds 400+ Vulnerabilities in AI Hackathons — www.infosecurity-magazine.com — 15.06.2026 12:30