I’ve spent this past year hunting for vulnerabilities across the stack using AI, and a lot has changed in the security world. In this post, I’d like to share what’s changed, what hasn’t, and where I think security research is headed.
Commoditization of research
This year, AI became more capable of finding vulnerabilities at low cost and high speed. It was a bittersweet feeling when I gave Claude a target repository and vulnerabilities started pumping out. I remember scouring through obscure C++ libraries, learning how to read templated C++ code, and wrestling with the compiler to get libFuzzer working. Now much of that setup and exploration can be done with a prompt and a few minutes with an agent. Using AI, I spent countless hours taking apart software I had always dreamed of investigating, learning and experimenting with fuzzing techniques. This led to unique discoveries, including some the agent had missed during code review. The quality of the research still depends on the operator and their ability to reason and steer the agent. That judgement shows up in choosing targets, questioning assumptions, and deciding where to look next.
Another capability that I feel deserves more spotlight is AI’s ability to help reverse engineer binaries. Before AI, reverse engineering was a magical skill that only those who had stared at assembly long enough could acquire. Today, an agent with access to Ghidra can help reconstruct readable code, explain unfamiliar functions, and navigate a binary much faster. With an agent helping me navigate unfamiliar binaries, I have been able to investigate closed-source targets that previously felt out of reach.
Last but not least, exploit engineering has become cheaper and easier. Agents are particularly effective at exploit engineering tasks when they have a test environment that provides useful feedback. They can test an approach, inspect what happened, and iterate towards a desired outcome, such as popping a shell.
Overall, it has become significantly easier to conduct security research, and I’m excited to continue my work as a researcher.
Slopification of security research
Commoditization has brought a new set of issues. Some bug bounty programs are being overwhelmed by low-quality submissions and duplicates. Programs are responding by tightening proof requirements, reducing rewards, or ending paid bounties altogether. The good news is that AI is also helping us uncover previously unknown vulnerabilities. The challenge is that coordination gets harder as report volume grows and the signal-to-noise ratio falls. Generating a plausible report can cost very little for the submitter, but verification can still take substantial time and attention. I expect more programs to prioritize reproducible evidence and demonstrated impact, adopt approaches similar to Apple’s Target Flags, and bring more vulnerability discovery in-house.
The paradox of innovation
So far, the biggest changes in my own work have been in finding and exploring vulnerabilities. I think the harder challenge is turning those capabilities into stronger defenses. Findings still need to be verified and prioritized, and fixes need to be tested and deployed. Meanwhile, AI systems themselves need to be secured, and attackers have gained more scalable tools. I see an opportunity for security researchers to become builders and turn their insights into defensive infrastructure, from automated validation and remediation to architectures that prevent whole classes of vulnerabilities.
The future researcher
Many security researchers develop deep expertise in specific software, like VMs, browsers, and operating systems. Those strong fundamentals can make us powerful generalists in the age of AI, helping us investigate unfamiliar systems and apply what we learn across the stack.
I’m excited to see how security research evolves and to help turn those capabilities into stronger defenses.