RAVNSecurity

Findings · CVE

One pixel was enough.That is how an AI got into Bing.

Johan Almgren · Pentester and founder

Published 2026-07-24 · 7 min read

The question is no longer whether an AI can find a real security flaw. That has been answered several times over, in software sitting at the foundation of almost everything. The question is how often it is right, and what it takes to know.

Four findings in software you use without knowing it

SQLite is a small database found in practically every phone and browser. In July 2025 Google reported that its AI had found a flaw in it that Google says was known only to attackers and close to being exploited. Google describes it as the first time an AI was used to directly stop an attack already underway.[01]

OpenSSL is the code that handles encryption across much of the internet. The year before, Google's automated testing, boosted with AI, found a flaw there that had sat unnoticed for about twenty years. Google's own account is that it would not have been found by the test routines people had already written.[02]

In March 2026 Microsoft fixed two flaws in Bing Images found by an AI platform. Both were rated top severity. The attack was a tiny one-pixel image, built so that the image processing on Microsoft's servers was tricked into running a command instead of opening an image file. The command ran with the system's highest privileges.[03]

In April 2026 the AI vendor Anthropic reported that its model both found and exploited, on its own, a seventeen-year-old flaw in the FreeBSD operating system that granted full control of the machine without logging in. No human was involved after the initial request to look.[04]

This is not a handful of lucky hits

A single finding can be luck. The US research agency DARPA ran a competition to find out whether it was. Seven competing systems found 54 of 63 planted vulnerabilities, patched 43 of them, and additionally found 18 previously unknown flaws in real code. The average cost was 152 dollars per task.[05]

90,6 %

Anthropic had outside security firms review 1,752 of the findings its AI had made in open-source software. 90.6 percent were judged real. At that point the programme had turned up over 23,000 items across a thousand projects.[06]

Strong numbers. But note what they measure. These are the kind of flaws that make a program crash, and a crash can be proven. The machine can try again and again until it sees a clear yes or no.

The other half of the story

On 26 January 2026 Daniel Stenberg shut down the bounty programme for curl, a small program used to fetch data over the network that ships in billions of devices. It had run since 2019, produced 87 confirmed vulnerabilities and paid out over 100,000 dollars. The share of reports that turned out to be real had fallen from just over 15 percent to below 5.[07]

We saw an explosion in AI slop reports combined with a lower quality even in the reports that were not obvious slop.
Daniel Stenberg · curl · 2026-01-26

This is the same technology that found the vulnerabilities higher up this page. In practice the maintainers were handed a full-time job reading reports that looked credible but were not.[07]

And in the same project, the same year, the opposite happened. An independent researcher ran several AI tools against curl, went through the results himself, and reported what held up. Around 150 flaws had been fixed by the time he wrote about it. Roughly a fifth of what the AI pointed at was a false alarm. Stenberg himself said he was almost blown away by the quality of some of the findings.[08]

Same technology, same project, same year. Under 5 percent accuracy in one case, around 80 in the other. The difference was the process.

What the pattern says

Go back and look at the list again. Every finding that got published has a proof step. Something crashed. A command ran. An attack actually worked. None of them is an AI saying something looks suspicious.

It is also why the public list is so heavily about crashes and commands running in the wrong place. Those can be proven. Permission failures, hijacked accounts and broken rules about who may see what are what most often hits an ordinary web application, and there is nothing there that crashes. There you need someone who knows what the system was meant to allow.

Attackers read the same reports

In May 2026 Google's threat intelligence group reported the first AI-written attack code they had seen used for real, against a well-known administration tool. That the code was AI-written showed in, among other things, an invented severity rating the AI had made up itself.[09]

Pause on that detail. The tool that built a working attack also invented a factual claim. Same AI, same file, at the same time.

That is the whole argument in one sentence. An AI can produce a real attack and an invented claim without noticing the difference. Someone has to know which is which, and that someone signs the report.

Sources

  1. [01]Cybersecurity updates, summer 2025 (Big Sleep, CVE-2025-6965)Google · 2025-07-15
  2. [02]Google's AI-powered OSS-Fuzz tool finds 26 vulnerabilities in open-source projectsThe Hacker News · 2024-11-20
  3. [03]Bing Images flaws let crafted SVGs run commandsThe Hacker News · 2026-07-24 · secondhand
  4. [04]Claude Mythos PreviewAnthropic · 2026-04-07
  5. [05]AI Cyber Challenge resultsDARPA · 2025-08-08
  6. [06]Project Glasswing, initial updateAnthropic · 2026-05-22
  7. [07]The end of the curl bug-bountyDaniel Stenberg · 2026-01-26
  8. [08]Retrospective on AI source code security scanners run against curlJoshua Rogers · 2025-10-19
  9. [09]Threat actors leveraging AI for vulnerability exploitation and initial accessGoogle Threat Intelligence · 2026-05-11
All articles
Next step

Test it beforesomeone else does.

Free scoping. Fixed price before we start.

[AI] depth and pace[HUMAN] judgement and accountability[EU] residency in Sweden