LLM multi-agent workflow finds open-source 0-days across Nextcloud, Grafana and more
cyb3rops · x · 2026-07-29
How an LLM multi-agent workflow helped find open-source 0-days
Hyunseo Shin describes building an LLM-based security workflow after moving from CTF-style practice toward real-world vulnerability research. The article frames AI as becoming a practical hacking aid, citing the rise of CLI tools like Claude Code and Codex, MCP, and AI systems winning bug bounty competitions.
He explains why he pivoted away from memory-corruption and black-box server targets: simple crashes are often not enough for major bounty programs, and automating full exploit chains with AI is still hard. Given his stronger background in web hacking, he focused on targets where an AI-assisted workflow could produce actionable findings.
The post is presented as a write-up of a workflow that led to real bugs, and the accompanying screenshot shows multiple awarded issues across projects such as Nextcloud, Grafana, Protobuf, Airflow, Matomo, OwnCloud, and Discourse.
More from Safety
- NVIDIA and 70+ Companies Sign Open Letter Supporting Open-Weight AI Models — NVIDIAAI · 2026-07-30
- Overly Strict Guardrails: Claude Blocks Enterprise Cyber Defense Investigations — RexDouglass · 2026-07-30
- AI Copyright Moats Fail, Prompting Shift to Government Protection — RexDouglass · 2026-07-30
- Sam Altman Tells Capitol Hill: Other Systems Hacked by OpenAI Are Possible — ns123abc · 2026-07-30
- OpenClaw Exposes Critical RCE Flaw, 50k+ Nodes Compromised — ericelliott_ · 2026-07-30
- xAI Sues Minnesota to Block Anti-Nudification App Law — The Verge AI · 2026-07-30