LLM multi-agent workflow finds open-source 0-days across Nextcloud, Grafana and more

cyb3rops · x · 2026-07-29

How an LLM multi-agent workflow helped find open-source 0-days

Hyunseo Shin describes building an LLM-based security workflow after moving from CTF-style practice toward real-world vulnerability research. The article frames AI as becoming a practical hacking aid, citing the rise of CLI tools like Claude Code and Codex, MCP, and AI systems winning bug bounty competitions.

He explains why he pivoted away from memory-corruption and black-box server targets: simple crashes are often not enough for major bounty programs, and automating full exploit chains with AI is still hard. Given his stronger background in web hacking, he focused on targets where an AI-assisted workflow could produce actionable findings.

The post is presented as a write-up of a workflow that led to real bugs, and the accompanying screenshot shows multiple awarded issues across projects such as Nextcloud, Grafana, Protobuf, Airflow, Matomo, OwnCloud, and Discourse.

Original post →

More from Safety

Safety channel →