Google Reveals AVDH: Agentic Framework for Automated Vulnerability Discovery
rseroter · x · 2026-08-19
Google Cloud and Mandiant published a detailed blog post introducing the Agentic Vulnerability Discovery Harness (AVDH), an internal framework designed to automate the discovery of security vulnerabilities in large codebases.
Core Mechanism:
- Structures the analysis process and enforces skeptical validation steps.
- Injects domain-specific human expertise directly into the AI pipeline.
- Uses multi-agent orchestration to assist experts during proactive reviews, penetration tests, and incident response.
Real-World Results:
- AVDH has demonstrated a significant leap in efficacy over the past 10 months.
- In a recent incident response involving stolen corporate repositories, the harness identified over 100 true-positive critical vulnerabilities in just two days.
More from coding & agent
- Obsidian Plugin Hyo Adds Task Mode: Turn Agent Chats Into Manageable Tasks — evielync · 2026-08-19
- LangChain updates onboarding for managed deep agents — hwchase17 · 2026-08-19
- Perplexity's MCP server ships as an Agent Plugin for Codex, Cursor, and VS Code — inductionheads · 2026-08-19
- AI Agent Scaffolding Guide: Context, Tools, and Orchestration Patterns — tom_doerr · 2026-08-19
- Rewriting AI Agent in Rust: Memory-Safe with Secure Plugin System — doodlestein · 2026-08-19
- Transparent Headroom MITM config: no client changes needed — m0ntanoid · 2026-08-19