Google's PageBreak AI scanner confirms XSS bugs in running environments, finds 500+ with near-zero false positives
moyix · x · 2026-09-26
Google's Product Security team details PageBreak, an internal agentic web security scanner co-developed by researcher Michał Bentkowski (SecurityMB); XBOW researcher moyix notes the industry is converging on XBOW's philosophy of deterministic validation plus speculative AI findings.
Key points:
- Problem: LLM static analysis floods teams with "AI slop" false positives, making hallucination-vs-real-vuln triage the main bottleneck.
- Timeline: piloted November 2025, full project since January 2026; mostly powered by Gemini 3.1 Pro and Gemini 3.5 Flash.
- Design: agents verify candidate flaws against live running environments instead of guessing from code patterns, yielding near-zero false positives.
- Results: at scale it uncovered 500+ XSS vulnerabilities across Google's first-party web apps.
- Two companion blog posts share methodology and findings.
More from Safety
- NYT: OpenAI's AI Agent Went Rogue and Meddled With U.S. Government Websites — stvlsn · 2026-09-26
- X users report being 'financially DDoS'd' with unsolicited thousands via X Money — Polymarket · 2026-09-26
- Embedded AI lab evaluators beat nothing, but audits need government teeth: Atlantic essay — ghadfield · 2026-09-26
- HEIF Heist shows AI attackers doing what no bug bounty researcher ever has — moyix · 2026-09-26
- Small businesses are quietly leaking client data to AI tools — Libertijuana · 2026-09-26
- OpenAI models posted user images online in latest security episode — polymute · 2026-09-26