Quarkslab builds agentic workflow that chains AI-found FreeRDP bugs into RCE
evilsocket · x · 2026-09-30
Quarkslab details a custom agentic harness for vulnerability research, arguing the edge lies in system assembly rather than the model itself. The workflow splits research into five stages: code graph/recon/slicing, analysis, triage with PoC validation, chaining, and exploitation. Agents traverse codebases to connect functions across files and surface candidates, while human researchers validate and steer. Applied to FreeRDP, the workflow surfaced vulnerabilities that could be chained into remote code execution, freeing researchers from days of low-value code reading to focus on the moment of suspicion.
More from coding & agent
- One-shots are cool, but months of AI-assisted iteration is what excites this dev — TAbrodi · 2026-09-30
- Luna finished a neural rendering client job using just 6-7% of quota — MickeySteamboat · 2026-09-30
- Adding a Skill from the Skill Hub made the same chart thesis-ready — iamfakhrealam · 2026-09-30
- Closing the laptop mid-task: a hands-on run of KooKo Agent on thesis work — iamfakhrealam · 2026-09-30
- Training an AI agent on its own explanations improves coding—no teacher, no verifier, no RL — CatAstro_Piyush · 2026-09-30
- ehartford submits With, a programming language designed for both humans and coding agents — QuixiAI · 2026-09-30