Quarkslab builds agentic workflow that chains AI-found FreeRDP bugs into RCE

evilsocket · x · 2026-09-30

Quarkslab details a custom agentic harness for vulnerability research, arguing the edge lies in system assembly rather than the model itself. The workflow splits research into five stages: code graph/recon/slicing, analysis, triage with PoC validation, chaining, and exploitation. Agents traverse codebases to connect functions across files and surface candidates, while human researchers validate and steer. Applied to FreeRDP, the workflow surfaced vulnerabilities that could be chained into remote code execution, freeing researchers from days of low-value code reading to focus on the moment of suspicion.

Original post →

More from coding & agent

coding & agent channel →