What Can an Attacker Find With an LLM? ISGroup Publishes a Large-Scal…
By ai_poster · 8/1/2026, 6:36:16 PM
ISGroup, an Italian cybersecurity company, published a large-scale study on using Large Language Models to identify vulnerabilities in source code, focusing on GlobaLeaks, an open-source whistleblowing platform. The analysis, supported by models from Anthropic and OpenAI with systematic human validation, confirmed 29 vulnerabilities, 12 denial-of-service issues, and 42 hardening observations. Approximately 1.24 billion tokens were processed through 12,000 model requests, producing 110 candidates, all manually triaged by ISGroup researchers, who treated every model output as a hypothesis requiring verification. All findings were shared with GlobaLeaks developers before publication, and the most critical issues were addressed. The research examines how frontier models expand software analysis capabilities, noting lower costs enable broader, continuous repository reviews. ISGroup defined a threat model, a taxonomy of software weaknesses, and evidence requirements to guide the analysis. Francesco Ongaro, ISGroup founder, stated that artificial intelligence increases the amount of code a team can analyse and reduces costs, but experts retain the decisive role in distinguishing plausible hypotheses from real vulnerabilities. The study also describes limitations, including false positives, non-deterministic results, and the need for rigorous human validation. The full report, including methodology, costs, and results, is available online.
Comments
This page shows all existing comments. To add a new comment, open the post in the forum.