R0 · Offensive Research at AI Scale

    Zero-day discovery.
    Human-directed.

    A model can suggest where a vulnerability might be. Securin proves it, exploits it, reproduces it, and fixes it, under CNA and GNA authority.

    R1 · Program Intelligence · Advisory Index

    The full record.

    117 advisories published · indexed since 2015

    455
    Discovered
    By Securin researchers
    455
    Disclosed
    To upstream maintainers
    246
    Triaged
    Acknowledged by maintainer
    117
    Resolved
    CVE assigned, patch shipped
    183
    Maintainer review
    No acknowledgement yet
    26
    Rejected
    Out-of-scope or duplicate
    Triage integrity

    AI surfaces candidates at scale. Every candidate is reproduced by a practitioner before it counts as a finding, false positives, theoretical issues, and duplicates are discarded at this gate.

    318
    AI-surfaced candidates
    Pre-triage, machine output
    292
    Manually reviewed
    By Securin practitioners
    90.4%
    True-positive rate
    264 confirmed of 292 reviewed

    Counts a finding as a real vulnerability when a practitioner confirms it, including bugs later found to be already-reported or marked won't-fix. Shipped patches are the more reliable measure of impact.

    Advisory index, every finding, searchable.

    Published entries link to the full advisory via the Securin reference. CVE IDs are assigned and indexed after the coordination window closes.

    SEC ZD · CVEVendor · ProductVulnerabilityCVSSStatusArtifacts
    sec-zd-421
    CVE-2026-14191
    RARLAB
    WinRAR / RAR / UnRAR / UnRAR.dll
    WinRAR/UnRAR RAR5 Recovery Volume (.rev) Out-of-Bounds Heap Write in RecVolumes5::ReadHeader
    Jul 1, 2026
    7.8High
    Fixed-Read
    sec-zd-378
    CVE-2026-44041
    UltraVNC
    UltraVNC
    vncWc2Mb wcslen Before Bounds Check (UltraVNC)
    Jun 3, 2026
    4.3Medium
    Fixed-Read
    sec-zd-377
    CVE-2026-44042
    UltraVNC
    UltraVNC Repeater
    wi_uudecode Boundary Off-by-One — Bounded (UltraVNC Repeater)
    Jun 3, 2026
    3.7Low
    Fixed-Read
    sec-zd-376
    CVE-2026-7828
    UltraVNC
    UltraVNC Repeater
    Integer Overflow in Repeater win_log malloc — Bounded (UltraVNC)
    Jun 3, 2026
    5.3Medium
    Fixed-Read
    sec-zd-375
    CVE-2026-44040
    UltraVNC
    UltraVNC Server
    libc rand() Used for VNC Auth Challenge Generation (UltraVNC)
    Jun 3, 2026
    4.8Medium
    Fixed-Read
    sec-zd-374
    CVE-2026-7829
    UltraVNC
    UltraVNC Repeater
    OOB NUL Write in Repeater Rule Parser (UltraVNC — post-auth)
    Jun 3, 2026
    7.2High
    Fixed-Read
    Showing 1–6 of 117

    Counts as of August 2026 · 90-day coordinated disclosure window

    R2 · The Discovery Process

    From target to verified exploit.

    AI accelerates coverage. Every output is validated by a practitioner before it counts.

    01

    Intelligence-led targeting

    Rules of engagement established upfront. Vulnerability intelligence focuses effort on targets that matter.

    Defined scope, no hallucinated targets
    02

    AI-augmented recon & analysis

    Frontier models map the attack surface at scale. Human expertise directs them to the code paths that matter.

    Scale of AI, precision of expertise
    03

    Human-verified exploit chains

    Every output is triaged against practitioner tradecraft, discarding false positives, theoretical issues, and hallucinated findings. What remains is forged into working exploits and exploit chains.

    No PoC, no finding
    04

    90-day disclosure, full advisory

    Vendor receives the report and exploit under a 90-day embargo. We coordinate the patch and publish the full advisory under CNA and GNA authority.

    Citable, signed, indexed
    CVE & GCVE Numbering Authority
    CISA-sponsored CNA · EU GCVE GNA
    Disclosure Process
    ISO/IEC 29147 & 30111 aligned
    CISA KEV Contributor
    Active exploitation reporting
    Vulnerability Intelligence
    VI Platform · 240k+ CVEs tracked