What happened
Google Threat Intelligence Group/Mandiant publicly detailed for the first time its internal multi-agent AVDH pipeline (built on Google ADK), which found 100+ true-positive critical vulnerabilities in stolen corporate source code within two days during an IR case, and has yielded 12 assigned CVEs across 10 months of internal use.
Why it matters
Demonstrates a production-proven, structured multi-agent (Explorer/Discovery/Validation/Synthesis) code-review harness that materially outpaces manual review for vulnerability discovery, and Google is sharing the architecture publicly to help other defenders replicate it — a significant AI-for-cybersecurity capability from a top-tier vendor.
Applicability
Security teams running incident response, red-team, or source-code security review programs, especially after source-code theft events; also open-source maintainers seeking a replicable multi-agent review pattern.