Solutions  ·  2026-08-21

Google Mandiant discloses Agentic Vulnerability Discovery Harness (AVDH) architecture

SolutionsHigh impactGlobal
Google Threat Intelligence Group/Mandiant publicly detailed for the first time its internal multi-agent AVDH pipeline (built on Google ADK), which found 100+ true-positive critical vulnerabilities in stolen corporate source code within two days during an IR case, and has yielded 12 assigned CVEs across 10 months of internal use.
Demonstrates a production-proven, structured multi-agent (Explorer/Discovery/Validation/Synthesis) code-review harness that materially outpaces manual review for vulnerability discovery, and Google is sharing the architecture publicly to help other defenders replicate it — a significant AI-for-cybersecurity capability from a top-tier vendor.
Security teams running incident response, red-team, or source-code security review programs, especially after source-code theft events; also open-source maintainers seeking a replicable multi-agent review pattern.
Google Cloud Blog (Threat Intelligence)SQ Magazine
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →