What happened
On Oct 7 Microsoft's FORGE Lab published three lessons from scaling agentic vuln research: from May-Sep 2026 it helped discover Windows issues assigned 140 CVEs (52 in Sept alone), submitted 155 validated reports to 23 OSS projects including the Linux kernel, and achieved the first Akrites-sourced AI submission merged into the Linux kernel. The multi-model MDASH scanning harness combines frontier + distilled models with specialized auditors and PoV/PoC generators, and the team reports cutting ~45% duplicate findings via AST-based provers.
Why it matters
This is a maturity marker for AI-for-cybersecurity: the bottleneck is no longer whether agents can find bugs at scale but whether validation, remediation, and release can keep pace — the exact pipeline problem every agentic vuln-scanning product (including AWS Continuum, GitHub Security Lab, Codex Security Cloud) is now hitting. The first AI-found Linux-kernel patch is a concrete milestone.
Applicability
Security leaders and teams building/acquiring agentic vuln-discovery and auto-remediation should read this for pipeline design (dedup, PoV generators, review-capacity economics) rather than raw model capability.