• Home
  • Technology
  • Gaming
  • Entertainment
  • World & Business
  • Science
  • Sports
  • AI
HomeTechnologyGamingEntertainmentWorld & BusinessScienceSportsAI
Technology
Report

Armadin's AI agents reportedly found 90-plus zero-days since January

a16z says Armadin's agents probe customer networks from the outside, without access to source code.

a16zA1
2 Sources, 2h ago, first seen 2h ago

TLDR

In an a16z interview, Kevin Mandia says Armadin found more than 90 zero-days at customer sites since January 2026, all in production. He says its AI agents scan networks from the outside without source code, and that the team usually contacts a CISO within 48 hours. a16z says Armadin aims to eventually patch vulnerabilities autonomously.

Combined views

28.6K

2 Sources, first seen 2h ago

106 likes29 comments30 saves10 reposts

Combined views

28.6K

2 Sources, first seen 2h ago

106 likes29 comments30 saves10 reposts

Sentiment

Positive——Negative

Summary

Not enough discussion yet.

No sentiment analysis available yet.

Sentiment

Positive——Negative

Summary

Not enough discussion yet.

No sentiment analysis available yet.

2 Sources

a16z@a16zKevin Mandia on finding 90+ security holes at Fortune 500 companies that nobody knew existed: "When you have an AI-based attack, it'll find logic flaws rather than code flaws in custom applications. It'll exhaust all routes all the time." "Armadin, since January of this year, we have found over 90 zero-days at customer sites, all in production." "We've post-trained all our models with real red teamers, real folks that actually can develop exploits." "When we're scanning networks, we don't have source code to review. We're not finding these zero-days with source code. We're not finding these zero-days because we can log into an app and now we have access, and we can get to other things. We are black box coming from the internet." "Over 90 zero-days in major software companies, and they're thankful. We're coming from the outside, and then we're calling a CISO, usually within 48 hours, 'Hey, we've got remote code execution in your DMZ.' And usually from there we're getting in, and they agree with us." "That's not a pen test. That is like a real adversary coming at you." @ArmadinSecurity @DavidGeorge832h
    • Home
    • Technology
    • Gaming
    • Entertainment
    • World & Business
    • Science
    • Sports
    • AI

    2 Sources

    a16z@a16zKevin Mandia on finding 90+ security holes at Fortune 500 companies that nobody knew existed: "When you have an AI-based attack, it'll find logic flaws rather than code flaws in custom applications. It'll exhaust all routes all the time." "Armadin, since January of this year, we have found over 90 zero-days at customer sites, all in production." "We've post-trained all our models with real red teamers, real folks that actually can develop exploits." "When we're scanning networks, we don't have source code to review. We're not finding these zero-days with source code. We're not finding these zero-days because we can log into an app and now we have access, and we can get to other things. We are black box coming from the internet." "Over 90 zero-days in major software companies, and they're thankful. We're coming from the outside, and then we're calling a CISO, usually within 48 hours, 'Hey, we've got remote code execution in your DMZ.' And usually from there we're getting in, and they agree with us." "That's not a pen test. That is like a real adversary coming at you." @ArmadinSecurity @DavidGeorge832h
    Today's Rank

    —

    Not ranked yet

    Today's Rank

    —

    Not ranked yet