
LessWrong (Curated & Popular) "AI found 12 of 12 OpenSSL zero-days (while curl cancelled its bug bounty)" by Stanislav Fort
Jan 28, 2026
An AI system found 12 new OpenSSL zero-days, including high- and moderate-severity flaws. The team explains automated vulnerability hunting, historical low-severity CVEs, and accepted AI-suggested patches. They also describe curl canceling its bug bounty after a flood of AI-generated spam and discuss what AI-driven security means for the future.
AI Snips
Chapters
Transcript
Episode notes
AI Finds Holes In Hardened Crypto
- OpenSSL is one of the most audited cryptographic libraries yet still produced 12 new zero-days.
- AISLE's AI discovered all 12, showing AI can find real vulnerabilities at scale.
Early OpenSSL Wins In 2025
- In fall 2025 AISLE's AI found multiple previously unknown OpenSSL issues that led to four CVEs.
- Three of those CVEs were discovered, disclosed, and in some cases fixed by the AI system.
Operate AI As A Full Vulnerability Pipeline
- Use AI to handle the full vulnerability loop: scanning, analysis, triage, exploit construction, and patch generation.
- Keep humans as pilots overseeing targets and reviewing high-profile fixes.
