logo


You're contacting media contact of this press release

Title: ISGroup Publishes Large-Scale Study Showing AI Can Identify Real Software Vulnerabilities

Italy, 1st Aug 2026 -  What happens when you point a frontier AI model at real-world, battle-tested software and ask it to think like an attacker? ISGroup, the Italian offensive-security firm with two decades of experience in penetration testing and security research, set out to answer that question - and has now published the results in "What Can an Attacker Find With an LLM?", a large-scale study that places Italy at the forefront of global research on AI-assisted security analysis.The target was no soft one. ISGroup chose GlobaLeaks, the open-source whistleblowing platform trusted by newsrooms, corporations, and public institutions worldwide to protect sources - software refined over more than a decade and already subjected to multiple independent security audits. If AI could still find real flaws there, it could find them anywhere.It did. Using frontier models from Anthropic and OpenAI, ISGroup processed approximately 1.24 billion tokens across 12,000 model requests, generating 110 candidate findings. Every single one was manually triaged by ISGroup's researchers, who treated each model output as a hypothesis to be proven, not a conclusion to be trusted. The final tally: 29 confirmed vulnerabilities, 12 denial-of-service issues, and 42 hardening observations - all responsibly disclosed to the GlobaLeaks team before publication, with the most critical issues already fixed. The net result: stronger protection for whistleblowers and journalists around the world.Beyond the findings themselves, the study delivers something the international security community has been asking for: hard numbers. ISGroup documents the real costs, the methodology - including a defined threat model, a taxonomy of software weakness classes, and strict evidence requirements - and the...


This press release is issued by King Newswire

Email Information