VentureBeat
Follow
Capital One releases VulnHunter, an open-source AI tool that finds software flaws before hackers do
Capital One has released VulnHunter, an innovative open-source AI security tool designed to scan source code for exploitable vulnerabilities. This tool proactively identifies and maps attack paths before code deployment, offering targeted fixes. VulnHunter operates with an "attacker-first forward analysis," starting from potential entry points to trace exploitability. A key feature is its "falsification engine," which rigorously attempts to disprove potential findings before they reach developers, significantly reducing false positives. This approach contrasts with traditional scanners that often overwhelm teams with alerts. The development and release of VulnHunter are influenced by Capital One's significant 2019 data breach, which prompted a reevaluation of their cybersecurity strategies. Following the breach, the company intensified its commitment to open-source initiatives and advanced AI-driven defenses. VulnHunter is built upon this renewed focus, aiming to leverage collaborative security efforts to address widespread software supply chain risks. The tool's three-stage engine automates vulnerability detection, validation, and remediation, aiming for speed and efficiency. Capital One believes that in the face of AI-enhanced attacks, traditional reactive security measures are becoming increasingly insufficient.