SecretCon 2026
Finding and Fixing CVEs with AI the Right Way
Rambo Anderson-You
Abstract:
People are using AI to mass-file fake vulnerabilities against open source projects. The curl project shut down its bug bounty because of it. AI slop fabricates vulns, invents non-existent functions, and never verifies. With models like Claude Mythos on the horizon and the hype cycle pulling in beginners, this problem is about to get much worse.
Rambo will walk through how he steered AI agents to find real vulnerabilities in open source tools, with mandatory evidence at every step and a threat model gate that filtered out ~40% of false positives. These tools have few GitHub stars but run as root across thousands of enterprise machines. The vulns are neat bug classes – TOCTOU races, symlink attacks, eval injection, privilege escalation chains. He’ll demo live PoCs, show how he worked with maintainers to write patches and get fixes merged upstream, and cover what it actually takes to make AI produce 2 CVEs and 19 verified vulns instead of wasting some poor maintainer’s weekend proving they’re fake.

Rambo Anderson-You
Gotten by mostly on personality.
Rambo has been doing offensive security for almost a decade. He’s okay at it, and has gotten by mostly on personality. Recently he pointed AI agents at the open source tools nobody audits and accidentally ended up with two CVEs and a talk proposal. He lives in a net-zero house and enjoys walking everywhere.