Every time a new AI model drops, the cybersecurity world goes into a bit of a tailspin. It is genuinely hard to tell what is an actual breakthrough and what is just marketing fluff.
Take the announcement of Mythos and Project Glasswing earlier this year. There were non-stop proclamations that the world was coming to an end. Yet, here we are months after the release, and the last time I checked, society is still functioning. The very fact that you are reading this blog post is proof enough that the internet did not collapse.
But the endless cycle of fear, uncertainty, and doubt gets exhausting. A new model gets teased, the internet panics, and security teams are left trying to figure out what is real.
We think there is a better approach. The only way to fight FUD is to do the actual research, look at the data, and build a thesis based on facts.
That is our mission statement at Vulnerability Research Labs (VRL).
Here is how we plan to do it:
- Do cutting-edge AI research: We want to look past the hype and test what these models can actually achieve in security environments.
- Build in public: We are not going to hide our process behind closed doors. You will see what we are working on, including our successes and the things we screw up.
- Publish the results: Security works best when information is shared, so we plan to put our research out there for everyone to read.
- Offer tools for defenders: We do not just want to write papers. We want to hand defensive teams practical tools they can use to protect their infrastructure.
Partnership with Loginsoft
To do research well, you also need an outside perspective. If we just grade our own homework, we are not really solving the problem. Because of that, we have partnered with Loginsoft. They bring expertise in vulnerability intelligence and CVE enrichment to the table, and they will be independently reviewing and verifying our research results to ensure everything we publish is accurate and reliable. They also provide guidance and recommendations to make our tools better.
Research Roadmap
Right now, our immediate focus is much more practical. We are identifying vulnerabilities that are already out in the wild and building tools to help defenders detect them before they cause damage.
To be completely transparent about our roadmap, we are taking things one step at a time. Down the road, we plan to publish the results of our models doing zero-day research. But that is for later, not today.
We want to be responsible about how we share this data. We will not publish exploit codes, but we are more than happy to invite scrutiny from credentialed folks to review our research and keep us honest.
But as we go forward you will see more bleeding edge research projects launched by VRL.
Wrap Up
We do not need more doomsday predictions. We just need better data and better tools. If you want to see what happens when you build security tools in the open, stick around. We are just getting started.
Before you go:
- Read our press release
- Sign up for Deep Dive into VRL
- Watch our interview on Techstrong TV
- Explore the data
If you want to partner with us, please reach out. We would love to hear from you.