Frequently asked questions
What we measure, how, and what we will never release.
Our commitment
The exploits in this research are proof-of-concepts, controlled demonstrations that a vulnerability is exploitable, run in an isolated lab. They are not weaponized exploits: not malware, not payloads, not tooling for use against live systems. And we will never publish the exploit code or the PoCs. We release the measurements and findings, not the weapons.
- What is Vulnerability Research Labs?
- Vulnerability Research Labs (VRL) is a research unit of Quantro Security, in partnership with Loginsoft. We measure the impact of artificial intelligence on the exploitation of known software vulnerabilities, and publish the results at vulnerabilityresearchlabs.ai with an open methodology, independent third-party verification, and public data tools.
- What does “AI-exploitable” or “verified exploit” actually mean?
- It means an autonomous agent (Quantro's Exploit Harness) produced a proof-of-concept that a deterministic verifier confirmed actually fires against the vulnerability's target condition, inside a contained lab. It demonstrates a capability: proof that the flaw can be exploited by AI. It is not evidence of a real-world attack, and it is not a model merely claiming success.
- Are these weaponized exploits?
- No. What the harness produces are proof-of-concept (PoC) exploits: controlled demonstrations that a vulnerability is exploitable, run against a purpose-built target in an isolated lab. They are not weaponized exploits. They are not malware, not payloads, and not tooling designed to be used against live systems. The object of study is the economics of exploitation, not attacking anyone.
- Do you publish the exploit code or the PoCs?
- No, and this is a firm commitment. We publish the measurements (cost, time, success rate, tokens, the AI-XI index) and aggregate findings. We do not release the exploit code, the runnable labs, or step-by-step weaponization instructions. The study publishes its measurements, not its weapons.
- Is this zero-day research?
- No. Every vulnerability we analyze is an already-public, disclosed CVE with a public advisory. We are not discovering new vulnerabilities; we are measuring the changing economics of exploiting what is already known.
- How is a result verified?
- A vulnerability is only called AI-exploitable when a deterministic verifier proves it, never on the AI's own assertion. Every verified result clears two controls: a negative control (the patched build must not fire the marker) and a sham control (a benign input must not fire it). Loginsoft independently verifies the outputs.
- What is the AI Exploitability Index (AI-XI)?
- AI-XI scores each vulnerability from 1 (easy) to 5 (hard) by how much work the harness needed to exploit it. It measures real exploitability, which EPSS (probability of in-the-wild exploitation) and CVSS (theoretical severity) do not. You can score any CVE yourself with the ai-xi tool.
- What was studied?
- A dataset of 3,029 disclosed CVEs, each handed to the Exploit Harness. The report and the underlying dataset are released TLP:CLEAR so any finding can be reproduced; explore it via the Data Explorer and CVE Explorer.
- Who builds the technology behind this?
- Vulnerability Research Labs (VRL) is a research unit of Quantro Security, in partnership with Loginsoft. Quantro Security builds the autonomous exploitation system, the Quantro Exploit Harness, and funds the compute. Loginsoft supplies the vulnerability dataset, threat context, and enrichment data the Harness runs on, and independently verifies the results.
- Can I submit a CVE for assessment?
- Yes. Use the ai-xi tool to submit a CVE to the assessment queue, and watch it move through the queue on the Live AI Intel page.
- Isn't publishing this dangerous? Doesn't it help attackers?
- We deliberately withhold anything that would function as an offensive capability: no exploit code, no PoCs, no labs. What we publish is the aggregate economics of exploitation and a defender's response, including the finding that AI remediates about as fast as it exploits. The goal is to correct how defenders prioritize risk, not to arm attackers.
- How can my organization help?
- Several ways: sharing threat intelligence, offering compute to prioritize more CVEs for analysis, and more. See Partner with us.