Image: microsoft.com · rights & removal
3 lessons from frontier AI vulnerability research
Reporting by Microsoft Security BlogRead the original at microsoft.com
Executive Summary
Facts Only
* FORGE discovered 140 Windows CVEs, including 52 addressed in September 2026.
* FORGE members submitted 155 internally validated reports across 23 open-source projects, including the Linux kernel.
* One Linux report became the first Akrites submission to result in a patch merged into the Linux kernel.
* Automated validation of crash findings averaged $3.61 in model cost and 21.5 minutes per successful case on Linux kernel scale.
* The team used the multi-model agentic scanning harness codenamed MDASH to organize work.
* One internal project reduced about 45% duplicate findings across multiple scans using abstract syntax tree (AST) algorithms.
* Fifty participants produced 39 reports during the OSS Bug Hunt Party Hackathon across six projects.
* The validated validation costs for crash findings averaged $8.56 and 25.4 minutes when using automatic exploit generation (AEG).
Full Take
From the original · Microsoft Security Blog
The mission of Microsoft Security’s Frontier Offensive Research & Generative Exploitation (FORGE) Lab is to advance the frontier of autonomous security engineering. We’re building a team that enables AI-native vulnerability research at Microsoft, pushing the boundaries of finding and fixing zero-day vulnerabilities.Read the full story at microsoft.com
Sentinel — Human
The text reads as expert-level analysis, likely written by or heavily guided by someone intimately familiar with security research and AI systems, focused on synthesizing complex operational lessons.
