Search

Edgescan turns AI to the hunt for zero-day vulnerabilities

AI developed for autonomous penetration testing is now surfacing potential zero-day vulnerabilities in real-world software.

DUBLIN, September 9 — Edgescan today announced that AI developed as part of its forthcoming Autonomous Penetration Testing solution, Edgescan Atomic, is being applied by their security research team to find previously unknown vulnerabilities in released, real-world software. The work has already surfaced potential zero-day vulnerabilities, which are now moving through responsible disclosure with the affected vendors.

A zero-day is a flaw in software that the vendor does not yet know about. Because no patch exists, there is nothing for defenders to apply and nothing for scanners to detect. Attackers who find one first hold an advantage that lasts until someone else discovers it.

Finding them has always been slow, manual work. A researcher reads code, tests behavior, and follows hunches across systems that were never designed to be legible. Edgescan’s research applies AI to that discovery process, not to the scanning that follows it. The distinction matters. Vulnerability scanning looks for weaknesses that are already known and catalogued. This research looks for the ones that are not.

AI expands the zero-days discovery process, enabling Edgescan to examine released software at greater scale and surface potential vulnerabilities that may otherwise go undiscovered. Candidate weaknesses are investigated, reproduced and assessed for real-world impact before being confirmed as findings.

“Zero-day research has always been limited by how much code one person can hold in their head at once. AI lifts that ceiling. We can now examine a much larger body of released software and get to the interesting parts faster, which means we surface weaknesses that would have gone unexamined simply because nobody had the hours. The investigation work that follows is unchanged. You still must prove the flaw is real and prove it can be exploited,” said James Mullen, Head of Research Edgescan.


Every confirmed discovery enters responsible disclosure. Vendors are notified privately and given time to investigate and remediate before Edgescan publishes any detail. The sequence is fixed: discover, investigate, validate, disclose, allow remediation, then publish.

The research extends how Edgescan already uses AI across its platform, where models are grounded in the company’s own validated vulnerability data rather than general-purpose training. The same principle applies here. AI is pointed at a specific security problem, its output is checked by people who understand the systems, and the results are held to the standard of proof Edgescan applies to customer findings.

 

“AI fundamentally changes the scale at which we can approach zero-days research. Instead of being constrained by the amount of software a researcher can manually examine, we can apply intelligence across a much broader landscape and identify potential weaknesses that may otherwise remain undiscovered. This is exactly where we believe AI can have a meaningful impact on security. Finding real problems faster and turning that intelligence into better security outcomes,” said Eoin Keary, CEO, Edgescan.


Edgescan plans to publish further technical research once disclosure timelines allow, including detail on confirmed discoveries and any CVEs assigned.

 



About Edgescan

Edgescan is a proactive security platform delivering Hybrid Penetration Testing that combines automation with human validation, headquartered in Dublin, Ireland, with offices in New York. The company pairs continuous automated testing with expert-led penetration testing to deliver validated, false-positive-free vulnerability intelligence across the full attack surface, including web applications, APIs, networks, mobile, and cloud. Edgescan’s data lake of over 20 million validated vulnerabilities powers its AI-driven risk prioritization. Edgescan is a contributing data partner to the Verizon Data Breach Investigations Report (DBIR), a certified PCI-ASV and a barometer for the vulnerability landscape for the past 10 years.

Related Articles

AI developed for autonomous penetration testing is now surfacing potential zero-day vulnerabilities in real-world software. DUBLIN, September 9 — Edgescan today …

September is when this question should come up. Most teams ask it in November, and that’s the problem. By then, …

Application environments move faster than ever. Code ships weekly, infrastructure shifts under you, and new APIs appear between one assessment …

Ready for security that is fast, accurate and quiet?
Experience the hybrid advantage of AI Scale + Human Validation.