{
  "schema_version": "1.1",
  "id": "s8:https://www.youtube.com/watch?v=ZFxh7sqbUZo",
  "slug": "teaching-ai-to-find-real-vulnerabilities-david-brumley-bugcrowd-1ok0f7q",
  "url": "https://feed7.dev/p/teaching-ai-to-find-real-vulnerabilities-david-brumley-bugcrowd-1ok0f7q",
  "title": "Teaching AI to Find Real Vulnerabilities — David Brumley, Bugcrowd",
  "why_included": "Cybersecurity agents need deterministic exploit oracles and tasks that reward finding distinct vulnerabilities, not self-reported wins or one crash. A capability ladder makes partial progress measurable.",
  "summary": "Brumley describes reproducible vulnerable containers exposed through MCP, with setup, sandboxed file tools, and deterministic grading. He argues that crash-only checks miss exploit quality and duplicate findings; **50%** of DARPA Cyber Grand Challenge tasks reportedly contained unintended vulnerabilities, while AIxCC produced **18 unintended bugs**.",
  "practical_implication": "For security-agent evals, grade concrete effects rather than model claims, deduplicate proofs by the vulnerabilities they trigger, and measure precision and recall across an audit set. A **16-capability ladder** can show where an agent stalls between triggering a flaw and building an out-of-sandbox exploit.",
  "agent_context": "Brumley describes reproducible vulnerable containers exposed through MCP, with setup, sandboxed file tools, and deterministic grading. He argues that crash-only checks miss exploit quality and duplicate findings; **50%** of DARPA Cyber Grand Challenge tasks reportedly contained unintended vulnerabilities, while AIxCC produced **18 unintended bugs**.\n\nFor security-agent evals, grade concrete effects rather than model claims, deduplicate proofs by the vulnerabilities they trigger, and measure precision and recall across an audit set. A **16-capability ladder** can show where an agent stalls between triggering a flaw and building an out-of-sandbox exploit.\n\nEven deterministic oracles encode a chosen definition of progress, and newly discovered bugs can change the ground truth. Publishing transcripts is also unresolved when a benchmark agent produces weaponized, previously private exploits.",
  "source": {
    "name": "AI Engineer",
    "url": "https://www.youtube.com/watch?v=ZFxh7sqbUZo",
    "published_at": "2026-08-01T00:30:06.000Z"
  },
  "source_class": "video",
  "content_type": "Video",
  "layer": "benchmark",
  "domains": [
    "security"
  ],
  "topics": [
    "agent-evals",
    "benchmark-integrity",
    "agent-reliability"
  ],
  "verification": {
    "status": "source_linked",
    "label": "Source Linked",
    "method": "source_feed",
    "verified_at": null
  },
  "uncertainty": [
    "Even deterministic oracles encode a chosen definition of progress, and newly discovered bugs can change the ground truth. Publishing transcripts is also unresolved when a benchmark agent produces weaponized, previously private exploits."
  ],
  "connected_context": {
    "meaning": "This sharpens general agent-eval guidance for offensive security: success should be graded by reproducible effects, duplicate proofs should collapse to the vulnerability they exercise, and capability stages should separate triggering a flaw from achieving a real exploit. It also exposes a domain-specific limit of fixed ground truth: unintended vulnerabilities can invalidate labels, while transcript publication may disclose weaponized results.",
    "corpus_size": 318,
    "generated_at": "2026-08-01T10:07:54.764Z",
    "connections": [
      {
        "title": "Rethinking Environments for Long-Horizon Work — Rayan Garg, Theta Software",
        "source_name": "AI Engineer",
        "source_url": "https://www.youtube.com/watch?v=2aS7aKoXn64",
        "feed7_url": "https://feed7.dev/p/rethinking-environments-for-long-horizon-work-rayan-garg-theta-software-11r7wbx",
        "reason": "Both reject proxy measures in favor of inspecting consequential state; here that principle becomes grading concrete exploit effects rather than model claims or nominal task duration."
      },
      {
        "title": "Verifiable Environments for AI in Biology — Kenny Workman, LatchBio",
        "source_name": "AI Engineer",
        "source_url": "https://www.youtube.com/watch?v=3ZMUiFaQ3qg",
        "feed7_url": "https://feed7.dev/p/verifiable-environments-for-ai-in-biology-kenny-workman-latchbio-1vs6y66",
        "reason": "The biology candidate’s brittle-grader problem parallels security benchmarks where valid unintended vulnerabilities can defeat a fixed oracle, supporting human review when ground truth changes."
      },
      {
        "title": "Vending-Bench: Long-Horizon Agent Evals — Lukas Petersson, Andon Labs",
        "source_name": "AI Engineer",
        "source_url": "https://www.youtube.com/watch?v=cO8qC6HBuBg",
        "feed7_url": "https://feed7.dev/p/vending-bench-long-horizon-agent-evals-lukas-petersson-andon-labs-0fu78nz",
        "reason": "Vending-Bench’s warning about agents exploiting evaluations is reinforced by security tasks containing unintended attack paths, making real-world checks and trajectory inspection important complements to deterministic containers."
      },
      {
        "title": "Win by Silence: Deletion Non-Monotonicity, Autonomous Exploitation, and Typed-State Gating in LLM Plan Evaluation",
        "source_name": "arXiv",
        "source_url": "https://arxiv.org/abs/2607.12986v1",
        "feed7_url": "https://feed7.dev/p/2607-12986v1-13g75k2",
        "reason": "Typed-state gating and the 16-capability ladder share a structural remedy: withhold credit until required intermediate states are demonstrated, rather than rewarding an incomplete plan or crash-only result."
      }
    ]
  },
  "lifecycle": "Current",
  "published_at": "2026-08-01T00:30:06.000Z",
  "modified_at": "2026-08-01T00:30:06.000Z",
  "supersedes": [],
  "expires_at": null,
  "formats": {
    "html": "https://feed7.dev/p/teaching-ai-to-find-real-vulnerabilities-david-brumley-bugcrowd-1ok0f7q",
    "json": "https://feed7.dev/p/teaching-ai-to-find-real-vulnerabilities-david-brumley-bugcrowd-1ok0f7q.json",
    "markdown": "https://feed7.dev/p/teaching-ai-to-find-real-vulnerabilities-david-brumley-bugcrowd-1ok0f7q.md"
  }
}