We matched Mythos on public zero-days with CVEs using widely available & open-source derived models & can run it air-gapped if needed. All this with a small team out of Europe
Berkeley study ranks us #1 globally in 3 of 8 categories
The full evidence: https://t.co/NGVaWxFneq
Today we're launching AISLE Snapshot.
Attackers now have Mythos-class models pointed at your code. Defenders have been fighting that with tools built for a slower threat - and they’re falling behind.
Snapshot puts frontier-class capability on your side. It’s a one-time scan that runs inside your own environment, on‑prem and air‑gap compatible. It finds what’s actually exploitable, shows you the path, then tears itself down. No data leaves. Nothing stays behind.
AISLE ranked #1 in three categories of the UC Berkeley Vulnerability Initiative report.
And we've discovered more than 225 CVEs across open source projects, each independently validated.
This is what defense looks like when both sides have frontier-class AI.
Get your Snapshot here: https://t.co/IEmJTAOpB0
Anthropic chose FreeBSD to showcase their Mythos zero-days. In the latest release, 8 CVEs were announced:
3 found by Anthropic, 3 discovered by AISLE's AI (!)
AISLE is matching Mythos 3-for-3 on zero-days on the very codebase of their choosing at a fraction of the cost
Zero-day discovery with AI is way bigger than a single team and given the magnitude and importance of the problem, only democratization of access to defensive tools will secure our future with strong AIs.
Full write-up on the @Aisle_Inc blog:
https://t.co/HLXZ4ujrO5
AISLE has discovered 20 of 23 OpenSSL zero-days (CVEs) across the last 3 consecutive security releases
Latest release: 5 of 7 are AISLE
1 was co-reported by Anthropic (Mythos?) 63 days after AISLE
OpenSSL encrypts 2/3 of the internet
10 fixes accepted straight into production
New post: We show that small, cheap models can detect the flagship Mythos FreeBSD zero-day (CVE-2026-4747) using a simple harness we call nano-analyzer
Models down to 3.6B active params (including open-weights ones you can run locally) would have detected it 100-1000x cheaper
We pointed the same scanner with just GPT-5.4-NANO in it at the full FreeBSD kernel (>10k files)
Result: <$100 spent + several new kernel bugs + a potential 20+ year-old memory safety issue now under investigation by the security team
Found by the cheapest model available.
New post: We tested the Mythos showcase vulnerabilities with open models.
They recovered similar scoped analysis! 8/8 models found the flagship FreeBSD zero-day, including a 3B model.
Rankings reshuffle completely across tasks => the AI cybersecurity frontier is super jagged!
AWS directly credited our AI system, AISLE, in their security bulletin with 3 new CVEs in AWS-LC = Amazon's backbone cryptographic library. Certificate chain validation bypass, timing side-channel in AES-CCM, signature validation bypass.
4th (!!) high-severity (!!!) vulnerability in Firefox discovered by @Aisle_Inc 's autonomous AI system in the last few months.
CVE-2026-2757: heap overflow in WebRTC H.264 decoding, attacker-controlled out-of-bounds read/write. Patched in Firefox 148.
AISLE is now the #1 source of accepted security findings in OpenClaw, the fastest-growing AI agent framework. Our AI discovered 15 vulnerabilities: 1 Critical (CVSS 9.4), 9 High, 5 Moderate. 21% of all OpenClaw security advisories globally are from us, more than anyone else ⏬
Daniel Stenberg of curl now invokes our Analyzer on his PRs. His reaction to the OpenSSL news:
"I'm a little amazed.. 12(!) of them were reported by people at Aisle... if you are curious what AI can do for Open Source security when used for good"
Blog: https://t.co/IXzW8V0Wdj
New post on what AI cybersecurity research looks like when it actually works! I wrote up what we've learned discovering 12 of 12 new OpenSSL zero-days, 5 CVEs in curl, and additional 100+ validated CVEs across critical open source infrastructure, middleware, and secure apps 🔗⏬
Another critical severity vulnerability we've autonomously surfaced at AISLE @WeAreAisle! 🔥🔥🔥
This one has the perfect 10.0/10.0 CVSS severity score and hid for 13 years in a central piece of the Windows/Linux cross-platform infra
Here are details: https://t.co/bPIB33BmRm
Another CVE detected by Aisle's AI system in the world's critical software infrastructure!
This time in cURL which has over 10B installations across devices & applications.
There aren't many more higher impact projects than this! Super proud of our team at @WeAreAisle 🔥🔥🔥
In 2025, only 4 security vulnerabilities with CVEs were disclosed in OpenSSL = the crypto library securing most of the internet.
AISLE @WeAreAisle's autonomous AI system discovered 3 out of the 4. And proposed the fixes that remediated them.
After a year in stealth, we at AISLE @WeAreAisle built an AI system that autonomously finds & fixes vulnerabilities in critical infrastructure code. We've proven it on the most hardened software out there. Our mission is to secure the software foundation of modern civilization.
⚡ Investment Announcement ⚡ @ondrej_vlcek's New AI Startup AISLE™, co-founded together with top AI scientist @stanislavfortcz and Head of Security @jayabaloo, emerges from Stealth to change the Rules of Cybersecurity.
Rok v tichosti ladil a šteloval startup Aisle, který vyhledává a opravuje zranitelnosti v počítačových systémech. Nyní Ondřej Vlček, někdejší dlouholetý šéf Avastu a jeden z českých mecenášů, poodkryl, jak o své nové byznysové dráze startupisty přemýšlí. https://t.co/bSBJyDo1AV