The existing open models are good enough as it is at vulnerability discovery with a proper harness. Attackers have done a pretty good job with existing tools as well to actually exploit systems and to orchestrate campaigns. The problem for defence is that teams aren't even fixing what's already known, so if you have X vulnerabilities you don't fix or 2X doesn't really matter.
Iโve mentioned this before: this is one of the oncoming trains for corp-security. Weโve long failed at least-privilege, but werenโt often punished for it.
Helen in HR (or Bob in accounts) didnโt know what to do with the extra perms they didnโt know they had.
Their agents will.
@wallyrashid Finding it in publications intended for fringe religious groups doesn't say a thing about the vast majority of the public.
As an example here are excerpts from the Beni Goren math books which are probably the most used ones.