"If you’re under the impression that these models are “glorified autocomplete” or that progress is slowing down, I need to urge you: stop thinking that." https://t.co/SgtFjZmlkW
We're excited to announce Savant Pathseeker 🟧 💥
For the first time, security teams can run continuous agentic pentesting across every web application and API to get findings with real proof of exploitability.
Bugcrowd is a complete preemptive security platform:
1️⃣ Autonomous testing
2️⃣ Asset discovery
3️⃣ Human-led validation
By combining these three, your team can uncover the full picture of your risk 🔎
https://t.co/EzbIzAEleD
Meet Savant: the AI fabric inside Bugcrowd’s platform 🟧
To the customers who trust us, the hackers who power us, and the partners who help extend our impact, we’re excited to introduce Savant!
Savant brings Bugcrowd’s AI features, autonomous agents, human hacker insights, and platform signals under one umbrella, making it clear where AI is used and how it supports the work happening across our platform. ☂️
Bugcrowd’s preemptive security vision comes to life with Savant, and we’re excited to bring our community along for what’s next. 🚀
Learn more from our CEO, @davegerryjr: https://t.co/kNaXRGvGXa
Security teams already drown in vulnerability data, but they're missing the context that makes the difference between a triaged backlog and an actual decision.
Today, @Bugcrowd announced Savant - the AI fabric of the Bugcrowd Platform - and with it, the ability to deliver actionable results across appsec, bug bounty and vdp, red-teaming or pentest results in a single platform.
You'll see Savant across many of our current products and future releases:
- Savant Vista (formerly Asset View), helps teams understand what’s exposed.
- Savant Triage (formerly AI Triage Assistant), validates and prioritizes findings faster, cutting through noise so teams focus on what’s real.
- Savant Analytics (formerly AI Analytics), surfaces patterns across program data and supports clearer, more confident reporting.
- Savant Match (formerly CrowdMatch), activates the right hackers and connects them to customers for better results over time.
- Savant Forge (formerly Mayhem Code Security), supports autonomous testing for code.
- Savant Probe (formerly Mayhem API Security), supports live API testing.
- Savant Runtime (formerly Mayhem Dynamic SBOM), adds context from running software.
https://t.co/K4tkloUHEz
Well, it’s been an interesting 24 hours to watch this play out and there’s been a lot of conversation about using submission data for training. I want to be very clear on Bugcrowd’s position.
Hackers are and continue to be the heart of @Bugcrowd. We are a part of the community and value the work the researcher community does to help customers identify vulnerabilities.
AI is here to stay and will play a large role in cybersecurity going forward. However, that doesn’t change our commitment to the hacker community.
We’ve been exploring ways to bring hackers along for the journey - not replace them with AI - and have been working in conjunction with members of the community, our own team & our Hacker Advisory Board to figure out the right way to incentivize and monetize AI-driven products for the hackers contributing.
We won’t get everything right, but you have our commitment to be transparent as we strive to get this right and chart a path towards a human+AI future.
European data stays in Europe. But your security program doesn’t have to stay small 🤌
Bugcrowd’s EU Data Residency Option gives European and EU-focused organizations more control over sensitive vulnerability data and PII, while still giving them access to our global Crowd.
Kevin Kersley breaks down what that means for teams under pressure to meet regional requirements and reduce risk faster.
Read the Q&A: https://t.co/K8LtozaTKh
We've heard it from customers across the EU for years: they want access to the @Bugcrowd Platform for the global researcher community, world-class triage capability, & AI-augmented and autonomous testing, but the vulnerability data has to stay in-region.
Previously an EU data residency requirement meant they had to choose other niche local providers which met some, but not all of their needs.
On the heels of our FedRAMP authorization, today, we launched the EU Data Residency Option which runs in @awscloud Frankfurt, generally available July 1.
https://t.co/tC0benfMD5
Most AI security training stops at detection. That’s pattern matching, not skill.
We just launched RL Environments at @Bugcrowd.
Hundreds of thousands of real open-source vulnerabilities. Find, exploit, patch, audit. The full loop.
Frontier labs are already training on them.
https://t.co/zjssyF3Jls
Today, Bugcrowd is launching Reinforcement Learning environments.
Built for AI developers and supported by our acquisition of Mayhem Security, this new offering gives LLM providers and frontier AI research teams instant access to enterprise-grade infrastructure for model training and optimization.
That means teams can spend less time building platform infrastructure and more time advancing model capability.
All environments are derived exclusively from open-source software. No customer data or security researcher data is used at any stage of the training process.
We’re excited to share what we’ve built and help AI teams move faster with infrastructure designed for this work.
Read the full announcement: https://t.co/B7MmgPuIFp
Exciting new research from @thedavidbrumley and Seunghyun Lee: ExploitBench, the first benchmark measuring how far AI models climb the exploitation ladder. Not "did it find a bug," but "could it weaponize one."
On V8, GPT-5.5 bypassed the sandbox ~50% of the time and hit full code execution on two vulnerabilities. Mythos went further than published human experts on several CVEs.
Public frontier models are past crash-finding. They are exploit-development accelerators, and, that should change how you think about patch priority.
Through our acquisition of @MayhemSec, @Bugcrowd builds the RL environments that teach models these skills.
https://t.co/Anqt0Zl07T
Please remain calm, Bugmageddon has entered the chat 📳
AI is making vulnerability discovery faster, cheaper, and more accessible. Great news for defenders. Great news for attackers. A little chaotic for everyone trying to keep remediation queues under control.
📍🐝 At The Hive at @Infosecurity Europe, Bugcrowd CEO @davegerryjr and Chief AI & Science Officer Dr. @thedavidbrumley will discuss what happens when AI starts moving faster than the security model was built to handle.
Is “Bugmageddon” inevitable? Come find out.
Your finance team can relax, it’s free: https://t.co/o6foToGSMu
Fun chatting with @angusloten from @WSJ about the impact of Mythos (& AI more broadly) on the bug bounty space.
tl;dr vuln detection is becoming easier with AI, human researcher's aren't going away, and the hard part now is prioritization and triage.
https://t.co/IkiFeFtoAu
Well well well, look what day it is 😍
Tonight, GeoCyclone is hosting The Modern Hacker in London, where Bugcrowd CEO @davegerryjr will be sharing what we learned from surveying 2,000 hackers and what those insights mean for security teams trying to keep up with AI, bug bounties, and a rapidly shifting threat landscape.
Free to attend for a topic that could not be more relevant right now. ⏰
🎟️ Registration: https://t.co/Xn4KIYS41M
👨🏻🎓 Student registration: https://t.co/l7E275k0lc
The White House dropped its National Cyber Strategy this month, and the industry is still unpacking what it means for security professionals.
✅ Offense is now table stakes, AI skills are non-negotiable, and the compliance-heavy era is getting a rethink.
Bugcrowd CEO @davegerryjr says the traditional model of defense is changing. Red-teaming, AI tooling, and threat hunting aren't nice-to-haves anymore. They're becoming standard practice as organizations shift from reacting to attacks to anticipating them.
If you're wondering how federal policy is shaping careers or security programs, this Dice piece breaks it down clearly. 🤓
Check it out: https://t.co/IjWMvjNWz8
A donut is just a circle with a hole in it. 🍩
Your attack surface is the same, just with higher stakes!
This morning at The Hive, Braden Russell, Dominique DeVaux Jeffords, George Gerchow, Nick Terkay, and Deap Ubhi spent an hour talking about those gaps and how to close them.
Thank you to our speakers for kicking off The Hive the right way, and to everyone who joined us for making it such a great conversation. 🔥
Two more sessions this week if you want in.
🗓️ Today at 3:30pm and tomorrow at 10:30am.
We couldn't save you a donut (sorry), but we can save you a seat, register here: https://t.co/3HjsvxoMpQ