---
schema: 1
kind: research
title: "GTIG Agentic Vulnerability Discovery Harness (AVDH): Mandiant's multi-agent pipeline found 100+ true-positive critical vulnerabilities in a stolen corporate source-code repository within two days"
headline: "Once source code leaks, the exploit-development clock now runs at machine speed, not at a defender's patch-cycle speed"
summary: >
  Mandiant describes AVDH, an AI-orchestrated, multi-agent source-code vulnerability discovery
  pipeline built on Google's Agent Development Kit. During a real incident-response engagement
  involving stolen corporate repositories, it found over 100 true-positive critical
  vulnerabilities in two days. Over ten months of deployment it has produced 12 assigned CVEs,
  with a further dozen in active disclosure. The defender-relevant inference is about exposure:
  once proprietary source code leaks, an
  adversary with comparable tooling can be assumed to enumerate its exploitable flaws in days
  rather than the weeks or months a patch cycle assumes.
discovered_at: "2026-08-28T06:36:00Z"
updated_at: null
event_date: "2026-08-18"
run_id: 2026-08-28T0409Z-intel
priority: notable
immediate_action: null
tags: [ai-abuse, vulnerabilities]
regions: [global]
sectors: [public-sector]
entities: [tool:avdh-agentic-vulnerability-discovery-harness]
techniques: [T1588.006]
affected_products: []
cves: []
sources:
  - url: "https://cloud.google.com/blog/topics/threat-intelligence/staying-ahead-of-adversarial-ai-through-agentic-source-code-review"
    publisher: "Mandiant / Google Threat Intelligence Group"
    date: "2026-08-18"
    role: primary
closed_sources: []
evidence:
  - quote: "During a recent incident response investigation involving stolen corporate repositories, the harness discovered over 100 true-positive critical vulnerabilities in just two days — achieving results in a fraction of the time required for manual review."
    publisher: "Mandiant / Google Threat Intelligence Group"
  - quote: "Adversarial misuse of AI has increased the risk of data theft and extortion events, because when proprietary source code is exposed, defenders must scramble to identify and patch vulnerabilities while attackers deploy machine-speed AI tools against them."
    publisher: "Mandiant / Google Threat Intelligence Group"
  - quote: "By structuring the analysis process, enforcing skeptical validation steps, and injecting domain-specific human expertise directly into the pipeline, we've achieved a leap in efficacy."
    publisher: "Mandiant / Google Threat Intelligence Group"
verification: single-source
sourcing_note: >
  Vendor's own account of its own defensive tool; the underlying assigned-CVE claim was not
  independently itemised or verified against NVD this run for lack of a named CVE list in the
  source.
confidence: medium
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
classification:
  reliability: B
  credibility: 2
watchlist_hit: false
actions: []
updates:
  - at: "2026-08-28T15:00:00Z"
    run_id: 2026-08-28T1500Z-audit
    type: improvement
    internal: true
    summary: >
      Operator-directed editorial pass (v4.2): removed composition-rationale narration and 
      pipeline-internal jargon from reader-facing text; tightened or cut paragraphs that 
      restated the summary or padded without responder value. No factual claim changed.
    fields: [body]
migrated_from: null
---

Mandiant describes the Agentic Vulnerability Discovery Harness (AVDH), an AI-orchestrated, multi-agent pipeline built on Google's Agent Development Kit that performs threat modelling, entry-point discovery, context enrichment, hypothesis generation and validation in a deterministic, sequential pipeline architecture rather than an unstructured single-prompt scan. During a real incident-response engagement involving stolen corporate repositories, the harness "discovered over 100 true-positive critical vulnerabilities in just two days — achieving results in a fraction of the time required for manual review" ([Mandiant / Google Threat Intelligence Group, 2026-08-18](https://cloud.google.com/blog/topics/threat-intelligence/staying-ahead-of-adversarial-ai-through-agentic-source-code-review)). Over ten months of deployment it has produced 12 assigned CVEs, with a further dozen currently in active disclosure. Mandiant attributes the low false-positive rate to structuring the analysis process, enforcing sceptical multi-agent validation steps, and injecting domain-specific human expertise directly into the pipeline rather than relying on an LLM's unstructured judgement: "by structuring the analysis process, enforcing skeptical validation steps, and injecting domain-specific human expertise directly into the pipeline, we've achieved a leap in efficacy" ([Mandiant / Google Threat Intelligence Group, 2026-08-18](https://cloud.google.com/blog/topics/threat-intelligence/staying-ahead-of-adversarial-ai-through-agentic-source-code-review)).

The defender-relevant inference is squarely about exposure, not about the tool itself: once proprietary source code is exposed — through a breach, a leaked repository, or a supply-chain compromise — an adversary with comparable agentic tooling can be assumed to enumerate its exploitable flaws at machine speed, inside a window measured in days rather than the weeks or months a defender's own patch cycle assumes: "adversarial misuse of AI has increased the risk of data theft and extortion events, because when proprietary source code is exposed, defenders must scramble to identify and patch vulnerabilities while attackers deploy machine-speed AI tools against them" ([Mandiant / Google Threat Intelligence Group, 2026-08-18](https://cloud.google.com/blog/topics/threat-intelligence/staying-ahead-of-adversarial-ai-through-agentic-source-code-review)).

The defender-relevant response is a standing incident-response planning assumption: treat any leaked-source-code incident as an accelerated exploit-development clock, not a days-to-weeks one.
