Findings Management to Combat Report Overload
Back when uncovering 0days moved at human speed, handling a true positive was infrequent enough that human processes could manage the triage. But AI has changed the speed and scale of bug discovery.
In the 5-year period from 2017-2021, CVEs grew at a compound annual rate of 4%. Over the next 5-year period since the public launch of ChatGPT, compound annual growth in CVEs quadrupled to 20%! From last year to this year alone CVEs are projected to increase by 34%.
Even these numbers belie just how fast true reports are coming in. This year Chrome CVE issuance has increased 563% year over year through May.
We have seen this dynamic play out in the real world. For example, one of our customers shared that they get vulnerability reports from Xint, their bug bounty program, and from early access to frontier cyber models. They didn’t need more reports; they needed a tool to get them above water.
Managing reports from different sources
With Xint, in addition to finding the bugs that hackers target, organizations are also getting a centralized findings management platform that reduces the noise.
This is because Xint provides three key functions that a simple bug-finding tool can’t match:
Deduplication: Often findings from different sources are the same underlying bug described differently depending on the source. With Xint you can collapse/deduplicate separate reports into a single, unique finding while maintaining the metadata (if, for example, they need to check if a bug bounty report came in before or after it had already been found through other methods).
Validation: Findings management isn’t merely a tack-on to bug discovery - the majority of Xint’s compute is spent on validation and findings management, not discovery. Xint’s ingestion delivers substantial discrimination — validating real findings, rejecting most of a noisy stream — by reasoning about reachability and impact. Xint’s triage can thus validate the very findings its own discovery misses, a direct signal of its value as a management layer over multiple discovery sources.
Validating the patch: Once a patch has been installed, Xint retests the application, checks the diff, and ensures the vulnerability has been addressed without adding new issues. This is then included in the report which is critical for compliance and audit checks.
For example, one of our researchers was analyzing the bug types that AI code is prone to generating looking across 28 applications. After the initial scan he had 8.8k raw detections. After de-duplicating, there were 513 distinct findings and after verification that dropped down to 434 verified findings that were fully categorized by type, severity, and included full trigger pathing and suggested remediations. This translates to reducing the number of findings security engineers need to focus on by 96% compared to just the raw detections.
Having a platform to coordinate triaging massive amounts of reports from various sources and being able to connect that to PRs that remediate the findings is what a mature pentesting platform needs to deliver in this era where AI has made it fast to find bugs.