OpenAI Builds 'Defense Factory' Where AI Agents Continuously Discover, Validate, and Patch Vulnerabilities
OpenAI unveiled a 'Defense Factory', an agent-first security operation that wires AI agents into tools like GitHub, Snyk, Semgrep, Tenable, and ServiceNow to continuously discover, reproduce, patch, and verify vulnerabilities, warning that agentic attackers…
OpenAI described a Defense Factory workflow in which AI agents integrate source control, scanners, issue trackers, and secret stores via APIs, CLIs, and Model Context Protocol (MCP) integrations, with named integrations including GitHub, GitLab, Snyk, Semgrep, Tenable, Jira, Linear, and ServiceNow. The pipeline covers inventory, discovery, validation, triage, and verified remediation, and responds to agentic attackers that can retain knowledge across sessions and chain separate vulnerabilities into multi-stage attack paths faster than human triage can respond — a phenomenon OpenAI calls a shrinking defender's window. One report frames the window as a temporary advantage defenders should exploit using source-code access and frontier models before open-weight models enable autonomous offensive agent fleets. During an internal security sprint involving 250+ people across 100+ service areas, agents closed 53 urgent or high-priority issues on day one, achieved a 90.6% ownership-routing acceptance rate, and deduplication flagged 37% of findings as duplicates. Runtime validation reproduced 19.5% of findings and cut the false-positive rate to 0.81%, while Codex-generated patches had a 0.53% rollback rate (one report says Codex generated all remediation patches). Each agent operates in isolated, reproducible environments with a control plane for policy and credentials and human oversight for major changes; OpenAI recommends organizations start with one workflow plus reproducible environments and auditing.
- Internal security sprint involved 250+ people across 100+ service areas.
- Agents closed 53 urgent or high-priority issues on day one of the sprint.
- Agent-assisted ownership routing achieved 90.6% acceptance.
- Deduplication flagged 37% of findings as duplicates.
- Runtime validation reproduced 19.5% of findings and cut the false-positive rate to 0.81%.
- Codex-generated patches had a 0.53% rollback rate.
- Agents connect to developer and security tools via APIs, CLIs, and MCP integrations including GitHub, GitLab, Snyk, Semgrep, Tenable, Jira, Linear, and ServiceNow.
- Agentic attackers can retain knowledge across sessions and chain separate vulnerabilities into multi-stage attack paths, compressing the defender's window.
Coverage timelineoldest first · each row is one article
- · 6d agoOpenAI Builds ‘Defense Factory’ as AI Agents Gain Ability to Chain Cyber Exploits
GBHackers· 58
OpenAI unveiled a Defense Factory using AI agents to continuously discover, validate, patch, and verify vulnerabilities, warning the defender's window against agentic attackers is shrinking.
- · 6d agoOpenAI Builds ‘Defense Factory’ Where AI Agents Continuously Find and Fix Vulnerabilities
Cyber Security News· 55
OpenAI unveils a Defense Factory where AI agents continuously discover, validate, and fix vulnerabilities, integrating GitHub, Snyk, Semgrep, Tenable, and ServiceNow.