ZeroHour
Story · 2 sources · 2 articlesfirst updated ()

OpenAI Builds 'Defense Factory' Where AI Agents Continuously Discover, Validate, and Patch Vulnerabilities

infoAI safety & securityimportance 58
What's new: This is the first merged story, so there is no prior state to compare. The development being reported is OpenAI's unveiling of the Defense Factory: a shift from standalone security tooling to an agent-first, continuous pipeline for vulnerability discovery, validation, triage, and verified remediation, backed by newly published internal sprint metrics (53 issues closed on day one, 90.6% routing…
Merged summary · glm-5.3-flash · rewritten as coverage arrives

OpenAI unveiled a 'Defense Factory', an agent-first security operation that wires AI agents into tools like GitHub, Snyk, Semgrep, Tenable, and ServiceNow to continuously discover, reproduce, patch, and verify vulnerabilities, warning that agentic attackers…

OpenAI described a Defense Factory workflow in which AI agents integrate source control, scanners, issue trackers, and secret stores via APIs, CLIs, and Model Context Protocol (MCP) integrations, with named integrations including GitHub, GitLab, Snyk, Semgrep, Tenable, Jira, Linear, and ServiceNow. The pipeline covers inventory, discovery, validation, triage, and verified remediation, and responds to agentic attackers that can retain knowledge across sessions and chain separate vulnerabilities into multi-stage attack paths faster than human triage can respond — a phenomenon OpenAI calls a shrinking defender's window. One report frames the window as a temporary advantage defenders should exploit using source-code access and frontier models before open-weight models enable autonomous offensive agent fleets. During an internal security sprint involving 250+ people across 100+ service areas, agents closed 53 urgent or high-priority issues on day one, achieved a 90.6% ownership-routing acceptance rate, and deduplication flagged 37% of findings as duplicates. Runtime validation reproduced 19.5% of findings and cut the false-positive rate to 0.81%, while Codex-generated patches had a 0.53% rollback rate (one report says Codex generated all remediation patches). Each agent operates in isolated, reproducible environments with a control plane for policy and credentials and human oversight for major changes; OpenAI recommends organizations start with one workflow plus reproducible environments and auditing.

  • Internal security sprint involved 250+ people across 100+ service areas.
  • Agents closed 53 urgent or high-priority issues on day one of the sprint.
  • Agent-assisted ownership routing achieved 90.6% acceptance.
  • Deduplication flagged 37% of findings as duplicates.
  • Runtime validation reproduced 19.5% of findings and cut the false-positive rate to 0.81%.
  • Codex-generated patches had a 0.53% rollback rate.
  • Agents connect to developer and security tools via APIs, CLIs, and MCP integrations including GitHub, GitLab, Snyk, Semgrep, Tenable, Jira, Linear, and ServiceNow.
  • Agentic attackers can retain knowledge across sessions and chain separate vulnerabilities into multi-stage attack paths, compressing the defender's window.

Coverage timeline

  1. · 6d ago
    GBHackers· 58
    OpenAI Builds ‘Defense Factory’ as AI Agents Gain Ability to Chain Cyber Exploits

    OpenAI unveiled a Defense Factory using AI agents to continuously discover, validate, patch, and verify vulnerabilities, warning the defender's window against agentic attackers is shrinking.

  2. · 6d ago
    Cyber Security News· 55
    OpenAI Builds ‘Defense Factory’ Where AI Agents Continuously Find and Fix Vulnerabilities

    OpenAI unveils a Defense Factory where AI agents continuously discover, validate, and fix vulnerabilities, integrating GitHub, Snyk, Semgrep, Tenable, and ServiceNow.