An AI Agent Found 21 Zero-Days in FFmpeg for $1,000 — One Is a Network-Reachable RCE via a Single 183-Byte Packet
Summary
An autonomous AI agent from depthfirst discovered 21 zero-day vulnerabilities in FFmpeg, including a network-reachable RCE via a single 183-byte packet, for only $1,000 in compute costs; the find highlights the disparity between automated bug finding and patching.
Similar Articles
Twenty One Zero-Days in FFmpeg
depthfirst's autonomous security agent discovered 21 zero-day vulnerabilities in FFmpeg, including several that had remained latent for 15-20 years, with a proof-of-concept demonstrating remote code execution. The findings highlight the capability of AI-driven security agents to uncover critical bugs that evaded previous intensive analyses by Google and Anthropic.
@seclink: 1. Agent security has evolved from an academic topic to an industry reality: FFmpeg zero-day ($1,000 cost) + Chrome 429 patch + OpenAI Lockdown Mode + OWASP framework — the security supply chain is being reshaped by AI Agents. 2.…
AI Agent security has moved from an academic topic to an industry reality, involving FFmpeg zero-day vulnerabilities, Chrome 429 patch, OpenAI Lockdown Mode, and the OWASP framework; meanwhile, Agent payment standards are becoming a battlefield for infrastructure, with Visa stablecoin settlement competing with traditional card networks.
@0x0SojalSec: Kimi K3 can found a 0-day in 27 minutes, One simple prompt then Full RCE & it fully exploited , No human reverse-engine…
Kimi K3, an AI model, is claimed to autonomously find a zero-day vulnerability and achieve full RCE in 27 minutes with a single prompt, no human reverse-engineering.
All the bugs they found
This article details over 20 security vulnerabilities found by AI agents in Epsilon, a small WASM runtime written in Go, including several sandbox escapes that allow malicious modules to break out of isolation.
@P3b7_: The price of a 0-day just hit zero. Literally. It's on GitHub The interesting part is not the chaos. It is the price si…
A Twitter thread discusses how AI has collapsed the cost of finding zero-day vulnerabilities, making high-value exploits available for free on GitHub and fundamentally altering security economics.