6 Sources
[1]
Google AI "Big Sleep" Stops Exploitation of Critical SQLite Vulnerability Before Hackers Act
Google on Tuesday revealed that its large language model (LLM)-assisted vulnerability discovery framework discovered a security flaw in the SQLite open-source database engine before it could have been exploited in the wild. The vulnerability, tracked as CVE-2025-6965 (CVSS score: 7.2), is a memory
[2]
Google's AI agent 'Big Sleep' just stopped a cyberattack before it started
Google's AI agent, dubbed Big Sleep, has achieved a cybersecurity milestone by detecting and blocking an imminent exploit in the wild -- marking the first time an AI has proactively foiled a cyber threat. Developed by Google DeepMind and Project Zero, Big Sleep identified a critical vulnerability
[3]
Google's AI Agent Finds a Critical Security Flaw in SQLite | AIM
Google also stated that this is the first time an AI agent has been used to directly foil efforts to exploit a vulnerability in the wild. Google revealed on July 15 that Big Sleep, its AI agent that finds unknown security vulnerabilities, recently discovered a critical security flaw in SQLite. The
[4]
Google's Big Sleep AI Agent Discovers Major Security Flaw
Google said the vulnerability was known to bad actors The AI agent is also being deployed for open-source projects Big Sleep found the first security flaw in November 2024 Google announced on Tuesday that its artificial intelligence (AI) agent Big Sleep recently made a major cybersecurity
[5]
How AI agent Big Sleep became Google's secret cyber watchdog
Google's AI agent Big Sleep has blocked a cyber exploit before hackers could use it, marking a first for proactive artificial intelligence in digital security. CEO Sundar Pichai confirmed the breakthrough, saying the tool stopped an imminent attack targeting SQLite. Built by DeepMind and Project
[6]
Can Google's 'Big Sleep' AI Agent Be the Future of Cybersecurity Defense?
It stopped a live exploit before it ever reached the surface. This wasn't just a lucky catch. It was a calculated interception by a new kind of digital sentinel. Big Sleep isn't your everyday software patching tool. Developed by in collaboration with Google's elite Project Zero team, this AI
Share
Copy Link
Google's AI agent 'Big Sleep' has made a breakthrough in cybersecurity by detecting and preventing the exploitation of a critical SQLite vulnerability before hackers could act, marking the first instance of an AI agent proactively foiling a cyber threat.
In a significant advancement for artificial intelligence in cybersecurity, Google has announced that its AI agent, named 'Big Sleep', has successfully detected and prevented the exploitation of a critical vulnerability in the SQLite open-source database engine. This marks the first instance where an AI agent has proactively thwarted a cyber threat before it could be exploited in the wild
1
.
Source: Gadgets 360
The vulnerability, tracked as CVE-2025-6965 with a CVSS score of 7.2, is a memory corruption flaw affecting all SQLite versions prior to 3.50.2. Big Sleep, developed through a collaboration between DeepMind and Google Project Zero, identified this critical security issue that was previously known only to threat actors
1
.According to SQLite project maintainers, "An attacker who can inject arbitrary SQL statements into an application might be able to cause an integer overflow resulting in read off the end of an array"
1
.Source: Digital Trends
Kent Walker, President of Global Affairs at Google and Alphabet, emphasized the unprecedented nature of this event: "Through the combination of threat intelligence and Big Sleep, Google was able to actually predict that a vulnerability was imminently going to be used and we were able to cut it off beforehand"
2
.This breakthrough shifts cybersecurity defense from reactive patching to AI-driven prediction and prevention, potentially saving devices and data worldwide. Google CEO Sundar Pichai called it "a first for an AI agent -- definitely not the last"
2
.Since its launch in 2024, Big Sleep has demonstrated its capabilities in discovering real-world security flaws. In October 2024, it identified another vulnerability in SQLite - a stack buffer underflow that could have led to crashes or arbitrary code execution
1
.Google is now deploying Big Sleep to protect popular open-source projects, scaling human expertise to scan vast codebases autonomously
4
.Related Stories

Source: Analytics Insight
Alongside this development, Google has published a white paper outlining its approach to building secure AI agents. The company advocates for a hybrid defense-in-depth strategy that combines traditional, deterministic controls with dynamic, reasoning-based defenses
1
.This approach aims to create robust boundaries around the agent's operational environment, mitigating risks associated with potential harmful outcomes, including those resulting from prompt injection attacks
1
.Google is expanding its AI security initiatives beyond Big Sleep. The company is enhancing its open-source digital forensic platform, Timesketch, with AI capabilities to speed up incident response. Additionally, Google is partnering with DARPA for the AI Cyber Challenge to crowdsource more innovations in this field
2
.As part of its commitment to responsible AI development, Google announced it will donate data from its Secure AI Framework (SAIF) to support the Coalition for Secure AI (CoSAI) initiative, which focuses on ensuring the safe implementation of AI systems
4
.This breakthrough by Big Sleep represents a significant step forward in the use of AI for proactive cybersecurity, potentially reshaping the landscape of digital threat prevention and response.
Summarized by
Navi
[1]
[4]
05 Nov 2024•Technology

05 Aug 2025•Technology

16 Jul 2025•Technology
