11 Sources
[1]
OpenAI unveils 'Aardvark,' a GPT-5-powered agent for autonomous cybersecurity research
Also: 96% of IT pros say AI agents are a security risk, but they're deploying them anyway Aardvark, OpenAI's new agentic security researcher powered by GPT-5 and released Thursday, can assist security teams by identifying and helping patch vulnerabilities. The agent is meant to tackle existing
[2]
OpenAI unleashes Aardvark security agent in private beta
After helping expand the modern software attack surface with the rise of AI services prone to data poisoning and prompt injection, OpenAI has thrown a bone to cyber defenders. The maker of ChatGPT on Thursday announced that it is privately testing Aardvark, an agentic security system based on
[3]
OpenAI Unveils Aardvark: GPT-5 Agent That Finds and Fixes Code Flaws Automatically
OpenAI has announced the launch of an "agentic security researcher" that's powered by its GPT-5 large language model (LLM) and is programmed to emulate a human expert capable of scanning, understanding, and patching code. Called Aardvark, the artificial intelligence (AI) company said the
[4]
OpenAI unveils Aardvark AI to secure software against cyberattacks
Aardvark continuously monitors source code repositories, analyzing commits, scanning for vulnerabilities, and prioritizing which ones matter most. It then tests potential flaws in a secure, sandboxed environment to confirm if they can actually be exploited. Once verified, Aardvark automatically
[5]
OpenAI wants your next security researcher to be a bot - new Aardvark tool finds and fixes software flaws automatically
In benchmark tests, Aardvark achieved a 92% success rate on known vulnerable repositories OpenAI wants your next security researcher to be a bot - and has launched Aardvark, its very own agentic security researcher, powered by ChatGPT. Now in private beta, the company describes Aardvark as a
[6]
Meet Aardvark, OpenAI's first-party AI security agent
OpenAI has introduced Aardvark, a GPT-5-powered autonomous security researcher agent now available in private beta. Designed to emulate how human experts identify and resolve software vulnerabilities, Aardvark offers a multi-stage, LLM-driven approach for continuous, 24/7/365 code analysis,
[7]
OpenAI's new agent hunts software bugs like a human
Why it matters: Tools like this could shift the cybersecurity balance toward defenders in their quest to stop malicious hackers. The big picture: Software flaws are an unavoidable part of coding, and they provide prime entry points for cyberattacks. * Source code is an especially high-value
[8]
OpenAI Launches Aardvark, an AI Agent for Automated Security Research | AIM
The agent continuously monitors code repositories to find and validate vulnerabilities, assess their exploitability, and propose targeted patches. OpenAI has introduced Aardvark, an autonomous AI agent designed to identify and fix security vulnerabilities in software codebases. The system, powered
[9]
OpenAI unveils Aardvark, an autonomous GPT-5 agent built to hunt software vulnerabilities - SiliconANGLE
OpenAI unveils Aardvark, an autonomous GPT-5 agent built to hunt software vulnerabilities OpenAI Group PBC today unveiled Aardvark, a new GPT-5-powered autonomous artificial intelligence agent designed to identify, verify and help fix software vulnerabilities in real time. Pitched by OpenAI as
[10]
OpenAI's New AI Agent Can Discover and Fix Software Vulnerabilities
Aardvark has fixed several vulnerability in OpenAI systems OpenAI, on Thursday, introduced a new artificial intelligence (AI) agent that can perform as a software security researcher. Dubbed Aardvark (an African mammal known for its digging ability), the AI agent can analyse, discover, and fix
[11]
What is Aardvark? OpenAI's AI cybersecurity agent explained
New AI agent detects threats in software before hackers strike In a digital era where software vulnerabilities can topple companies and compromise entire infrastructures overnight, OpenAI's latest experiment takes aim at one of technology's oldest weaknesses: human fallibility. The company's new
Share
Copy Link
OpenAI introduces Aardvark, an autonomous AI agent powered by GPT-5 that continuously scans code repositories to identify, validate, and help fix security vulnerabilities. The tool is currently in private beta and has achieved 92% success rate in benchmark testing.

OpenAI has unveiled Aardvark, an autonomous AI security agent powered by GPT-5 that promises to revolutionize how organizations approach cybersecurity vulnerability management. The tool, currently available in private beta to select partners, represents what the company calls "a breakthrough in AI and security research"
1
.Aardvark addresses a critical challenge in software security: the discovery of tens of thousands of new vulnerabilities across enterprise and open-source codebases every year. Unlike traditional security tools that rely on program analysis techniques like fuzzing or software composition analysis, Aardvark uses LLM-powered reasoning and tool-use to understand code behavior and identify vulnerabilities
2
.The AI agent operates through a systematic approach that mirrors human security research methodology. First, Aardvark examines repositories to understand the codebase's purpose and security implications, including objectives and design. It then scans for vulnerabilities by examining past actions and new code commits, explaining discovered issues by annotating the code for human review
1
.A key differentiator is Aardvark's validation process. The agent attempts to prove vulnerability existence by testing exploits in sandboxed environments, confirming real-world exploitability before flagging issues. Results are labeled with metadata for filtering and deeper analysis
3
.Finally, Aardvark leverages OpenAI's Codex coding assistant to generate patches for discovered vulnerabilities, providing users with ready-to-review fixes that can be implemented after human approval
4
.In benchmark testing on "golden" repositories containing well-documented vulnerabilities, Aardvark achieved a 92% success rate in identifying known and synthetically introduced flaws
5
. The tool has been running across OpenAI's internal codebases and those of external alpha partners for several months, surfacing "meaningful vulnerabilities" that contributed to OpenAI's defensive posture2
.During its testing phase, Aardvark has already discovered at least ten vulnerabilities worthy of Common Vulnerabilities and Exposures (CVE) identifiers in open-source projects
3
. This performance positions it competitively alongside other AI-powered security tools, though it falls short of Google's CodeMender, which claims 72 security fixes.Related Stories
Aardvark enters a growing field of AI-powered security tools. Google recently announced CodeMender for automated vulnerability detection and patching, while the tech giant's OSS-Fuzz project identified 26 flaws a year ago
2
. The emergence of these tools reflects the industry's recognition that traditional security approaches struggle to keep pace with modern software development cycles.Matt Knight, VP at OpenAI, noted that Aardvark began as an internal tool after developers found value in how clearly it explained issues and guided them to fixes
1
. This organic development suggests genuine utility beyond marketing positioning.OpenAI plans to use participant feedback during the private beta to refine the entire experience, working with teams to improve detection accuracy and enhance validation workflows
1
.Summarized by
Navi
[2]
[4]
06 Mar 2026•Technology

14 Aug 2026•Technology

06 Oct 2025•Technology

1
Policy and Regulation

2
Technology

3
Technology
