ISGroup Publishes Large-Scale Study Showing AI Can Identify Real Software Vulnerabilities

1.24 billion tokens. 12,000 model requests. 29 confirmed vulnerabilities in a platform hardened by a decade of independent audits. One of the most extensive public studies to date on LLM-driven vulnerability research.

Italy, 1st Aug 2026 –  What happens when you point a frontier AI model at real-world, battle-tested software and ask it to think like an attacker? ISGroup, the Italian offensive-security firm with two decades of experience in penetration testing and security research, set out to answer that question – and has now published the results in “What Can an Attacker Find With an LLM?”, a large-scale study that places Italy at the forefront of global research on AI-assisted security analysis.

The target was no soft one. ISGroup chose GlobaLeaks, the open-source whistleblowing platform trusted by newsrooms, corporations, and public institutions worldwide to protect sources – software refined over more than a decade and already subjected to multiple independent security audits. If AI could still find real flaws there, it could find them anywhere.

It did. Using frontier models from Anthropic and OpenAI, ISGroup processed approximately 1.24 billion tokens across 12,000 model requests, generating 110 candidate findings. Every single one was manually triaged by ISGroup’s researchers, who treated each model output as a hypothesis to be proven, not a conclusion to be trusted. The final tally: 29 confirmed vulnerabilities, 12 denial-of-service issues, and 42 hardening observations – all responsibly disclosed to the GlobaLeaks team before publication, with the most critical issues already fixed. The net result: stronger protection for whistleblowers and journalists around the world.

Beyond the findings themselves, the study delivers something the international security community has been asking for: hard numbers. ISGroup documents the real costs, the methodology – including a defined threat model, a taxonomy of software weakness classes, and strict evidence requirements – and the honest limitations of the approach: false positives, non-deterministic results, and the non-negotiable need for expert human validation.

The strategic implication is significant. Reviewing an entire codebase – an effort that until recently demanded weeks of specialist work and substantial budgets – can now be done more broadly, more continuously, and at a fraction of the cost.

“Artificial intelligence does not replace specialist expertise, but it increases the amount of code a team can analyse and reduces the cost of doing so,” said Francesco Ongaro, founder of ISGroup. “Experts still have the decisive role of distinguishing a plausible hypothesis from a real vulnerability.”

With this publication, ISGroup adds to a growing body of research that demonstrates how European – and specifically Italian – security expertise is shaping the global conversation on AI and offensive security.

The full report, including methodology, costs, and complete results, is available at: https://www.isgroup.biz/en/cyber-security/llm-based-code-security-review-costs-findings-methodology.html

About ISGroup: ISGroup is an Italian cybersecurity company specialising in offensive security, penetration testing, and security research, serving clients internationally with a research-driven approach to protecting critical software and infrastructure.

Notes for Editors

Francesco Ongaro is available for interviews and technical briefings. A one-page summary of the methodology and aggregated data on model usage are available upon request.

About ISGroup

ISGroup S.r.l. is an Italian cybersecurity company serving clients around the world across a wide range of industries. The company specialises in security research, security assessments, penetration testing, and advanced security analysis of applications and infrastructure. Website: www.isgroup.biz 

Press Contact

Francesco Ongaro
Founder, ISGroup S.r.l.
Email: francesco.ongaro@isgroup.it
Phone: +393518158844 (WhatsApp)

www.isgroup.it  ITALY
www.isgroup.biz  WORLD

Media Contact

Organization: ISGroup S.r.l.

Contact Person: Francesco Ongaro

Website: http://www.isgroup.biz/

Email: Send Email

Country:Italy

Release id:47793

The post ISGroup Publishes Large-Scale Study Showing AI Can Identify Real Software Vulnerabilities appeared first on King Newswire. This content is provided by a third-party source.. King Newswire makes no warranties or representations in connection with it. King Newswire is a press release distribution agency and does not endorse or verify the claims made in this release. If you have any complaints or copyright concerns related to this article, please contact the company listed in the ‘Media Contact’ section

file

Disclaimer: The views, suggestions, and opinions expressed here are the sole responsibility of the experts. No Unique Analyst journalist was involved in the writing and production of this article.