OpenAI’s Aardvark is an AI Security Agent Combating Code Vulnerabilities
好的,我现在需要帮用户总结一篇文章的内容,控制在100个字以内。首先,我得仔细阅读文章,抓住主要信息。 文章讲的是OpenAI推出了一个AI工具Aardvark,它能自动检测和修复软件代码中的安全漏洞。这个工具基于GPT-5,目前处于私人测试阶段。它能持续监控代码库,发现漏洞,并生成补丁供开发者审核和实施。这能帮助开发团队更快更全面地解决安全问题,而传统方法是手动审查,效率较低。 接下来,我需要将这些关键点浓缩成一句话。重点包括:OpenAI推出Aardvark、AI工具、自动检测修复漏洞、提升安全性、加快开发速度。 最后,确保语言简洁明了,不超过100个字。 </think> OpenAI推出AI工具Aardvark,可自动检测并修复软件代码中的安全漏洞,提升安全性并加快开发速度。 2025-10-30 20:26:23 Author: securityboulevard.com(查看原文) 阅读量:6 收藏

Avatar photo

OpenAI on Thursday launched Aardvark, an artificial intelligence (AI) agent designed to autonomously detect and help fix security vulnerabilities in software code, offering defenders a potentially valuable tool against malicious hackers.

The GPT-5-powered tool, currently in private beta, represents what OpenAI calls a “defender-first model” that continuously monitors code repositories to identify vulnerabilities as software evolves. By integrating with OpenAI Codex, Aardvark not only flags security issues but generates patches that developers can review and implement with a single click.

Cruise Con 2025

By automating vulnerability discovery and remediation, Aardvark could help development teams address security issues faster and more comprehensively than traditional manual review processes allow.

“By catching vulnerabilities early, validating real-world exploitability, and offering clear fixes, Aardvark can strengthen security without slowing innovation,” OpenAI said in a blog post announcing the new AI agent.

“Software is now the backbone of every industry — which means software vulnerabilities are a systemic risk to businesses, infrastructure, and society. Over 40,000 CVEs were reported in 2024 alone,” OpenAI said. “Our testing shows that around 1.2% of commits introduce bugs — small changes that can have outsized consequences.”

The Microsoft Corp.-backed company has been testing Aardvark internally for several months across its own codebases and with close partners. The agent has also been applied to open-source projects, demonstrating its versatility beyond proprietary software.

Aardvark operates through a multi-stage process that leverages large language model (LLM) reasoning and tool integration. First, it analyzes a repository to understand the codebase’s purpose, objectives, and security implications. The agent then scans for vulnerabilities by examining both historical commits and newly added code.

When Aardvark identifies potential security issues, it annotates the problematic code with explanations that human developers can review. The system goes further by attempting to validate vulnerabilities in a sandboxed environment, actively trying to trigger them to confirm their existence. Results are tagged with metadata that allows teams to filter and prioritize findings.

Beyond detection, Aardvark assists with remediation by generating Codex-powered patches that have been pre-scanned for quality. While primarily focused on security vulnerabilities, the tool can also identify other code issues including logic flaws and incomplete fixes.

Aardvark is available through private beta to select partners invited by OpenAI.

Avatar photo

Jon Swartz

Jon Swartz is senior content writer at Techstrong Group. Most recently, he was MarketWatch’s senior reporter based in San Francisco covering technology and Silicon Valley. Previously, Swartz was USA Today’s San Francisco bureau chief. He has also written for Forbes, The (London) Independent, London Times, San Francisco Chronicle, and New Orleans Times-Picayune. He has won numerous journalism awards and is a two-time finalist for the Loebs, the Pulitzers of business reporting. Additionally, he frequently appears as a panelist on Fox Business and NBC Bay Area’s Press:Here program. He has been nominated four times for the Pulitzer Prize. Swartz is co-author of “Zero Day Threat: The Shocking Truth of How Banks and Credit Bureaus Help Cyber Crooks Steal Your Money and Identity” and sole author of “Young Wealth.”

jon-swartz has 18 posts and counting.See all posts by jon-swartz


文章来源: https://securityboulevard.com/2025/10/openais-aardvark-is-an-ai-security-agent-combating-code-vulnerabilities/
如有侵权请联系:admin#unsafe.sh