HomeSecurityOpenAI: Aardvark detects errors in code

OpenAI: Aardvark detects errors in code

OpenAI has unveiled Aardvark , an autonomous agent based on GPT-5 and designed to act like a human researcher security , capable of scanning, understanding, and fixing code with the reasoning skills of a professional vulnerability analyst. It was announced Thursday and is currently available in private beta . Aardvark is being touted as a major leap forward in AI-driven software security

OpenAI Aardvark

Unlike conventional scanners, which mechanically flag suspicious code, Aardvark attempts to analyze how and why code behaves the way it does. “OpenAI Aardvark is different in that it mimics a human security researcher,” said Pareekh Jain, CEO of EIIRTrend. “It uses logic LLM-based behavior of code, reading and analyzing the code as a human security researcher would.”

By integrating itself directly into the development pipeline, Aardvark aims to transform security from a post-development concern to ongoing protection that evolves with the software itself.

See also: Samsung Internet comes to PC with Galaxy AI and sync support

From code semantics to validated fixes

What makes Aardvark unique, according to OpenAI, is its combination of logic, automation, and verification. Rather than simply pointing out potential vulnerabilities, the agent promises multi-layered analysis — starting with mapping the entire repository and building a contextual threat model around it. From there, it continuously monitors new commits, checking to see if each change introduces a risk or violates existing security standards.

Additionally, once it detects a potential issue, Aardvark attempts to validate the exploitability of the finding in a sandbox environment (before flagging it).

OpenAI: Aardvark detects errors in code

This validation step could prove transformative. Traditional static analysis tools often inundate developers with false positives – issues that may seem dangerous but are not actually exploitable. “The biggest advantage is that it will significantly reduce false positives,” Jain noted. “It is useful in open source code and as part of the development pipeline.”

Once a vulnerability is confirmed, Aardvark integrates with Codex to suggest a fix and then reanalyzes the fix to ensure it doesn’t introduce new problems. OpenAI claims that in test testing, the system detected 92% of known and synthetically introduced vulnerabilities in testing repositories – a promising sign that AI may soon take on some of the burden of modern code review.

See also: OpenAI: Updates coming to AI-browser ChatGPT Atlas

OpenAI Aardvark: Securing open source

Aardvark’s role extends beyond enterprise environments. OpenAI has already deployed it to open source repositories, where it claims to have discovered multiple real vulnerabilities (ten of which have received official CVE identifiers). The LLM giant said it plans to provide free scanning for select non-commercial open source projects, under a coordinated disclosure framework that gives maintainers time to address vulnerabilities before public reporting.

OpenAI: Aardvark detects errors in code

This approach aligns with the growing recognition that software security is not just a private sector problem, but a shared responsibility of the ecosystem. “As security becomes increasingly important and complex, these autonomous security agents will be useful for both large and small businesses,” Jain added.

See also: OpenAI: Extra protections for Sora after concerns about Deepfake content

OpenAI’s announcement also reflects a broader industry concept known as “shifting security left,” integrating security checks directly into development, rather than treating them as end-of-cycle testing. With over 40,000 vulnerabilities listed on CVE annually and the global software supply chain under constant attack, integrating AI into developers’ workflows could help balance speed with vigilance.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS