AI Fuzzing Turns One Dump Into Mass PoCs

The break is speed. One researcher is not just publishing exploits, they are using AI-automated fuzzing to turn unknown bugs into public proof-of-concepts fast enough that disclosure can lag behind exploit code. That shrinks the time defenders have to learn about a flaw before working examples are already circulating. The repository, called Exploitarium, grew from about 15 PoCs to more than 30 over a few days and spans open-source projects including the Linux kernel, Libssh2, FFmpeg, Gogs, Gitea, Ghidra, 7-Zip, MyBB, PHP, OpenVPN and VLC. The researcher said they used OpenAI models and tools to automate the fuzzing process and did not notify maintainers first. The forward risk is broader than this one repo. If AI can mass-produce PoCs across unrelated OSS projects, the window between unknown bug and public exploit code can collapse across the open-source supply chain.

Part of the PlainSec briefing for 2026-07-03

Sources