Discovering Negative-Days with LLM Workflows | Spaceraccoon

Feb 7, 2026 Link: https://spaceraccoon.dev/discovering-negative-days-llm-workflows/ Time-to-Exploit is Negative  By now, you’ve probably read Anthropic’s zero-days blogpost where an “out-of-the-box” Claude Opus 4.6 workflow was used to find 500 vulnerabilities in open-source projects. While I think this is a logical application of LLMs (see my keynote at the recent Association for the Advancement of Artificial Intelligence workshop on Artificial Intelligence … Read more

Negative-Days with Vulnerability Spoiler Alert: Three Months Later (LLM) | Spaceraccoon

May 24, 2026 Link: https://spaceraccoon.dev/negative-days-vulnerability-spoiler-alert/ When I published Discovering Negative-Days with LLM Workflows three months ago, I got a lot of great feedback and interest. Since then, the waves have only gotten stronger in the vulnerability research world with plenty of critical disclosures in major open-source projects. Some of these were caught by my demo of Vulnerability … Read more