logo

Hands Free: What LLM Driven Vulnerability Research Looks Like

ID: 4093dc98-146f-5af5-9817-a944324d8a99

STIX ID: report--4093dc98-146f-5af5-9817-a944324d8a99

Feed Name: Claroty Team82

Threat Score
75/100

Date Published: 2026-06-01

Date Updated: 2026-06-03

Author: Tomer Goldschmidt

...
...

Team82 reports discovery and disclosure of five critical vulnerabilities (three command injections, an out-of-bounds write, and an XSS: CVE-2025-64126 through CVE-2025-64130) in the Zenitel TCIV-3+ video intercom and demonstrates that an Anthropic Claude Opus 4.6 LLM agent, using tools like UPX and Ghidra via Claude Code, can reproduce and accelerate vulnerability analysis end-to-end in under ten minutes, highlighting the potential for LLM-based automated vulnerability research to lower the barrier to finding severe flaws in embedded devices.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.