The announcement comes shortly after IBM joined OpenAI’s Daybreak Cyber Partner Program and launched a new application security service that uses advanced AI models to identify and validate software vulnerabilities.
As part of that effort, IBM launched a service that uses OpenAI models to analyze software code, identify vulnerabilities and determine whether attackers could exploit them. The service operates inside what IBM calls a “security harness,” a controlled environment designed to apply advanced AI capabilities while maintaining enterprise security controls.
Speaking on IBM’s Security Intelligence podcast, Jayesh Kamat, Global Competency Leader for Application Security at IBM said the technology goes beyond traditional code scanning by analyzing how vulnerabilities interact across applications.
“We use them to scan application code for clients and have the models think about what vulnerabilities they could find in that code,” Kamat said, “Not just vulnerabilities, but also chained vulnerabilities across pieces of code.”
Kamat explained the technology can do more than identify vulnerabilities by examining how flaws interact across an application.
“We also have the capability in the harness where the AI models can go and prove that those vulnerabilities can be exploited,” Kamat said on the podcast.