Google's Mandiant Launches AI-Powered Tool to Uncover Code Vulnerabilities Swiftly
August 19, 2026
Google’s Mandiant unveiled the Agentic Vulnerability Discovery Harness (AVDH), an AI-driven pipeline of specialized agents that hunt for vulnerabilities in source code, and in a live investigation of stolen corporate repositories it found more than 100 verified, high-severity flaws in two days.
AVDH acts as a force multiplier, automating routine vulnerability discovery so human defenders can focus on complex exploit chains, business-logic flaws, and adversarial activity that require judgment.
Google Cloud described AVDH as a framework that blends multiple AI agents with human review to identify exploitable flaws across large codebases.
Policy context: the DMCA security-research exemption renewal window closes in late August, with comments due in late September, preserving anti-circumvention protections for 2027–2030 and potentially requiring new petitions for changes.
Chrome updates: version 152.0.7977.64 is available for Linux, with Windows and macOS builds 152.0.7977.64/.65; users can update via the browser settings or await broader rollout.
Author background notes accompany the piece, including security expertise and a lighthearted personal aside.
NIST SP 1353 draft outlines structured prompts for governance review, current-state and target-state CSF artifacts, with comments due in mid-October and a focus on mapping policies to remediation evidence.
The report lists high-severity fixes across ANGLE, WebGL, V8, WebRTC, Extensions, Autofill, GPU, Bluetooth, Sandbox, and Passwords, among others, including several buffer and use-after-free issues.
AVDH is designed as a sequential pipeline starting with threat modeling, followed by file-wide analysis to identify entry points, then deeper control-flow and data-flow analysis.
The article cites researchers to contextualize the vulnerabilities and assesses the security posture surrounding the Chrome update.
Two disclosed flaws can be triggered by visiting a malicious site, with sandboxing limiting impact but not guaranteeing safety.
Google notes no active exploitation has been disclosed, and detailed bug information is temporarily restricted until most users update.
Summary based on 7 sources
Get a daily email with more Tech stories
Sources

Cyber Security News • Aug 19, 2026
Google Agentic AI Finds Over 100 Critical Security Flaws in Just Two Days
SecurityBrief Australia • Aug 19, 2026
Google Cloud unveils AI harness that finds flaws fast
Help Net Security • Aug 19, 2026
Google’s AI security agents found 100+ critical software vulnerabilities in just two days