Getting started with the Mantis harness to find and fix bugs

https://storage.googleapis.com/gweb-cloudblog-publish/images/Mantis.max-2500x2500.jpg

AI models have clearly proven their ability to discover and exploit vulnerabilities without much, if any, human assistance. To help defenders gain the advantage with AI, we built the Mantis harness to automate the discovery, triage, reproduction, and patching of software vulnerabilities.

Available to all as an open-source framework, Mantis is part of Google’s internal approach to find and fix vulnerabilities at machine-speed. It creates a more effective scalable, context-aware repository analysis.

While sloppiness in AI code scanning frequently leads to hallucinated bugs and weak true-positive rates under 7%, we designed Mantis to be effective by combining industry-standard agentic techniques like critic and review agents with sandboxed reproduction of vulnerabilities for grounding.

As we detailed in June, it examines the history of the repository to learn from past security fixes and automatically builds up architectural and threat model documentation, even if these are not provided.

It constructs a hierarchical...

Copyright of this story solely belongs to google.com. To see the full text click HERE

Read more

https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1920-80.jpg

A malware installer posing as a legitimate download service is infecting brands across almost every industry — Microsoft Edge, Razer, Kaspersky and more actively imitated

* Microsoft warns Chinese group Silver Fox spoofed download sites for major tech brands * Victims install backdoored software enabling persistence, disabling Defender/updates, and payload delivery * Targets span healthcare, manufacturing, gaming, government; Microsoft urges tamper protection and behavior‑based detection Cybercriminals are spoofing some of the world’s most popular technology