Capital One Open Sources AI-Powered ‘VulnHunter’ Security Tool

  Rassegna Stampa, Security
image_pdfimage_print

Financial services giant Capital One has released an internally developed AI-powered security tool to the public as open source.

Dubbed “VulnHunter”, the tool was designed to find and fix software vulnerabilities at the code level, but Capital One says it is not a traditional, passive vulnerability scanner.

“We designed VulnHunter with a developer-first mindset to solve a massive industry pain point: overwhelming false positives that create friction and slow down daily workflows,” Chris Nims, EVP & Chief Information Security Officer (CISO) at Capital One, explained in a LinkedIn post.

“It represents a shift in defensive tooling with an agentic reasoning workflow to identify potentially exploitable defects, map prospective attack paths, and propose highly targeted code remediations,” the company says.

Available on GitHub, along with a quickstart guide, architecture documentation, and example workflows showing how the tool traces code paths and generates remediations, users currently need access to Claude Opus 4.8 and access to a working Claude Code environment.

“Modern software supply chains are deeply interconnected. A single vulnerability in a widely-used open-source component can ripple across thousands of enterprises simultaneously. We’re open-sourcing VulnHunter because no single organization can solve this challenge alone,” Capital One said. “The defensive tools to address this reality need to be just as widely distributed, tested, and improved as the codebases they protect.”

Advertisement. Scroll to continue reading.

Capital One claimed that, when using VulnHunter internally, it was able to quickly and efficiently identify and remediate vulnerabilities across thousands of repositories, spanning tens of business areas.

https://www.securityweek.com/capital-one-open-sources-ai-powered-vulnhunter-security-tool/