How I hunt for vulnerabilities with AI
Blog post from ClickHouse
Tsvetan Stoychev, an ex-Principal Software Engineer at Akamai Technologies, shares his experience using AI tools like GitHub Copilot, Claude, and ChatGPT for vulnerability research in the ClickHouse codebase, despite not being a seasoned bug bounty hunter. Initially inspired by his manager's encouragement and a colleague's expertise, Stoychev explored AI-assisted methods to uncover vulnerabilities, leading to successful submissions to the ClickHouse bug bounty program. He describes a meticulous process of using AI to generate hypotheses, validate them, and create proofs of concept, emphasizing the importance of manual verification to avoid false positives. Stoychev highlights the evolving landscape of AI tools, the necessity of trusted access, and the benefits of using Python for scripting due to its reliability in AI-generated code. He underscores the importance of persistence and flexibility given the rapid advancements in AI technology, which continually offer new opportunities and challenges in cybersecurity research.
| Trend | Post Mentions | Total Month Mentions | Posts | Companies | MoM |
|---|---|---|---|---|---|
| AI Coding Assistant | 21 | 2,234 | 577 | 171 | +12% |
| Secrets Management | 3 | 2,539 | 400 | 136 | +9% |
| LLM | 2 | 6,292 | 1,205 | 252 | -36% |
| Local AI | 1 | 69 | 40 | 20 | +23% |
Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.