In short
- Google disclosed PageBreak, an inside AI agent from its Product Safety workforce that has discovered greater than 500 bugs.
- Not like typical AI scanners, PageBreak solely studies a bug after confirming it with a working exploit towards a reside atmosphere, giving it a near-zero false-positive price.
- Google plans to pair PageBreak with CodeMender, its automated bug-fixing agent.
Google simply gave certainly one of its AI brokers a brand new job: breaking into Google.
The corporate disclosed on September 24 that its Product Safety workforce constructed an autonomous system referred to as PageBreak, designed to hunt for actual, exploitable vulnerabilities in Google’s personal net purposes, in keeping with a blog post by info safety engineer Michał Bentkowski. The pitch is easy: an AI hacker that does not cry wolf.
“PageBreak is an inside AI agent of Google’s Product Safety workforce developed to check the safety of our first-party net purposes and handle this problem,” Google mentioned. “Beginning as a pilot in November 2025 and transferring to a fully-fledged mission in January 2026, its mission is to autonomously scale vulnerability discovery whereas minimizing handbook toil.”
That issues greater than it sounds. Safety groups in every single place have spent the final couple of years drowning in “AI slop,” Google explains, referring to the flood of low-quality, AI-generated bug studies that look believable however develop into nothing.
“Distinguishing a real, exploitable flaw from a convincing hallucination has turn out to be a serious problem,” Google wrote. Ask any AI mannequin to discover a safety gap, and it’ll often discover one. Whether or not that gap is actual is a special query totally.
PageBreak tries to reply that query earlier than a human ever sees the report. When the agent, constructed on Google’s Gemini fashions, spots a attainable flaw, it palms the speculation to a specialised validator that really tries to use it in a reside, working copy of the applying.
BitcoinBTC · USD
$84,970+5.79%
Sep 20Sep 22Sep 23Sep 25Sep 27
$87.2k$84.9k$82.7k$80.5k
24h ExcessiveExcessive$84,859
24h LowLow$83,835
VolVol$824.4M
Market projectionsOdds by Myriad
PageBreak has already uncovered greater than 500 XSS vulnerabilities throughout Google’s first-party net purposes, the type of flaw that may let an attacker hijack a logged-in session, steal information, or impersonate a person on a website you utilize day-after-day.
Run towards purposes constructed on Google’s newer, “high-assurance” net frameworks, meant to make whole bug courses structurally inconceivable, PageBreak discovered simply two. That hole is Google’s personal proof that constructing safer software program from the bottom up works higher than patching holes after the very fact.
The stakes round AI and safety have been climbing all yr.
In August, greater than 100 organizations, together with Google, Microsoft, and Anthropic, signed an open letter warning that AI-enabled cyberattacks have gotten extra widespread, after AI brokers from OpenAI and Anthropic had been discovered to have breached actual firms throughout testing. Since then, an AI Agent configured by OpenAI hacked the government of Australia and the studies of other attacks haven’t stopped.
PageBreak sits on the opposite facet of that very same coin: as a substitute of an AI inflicting a breach, it is an AI making an attempt to catch the bugs earlier than another person does. It isn’t Google’s first brush with this drawback both; the corporate beforehand needed to patch one of its own AI coding tools after a flaw let attackers execute malicious code by it.
Google says PageBreak leans on benefits most firms haven’t got, together with a single, unified code repository spanning billions of traces and years of inside scanning infrastructure, so a small startup cannot merely copy the method.
The following step is connecting PageBreak to CodeMender, Google’s automated patch-writing agent, so a confirmed vulnerability can arrive with a proposed repair already connected, leaving engineers to overview and approve fairly than begin from scratch.
Each day Debrief Publication
Begin day-after-day with the highest information tales proper now, plus unique options, a podcast, movies and extra.
You might also like
More from Web3
AI Agents Keep Escaping Their Creators’ Control—Here’s What We Know
Briefly Australia revealed an OpenAI agent breached a authorities web site in June, apparently the primary identified case of an …
SEC Staff Says Token Buybacks Don’t Make Crypto a Security—If the Network Works
In short The SEC's Division of Company Finance stated buyback bulletins on purposeful crypto networks do not depend as guarantees …
Bitcoin ETFs Notch Seven-Day Winning Streak as 2026 Flows Turn Green
In short U.S. spot Bitcoin ETFs took in $134.5 million Friday, extending a seven-day influx streak value about $2.98 billion, …





