VulnHunter: How Capital One Is Using Agentic AI to Hunt Vulnerabilities Before Attackers Do

Case study on Capital One's VulnHunter: autonomous agentic AI scanning codebases and identifying zero-day logic flaws.

VulnHunter: How Capital One Is Using Agentic AI to Hunt Vulnerabilities Before Attackers Do
Photo by Igor Omilaev / Unsplash
📌
Security Roundup Series: Week of July 20, 2026 • 4 min read deep dive

What VulnHunter Is

VulnHunter is an open-source, agentic AI security tool built by Capital One and released under the Apache 2.0 license. Rather than scanning source code for known-bad patterns the way a traditional static analysis (SAST) tool does, VulnHunter reasons about a codebase the way an attacker would: it looks for exploitable defects, traces plausible attack paths through the code, and proposes targeted remediations for a developer to review.

How It Works

The initial release is implemented as a Claude Code skill and is optimized specifically for Claude Opus 4.8, which means running it requires access to that model plus a working Claude Code environment. Rather than a single-pass scan, VulnHunter uses an agentic workflow: it can explore a codebase iteratively, reason about how different components interact, and validate whether a candidate finding is actually reachable and exploitable before surfacing it, aiming to cut down on the noisy false positives that make traditional SAST output hard to act on.

Why Capital One Open-Sourced It

Capital One has framed the release as a response to attackers increasingly using advanced AI models offensively to find and exploit vulnerabilities faster and at greater scale than manual code review allows. The reasoning is straightforward: if AI is lowering the cost of finding vulnerabilities for attackers, defenders benefit from equally capable, publicly available tooling rather than leaving offense-defense AI capability asymmetric in the attacker's favor.

Getting Started and Considerations

VulnHunter is available now on GitHub under capitalone/vulnhunter. Because it depends on Claude Opus 4.8 and Claude Code specifically, teams evaluating it should budget for the associated model access rather than expecting a drop-in, model-agnostic scanner. As with any AI-assisted security tool, treat its output as a strong starting point for a human reviewer rather than an authoritative finding, and validate proposed remediations in a non-production environment before merging.

This post is part of this week's Security Roundup: SharePoint's Next Zero-Day, Oracle's Record CPU, and the EY Breach (Week of July 20, 2026), at colibrisec.org/security-roundup-sharepoints-next-zero-day-cpu-and-the-ey-breach-week-of-july-20-2026/.


Read more

Brecha de Datos Médicos en Photon Health

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther