Offensive cybersecurity firm Theori said on Tuesday it was selected as a research performer for the U.S. Defense Advanced Research Projects Agency (DARPA) project on “autonomous AI application security” through its AI-based autonomous hacking simulation platform Xint.
The company said Xint will be used in the project to conduct detailed analysis of in-house and open-source messenger applications used across the U.S. Defense Department.
Xint analysed the Android version of the encrypted messenger app Signal during the proposal process and found three uncaught-exception vulnerabilities that force the app to shut down within an hour. The vulnerabilities were reported to the Signal development team and all were fixed through the version 8.11 update.
Theori CEO Se-jun Park (박세준) said organisations targeted by state-backed hackers, such as the military, major financial institutions, national critical infrastructure providers and technology companies, must meet the highest standards for application security, especially strict requirements to maintain communications secrecy. He said encryption functions in messaging apps undergo close scrutiny, but other code, especially parts that interface with networks or operating systems, often do not receive the same level of inspection, making them easier targets for attackers. He said Theori will use Xint to support regular and precise verification of such code using binaries alone, regardless of whether source code is available.