25
5 Comments

We built Donely’s security agent & it disclosed it's first CRITICAL vulnerability itself.

We built Donely’s security agent and submitted our first finding on intigriti

That first vulnerability was accepted as CRITICAL.

CVSS: 9.1

100% agentic.

posted toAvatar for product Donely
Donely
  1. 1

    An autonomous agent finding a CVSS 9.1 critical vulnerability on Intigriti is absolutely insane! The fact that it's 100% agentic makes it even more impressive. Congrats on getting the finding accepted.

    Out of curiosity, how does the agent handle authorization scopes so it doesn't accidentally probe unauthorized assets during testing? Keep up the amazing work!

  2. 1

    An accepted CVSS 9.1 on Intigriti is worth more than any landing page claim, so make that finding the entire sales pitch. I run a security and compliance company for SMBs, and buyers there don't purchase "agentic", they purchase proof their auditor and insurer will accept. How do you handle scope and authorization so the agent only probes systems you're cleared to test?

  3. 1

    That’s impressive.

    An agent autonomously finding and submitting a CVSS 9.1 critical vuln is a strong signal for where security is heading.

    Curious how you validate findings and avoid false positives

  4. 1

    ok how does it work

  5. 1

    yeah what was that