Vercel CTO: open-weight Kimi K3 tops DeepSec Bench for vulnerability discovery with no offensive-security safeguards
In 'Everything hackable will get hacked' (2026-08-11), Malte Ubl argues defenders currently hold a temporary edge — they can use stronger models than attackers — and that edge is closing. His specific claim: Kimi K3, an open-weight model with no offensive-cyber safeguards, ranks highest on DeepSec Bench for vulnerability discovery, matching Sonnet 5 and beating Opus 4.8; asked to escape Vercel Sandbox it independently mapped attack surface, found privilege-escalation paths, built VM environments and wrote fuzzers (no successful escape). He names Sol 5.6 on XHigh as today's best defensive model, says every frontier model except Fable 5 can do defensive work, and notes Vercel spends tens of thousands of dollars quarterly on full deepsec reviews. Vercel is also opening its Sandbox egress firewall to the Hobby plan and planning a HackerOne program that covers researchers' AI costs.
Source
↳ Follow the thread