The news
The Defense Advanced Research Projects Agency (DARPA) has selected Xint, an AI code security company that grew out of Theori, to research using autonomous AI to find vulnerabilities in military messaging apps used across the Department of War, SecurityWeek reported on September 29.
According to SecurityWeek, the work covers deep security analyses of messaging apps developed both inside and outside the department. Xint will examine source code, including from apps such as Signal and open-source projects, and will also analyze compiled binaries, the finished app files, using a new service launched in September 2026. SecurityWeek said Xint's analysis can extend beyond an app to underlying systems, such as the Linux kernel in Android environments, and related components. The value and length of the work were not disclosed.
Xint was chosen after its showing in DARPA's Artificial Intelligence Cyber Challenge (AIxCC), a two-year, $29.5 million competition in which it was one of three winners, SecurityWeek said. Cybersecurity Dive reported that Theori placed third at the finals, held at the DEF CON hacker conference in Las Vegas on August 8, 2025, behind Team Atlanta and Trail of Bits. Xint says it won a $1.5 million prize.
Andrew Wesie, Xint's chief technology officer and co-founder, told SecurityWeek that messaging apps are a special case because "an attacker needs read-only access to compromise the entire point of the app." He also said third-party software kits and libraries embedded in such apps can create hidden data risks. Xint's system uses frontier large language models to examine the code, triage the vulnerabilities it finds and generate patches, according to SecurityWeek.
The same technology is on sale to companies. Xint offers its analysis as a cloud service, and developers can run code through it before release and scan regularly afterward. Wesie told SecurityWeek the company is currently talking to customers that have written their own code, such as web apps. He said an on-premises version is still a work in progress, mainly because it would not be able to use the latest OpenAI models.
Xint has a track record outside the contest. In a May 4 blog post, the company said that in DARPA's follow-on bounty program it found CVE-2026-31789, a heap buffer overflow in OpenSSL, after scanning more than 600,000 lines of code in under six hours. Cybersecurity Dive has reported that Xint found flaws in Redis, Postgres, MariaDB, Python, Linux and Apple's XNU kernel.
The numbers
- AIxCC competition value
- $29.5 million over two years
- Theori's AIxCC finish
- Third (finals August 8, 2025)
- Xint's AIxCC prize, per Xint
- $1.5 million
- Vulnerabilities found by AIxCC finalists (Cybersecurity Dive)
- 83 in more than 30 projects
- Value of the DARPA messaging work
- Not disclosed
Why CEOs should care
For CISOs, the selection is a signal that automated flaw hunting is being trusted on software where a single weakness can expose sensitive communications. The practical lesson from Wesie's comments is to look past your own code. Ask the vendors of messaging and collaboration tools which third-party software kits their apps embed and how they check them, and consider binary analysis for software you buy but cannot see the source code for.
For technology buyers and CFOs, these tools are moving from contests into production budgets, so pilots need clear scoring. Measure how many findings are real, how many come with usable patches and how much engineering time they save. Also read the data terms closely. Wesie's own explanation for why an on-premises version is not ready, that it could not use the latest OpenAI models, suggests that code sent to such a cloud service may also pass through an outside model provider. Contracts should say where code goes, how long it is kept and whether it can be used for training.
For boards, the question is capacity, not just discovery. An AI tool that finds hundreds of possible issues in hours only helps if teams can fix them. Ask management how fast critical flaws are patched once found and whether faster discovery would simply lengthen the backlog.
The bigger picture
AIxCC's finalists are now turning contest work into businesses. Cybersecurity Dive reported that finalists found 83 vulnerabilities in more than 30 commercial and open-source projects, including Android, Linux, SQLite and Redis, and that Trail of Bits has partnered with the Department of Health and Human Services to hunt flaws in medical devices. DARPA Director Stephen Winchell has said current methods for finding and patching vulnerabilities are slow, expensive and limited by a small workforce, as quoted by Xint.
What’s next
Watch whether DARPA or Xint discloses findings from the messaging work, whether the terms of the selection become public, and when Xint's on-premises version is ready, since many regulated companies will not send source code to a cloud service.
What “Fact-checked” means
Fact-checking means testing a story’s facts against the evidence before it is published. This story went through at least two separate checks before this version was published.
- What we checked
- Its names, figures, dates, job titles, quotes and who said what were checked against the story’s sources, including its main source where it could be opened. The headline was checked for accuracy and overstatement.
- How
- A first check reviewed the whole story. If it passed, a second, skeptical check went back to the sources to look for mistakes in the most important facts. If a check flagged the story, it was edited to fix the problems found, and a separate re-check then reviewed the whole story again.
- Who
- The checks are made by our newsroom, as steps kept separate from the writing, under rules set by our editor, Hussein Mukhtar. A story the checks still flag is held for the editor, who decides whether it is fixed, published or dropped.
- If something is wrong
- “Fact-checked” does not mean error-free. If a material error is found after publication, we correct the story and add a note saying what changed. Report an error





