Capital One on Thursday released VulnHunter , an open-source, agentic AI security tool that scans source code for exploitable vulnerabilities, maps out how an attacker would reach them, and proposes targeted fixes — all before a single line ships to production. The tool, built internally and now available on GitHub under an Apache 2.0 license, is one of the most ambitious attempts by a major financial institution to turn offensive AI capabilities into a public defensive resource. At a time when security teams are facing a rising tide of new AI threats, Capital One’s decision to open-source the
Capital One releases VulnHunter, an open-source AI tool that finds software flaws before hackers do
calendar_today
July 17, 2026
person
michael.nunez@venturebeat.com (Michael Nuñez)
domain
venturebeat