David Brumley on Teaching AI to Find Real Zero Day…
Large language models can write code, pass medical exams, and generate prose, but can they reliably exploit complex software vulnerabilities? David Brumley, a security researcher with two decades of experience training human hackers, argues that teaching AI to discover bugs requires the exact same structured path used for humans: a progressive ladder of exploitation tasks. Speaking on the mechanics of automated security research, Brumley explained why current evaluation setups fail and how real reinforcement learning environments can prove whether a model truly knows how to hack.

Who Is David Brumley
David Brumley is a veteran cybersecurity researcher and academic who has spent twenty years building security education systems. He founded picoCTF, a widely used capture-the-flag learning platform, and spent years recruiting top competitive hackers at Carnegie Mellon University. Brumley also played a central role in designing the scoring mechanics for the DARPA Cyber Grand Challenge, establishing deterministic methods to evaluate automated vulnerability detection and patching systems.