AI vulnerability research agent Q2 RESULTS

Beyond language.
Into the flaw.

Autonomous vulnerability research across Windows, Linux, and complex software systems. Diffract goes beyond large language models—we focus more on the nature of bugs than on AI engineering.

Explore our results
37 RECOGNIZED CVEsQ2 WINDOWS #1Q2 OVERALL #4ANNUAL WINDOWS #9ANNUAL OVERALL #27 37 RECOGNIZED CVEsQ2 WINDOWS #1Q2 OVERALL #4ANNUAL WINDOWS #9ANNUAL OVERALL #27

01 / Q2 RESULTS

Research measured
in real impact.

Recognized by Microsoft Security Response Center, with findings extending into the Linux kernel.

Microsoft-recognized 37

CVEs

MSRC Windows · Q2 #1

Quarterly leaderboard

MSRC overall · Q2 #4

Quarterly leaderboard

MSRC Windows · Annual #9

Yearly leaderboard

MSRC overall · Annual #27

Yearly leaderboard

Beyond one ecosystemLinux

Kernel vulnerabilities discovered

02 / SELECTED RESEARCH

From finding
to evidence.

A growing archive of validated vulnerability research. Detailed material is released when disclosure conditions permit.

DFR / WIN

Windows vulnerability research

Validated findings recognized through Microsoft Security Response Center.

WINDOWS37 CVEs / TOTAL
DFR / LNX

Linux kernel research

Security findings across kernel components and low-level system interfaces.

LINUXKERNEL
RESEARCH ARCHIVE
DFR / ARC

Technical report archive

Root-cause reports, reproducibility material, and selected proof-of-concept code.

REPORTSPOC

37 recognized CVEs—and counting. We’re building an agent that turns AI capability into real security impact.

03 / RESEARCH SERVICES

Research you can
put to work.

Get access to selected findings from our research archive, with the technical depth needed to validate exposure and improve defenses.

REPORT / 01
DOC

Vulnerability reports

Root-cause analysis, affected components, attack surface, impact, and remediation guidance from our past research.

  • Technical analysis
  • Impact assessment
  • Mitigation notes
POC / 02
</>

Proof-of-concept

Private validation material and reproducible test cases for authorized security assessment and defensive research.

  • Reproduction steps
  • PoC code
  • Validation support
ADVISORY / 03
SIG

Research consulting

Direct collaboration on vulnerability triage, patch analysis, attack-surface review, and detection opportunities.

  • Research briefings
  • Patch analysis
  • Custom requests
PRIVATE RESEARCH ACCESS

Looking for a report or PoC?

Tell us what product, CVE, or research area you are investigating.

Discuss your request

04 / THE TEAM

Built by researchers.

THE WORK CONTINUES

We’re pushing Diffract
further.

View the MSRC leaderboard