Skip to main content

TrendAI Launches AI Vulnerability Scanner Backed by ZDI Bug Bounty Research

Image
TrendAI Launches AI Vulnerability Scanner Backed by ZDI Bug Bounty Research

Dallas – – September 29, 2026 -- TrendAI, the enterprise AI security unit of Trend Micro (TYO: 4704; TSE: 4704), has entered private preview with TrendAI Vision One Autonomous Vulnerability Discovery, a service that pairs an agentic AI engine with validation from the Zero Day Initiative (ZDI), described as the world's largest vendor-agnostic bug bounty program.

Engine outperforms rivals on CyberGym leaderboard

The service runs on an agentic system code-named AESIR, built primarily on Anthropic models, and deployed and operated on Amazon Bedrock from Amazon Web Services. When tested against the CyberGym benchmarking framework, the engine scored higher than both single-model and other agentic systems on the leaderboard. TrendAI states internal benchmarking shows its models identify more true-positive vulnerabilities with fewer false positives than leading vulnerability scanning and static analysis tools.

ZDI research validates findings before and after patching

Every AI-identified vulnerability is cross-checked against more than 20 years of research from ZDI, the program behind the Pwn2Own hacking competition. A ZDI expert conducts a scoping interview with each customer to define and tune a custom scan, and the service team monitors every scan rather than deploying an unsupervised system. Output for each finding includes a severity rating, an estimated CVSS score, and a written analysis. After a customer builds and deploys a patch, TrendAI reruns the scan to verify the fix against ZDI research before issuing a final verified patch status.

Source code never leaves the customer's AWS environment

Because the service is deployed natively on Amazon Bedrock, customers continue using their existing Git repositories and code registries as the system of record. The entire workflow, from initial scan through final patch verification, runs inside the customer's own AWS environment, addressing a common enterprise concern about exposing proprietary code to third-party scanning tools.

"Security teams shouldn't have to choose between the speed of AI and the judgment of the world's best vulnerability researchers," said Rachel Jin, Chief Platform and Business Officer and Head of TrendAI.

Access limited to select enterprise customers on AWS

Autonomous Vulnerability Discovery is available now in private preview to select enterprise customers running on AWS. Pricing is customized based on scan scope and deployment model, with access granted through a scoping interview via the customer's TrendAI account team.

Published by
fairsonline_team
News Type